MCP Server Settings

The MCP Server screen, opened from the Torii launcher, configures the endpoint AI clients connect to. Connection Setup always shows; the Rate Limiting, Trusted IP Protection, Tools, and Capabilities sections render in advanced mode. The tools page lists everything a client can call once connected.

The module itself is switched on under Torii Settings, Modules, as "MCP Server". Until then the endpoint is not registered, requests to it return a 404, and the screen says as much at the top.

Setting Default Meaning
MCP Server (Modules screen) off Registers the /membership-mcp/ endpoint and loads the module
Requests per minute 60 Per-user request cap before the endpoint answers 429
Require trusted IP on PII and Write tools only answer calls from the trusted IP list
Tool toggles all off Which tools clients can see and call

Connecting a client

The endpoint URL is shown on the screen: https://<your-site>/membership-mcp/. Authentication is an Application Password sent as a Basic auth header. Primary account passwords are rejected; create an Application Password from the link on the screen, which opens your WordPress profile.

Paste the password into the Connection Setup section and it builds a ready-to-use config block for your client: Claude Code, Claude Desktop, Cursor, Cline, and Windsurf share one flavor; VS Code (GitHub Copilot) and opencode each have their own. The screen shows which file the block belongs in, .mcp.json, claude_desktop_config.json, .cursor/mcp.json, .vscode/mcp.json, or opencode.json, and a copy button. Generation happens entirely in the browser; the password is never sent to the server.

Whoever owns the Application Password also needs the torii_use_mcp capability, or manage_options. See Capabilities below.

Requests per minute

Each user is capped at this many requests per rolling minute. Over the cap, the endpoint answers HTTP 429 with a JSON-RPC error telling the client to try later. The field accepts 1 to 600.

Require trusted IP

On by default. When on, tools that read member data (PII badge) or change data (Write badge) only answer when the caller's IP is in the trusted list. Open read tools stay available to any authenticated client.

The trusted list is the same Debug IPs list used elsewhere in Torii, managed under Settings, Diagnostics, Debug IPs. Editing it there changes MCP behavior too. The section shows the current list and your own resolved IP with a trusted or not-in-list indicator, so you can confirm your client will pass before fielding it. IP resolution is proxy and CDN aware.

Tools

Every tool ships disabled. Enable the ones you want clients to use, individually, in the Tools section. A disabled tool does not appear in the client's tool list and refuses calls if invoked anyway.

Each row carries a tier badge that tells you what the tool costs to expose:

  • Read (green badge): open read. Available to any authenticated client.
  • PII (amber badge): reads member data. Requires a trusted IP when the gate is on.
  • Write (red badge): changes data. Requires a trusted IP when the gate is on.

The full catalog, grouped the same way as the screen, is on the tools page.

Capabilities

MCP access is granted to users with either of these WordPress capabilities:

Capability Description
torii_use_mcp Assigned to the Administrator role by default. Grant it to other roles for MCP access without full admin.
manage_options Always grants MCP access as a fallback. Administrators have this capability.

Always-on protections

A few protections are not settings; they always apply:

  • Only Application Passwords authenticate; account passwords are refused outright.
  • Five failed authentication attempts for the same username and IP within ten minutes locks that pair out temporarily.
  • Every authentication or permission failure is written to the event log with the username, IP, and reason.
  • The endpoint speaks JSON-RPC 2.0 over POST only. There are no sessions and no state to hijack.