MagicWP Docs
MCP (AI assistants)

Tools

Every tool the MagicWP MCP server offers, what it does and the permission it needs

The MCP server has 54 tools. Your assistant sees only the ones your token's permissions allow: a For MCP (full) token sees all 54, a For MCP (read-only) token sees 19. You don't call tools yourself; your assistant picks them from what you ask.

The Needs column is the token permission, as it is named under Settings → API tokens. Any token means every token can use the tool.

Read

These only look. They never change anything on your sites.

ToolWhat it doesNeeds
whoamiThe workspace you're connected to, your role, what the token may do and when it expiresAny token
list_sitesYour sites with their status, PHP and WordPress version and storageAny token
get_siteOne site's details: domains, status, versions, storage, notesSee the site
site_overviewEverything at a glance: whether the site answers over HTTPS, pending updates, latest backups, running tasks and resource use. Says so while a site is still being builtSee the site
check_site_upFetches the site's front page over HTTPS: status code, response time, redirect and certificateSee the site
site_metricsCPU, memory, disk and traffic: live, today, or the last 30 daysSee the site
list_activityWhat happened on a site, or across the workspaceSee the site, or the workspace activity log
catalogRegions, base domains, templates, and how many sites you can still createAny token
list_tasksBackground tasks running now, or one site's recent tasksAny token
get_taskA task's progress and result, and which step a site build is on. Can wait for it to finishAny token
list_backupsA site's backups, or full backups across the workspaceAny token
get_stagingA site's staging copy, and what pushing it live would changeSee the site
list_staging_revert_pointsThe backups taken automatically before each staging push, so a push can be rolled backSee the site
list_extensionsInstalled plugins or themes with versions and available updates, or a search on WordPress.orgSee the site
list_updatesPending core, plugin and theme updates on one site or all of themSee the site
get_site_configWordPress settings, debug and maintenance mode; PHP version, php.ini, PHP-FPM and extensions; page cache, nginx features and RedisSee the site
list_wp_usersThe site's WordPress users and their rolesManage WordPress users
database_statsTable sizes, and how much a cleanup would removeSee the site
search_replace_previewA dry run of a database search and replace: how many rows would changeDatabase
list_redirectsThe site's redirect rulesSee the site
list_domainsThe site's custom domains, their status and the DNS records they needSee the site

Change

These change something that is easy to change back, or harmless to repeat. Your assistant may still ask before it runs them.

ToolWhat it doesNeeds
create_siteStarts building a new WordPress site. The assistant tells you when it's readyCreate sites
clone_siteCopies a site into a new siteCreate sites
update_siteRenames a site or edits its notesEdit the label and notes
site_powerRestarts a site, or runs Fix (repairs Redis, the MagicWP plugin and the database connection)Restart, fix, maintenance
create_backupTakes a full backup now and keeps it until you delete itBackups
manage_stagingCreates a staging copy, or gives it more timeCreate and extend staging
manage_extensionInstalls, activates, deactivates or updates plugins and themes, or turns their auto-update on or offPlugins and themes, or updates
manage_updatesChecks for updates, applies them, and turns auto-updates on or offUpdates
update_wp_configWordPress settings (site title, timezone and more), debug mode and maintenance modeWordPress settings, or restart, fix, maintenance
magic_loginA one-time link that logs you into wp-admin. It works once and expires after 5 minutesMagic Login
send_password_reset_emailSends WordPress's own Password Reset email to a WordPress userManage WordPress users
manage_wp_userCreates a WordPress user, edits one, or changes their roleManage WordPress users
update_phpPHP version, php.ini, PHP-FPM settings and extensionsPHP, caching and Redis
update_cache_configPage-cache expiry, nginx features and the Redis object cachePHP, caching and Redis
flush_cacheClears the WordPress, page, OPcache or Cloudflare cacheRestart, fix, maintenance, or domains
manage_redirectCreates, changes or imports redirect rulesRedirects
manage_domainAdds a custom domain, re-checks its DNS, or makes it the site's addressDomains

Destructive

These lose data or are hard to undo. Each one needs confirmation: the site's domain, typed by you (see Safety).

ToolWhat it doesNeeds
delete_siteDeletes a site and everything on itDelete the site
reset_siteWipes the site's files and database and reinstalls WordPressReset and restore
restore_backupRestores a backup over a site, or a full backup of one site onto anotherReset and restore
clone_into_siteCopies one site over an existing site, replacing everything on itReset and restore
push_stagingReplaces the live site with its staging copy (a revert point is taken first)Reset and restore
delete_backupDeletes a kept or download backupBackups
delete_extensionDeletes plugins or themes with their filesPlugins and themes
delete_wp_userDeletes a WordPress user and hands their posts to another userManage WordPress users
shuffle_saltsRegenerates the WordPress keys and salts, signing everyone outWordPress settings
reset_phpPuts php.ini and PHP-FPM back to the plan defaultsPHP, caching and Redis
search_replaceReplaces text across the whole database. Runs only after a preview of exactly the same changeDatabase
database_maintenanceOptimizes tables, or deletes revisions, drafts, trash, spam and expired transientsDatabase
change_db_prefixRenames every database table to a new prefixDatabase
delete_redirectsDeletes redirect rulesRedirects
remove_domainDisconnects or deletes a custom domainDomains
detach_cloudflare_dnsRemoves the DNS records MagicWP wrote in Cloudflare for the siteDomains

Not available through MCP

On purpose, the MCP server has no tools for:

  • billing and payments, members and invitations, API tokens and site transfers;
  • SFTP and database passwords and phpMyAdmin;
  • setting a WordPress user's password (use send_password_reset_email);
  • backup download links, email provider settings and connecting Cloudflare.

Those stay in the dashboard.

On this page

Try MagicWP free
  • Temporary sites
  • Free templates
  • Staging sites
  • Offsite backups
  • Team access
  • API tokens
  • PHP 8.5
Go to your dashboardManage your sites, backups and team