MCP Server Settings
The MCP Server screen, opened from the Torii launcher, configures the endpoint AI clients connect to. Connection Setup always shows; the Rate Limiting, Trusted IP Protection, Tools, and Capabilities sections render in advanced mode. The tools page lists everything a client can call once connected.
The module itself is switched on under Torii Settings, Modules, as "MCP Server". Until then the endpoint is not registered, requests to it return a 404, and the screen says as much at the top.
| Setting | Default | Meaning |
|---|---|---|
| MCP Server (Modules screen) | off | Registers the /membership-mcp/ endpoint and loads the module |
| Requests per minute | 60 | Per-user request cap before the endpoint answers 429 |
| Require trusted IP | on | PII and Write tools only answer calls from the trusted IP list |
| Tool toggles | all off | Which tools clients can see and call |
Connecting a client
The endpoint URL is shown on the screen:
https://<your-site>/membership-mcp/. Authentication is an Application
Password sent as a Basic auth header. Primary account passwords are
rejected; create an Application Password from the link on the screen,
which opens your WordPress profile.
Paste the password into the Connection Setup section and it builds a
ready-to-use config block for your client: Claude Code, Claude Desktop,
Cursor, Cline, and Windsurf share one flavor; VS Code (GitHub Copilot)
and opencode each have their own. The screen shows which file the block
belongs in, .mcp.json, claude_desktop_config.json,
.cursor/mcp.json, .vscode/mcp.json, or opencode.json, and a copy
button. Generation happens entirely in the browser; the password is
never sent to the server.
Whoever owns the Application Password also needs the torii_use_mcp
capability, or manage_options. See Capabilities below.
Requests per minute
Each user is capped at this many requests per rolling minute. Over the cap, the endpoint answers HTTP 429 with a JSON-RPC error telling the client to try later. The field accepts 1 to 600.
Require trusted IP
On by default. When on, tools that read member data (PII badge) or change data (Write badge) only answer when the caller's IP is in the trusted list. Open read tools stay available to any authenticated client.
The trusted list is the same Debug IPs list used elsewhere in Torii, managed under Settings, Diagnostics, Debug IPs. Editing it there changes MCP behavior too. The section shows the current list and your own resolved IP with a trusted or not-in-list indicator, so you can confirm your client will pass before fielding it. IP resolution is proxy and CDN aware.
Tools
Every tool ships disabled. Enable the ones you want clients to use, individually, in the Tools section. A disabled tool does not appear in the client's tool list and refuses calls if invoked anyway.
Each row carries a tier badge that tells you what the tool costs to expose:
- Read (green badge): open read. Available to any authenticated client.
- PII (amber badge): reads member data. Requires a trusted IP when the gate is on.
- Write (red badge): changes data. Requires a trusted IP when the gate is on.
The full catalog, grouped the same way as the screen, is on the tools page.
Capabilities
MCP access is granted to users with either of these WordPress capabilities:
| Capability | Description |
|---|---|
torii_use_mcp |
Assigned to the Administrator role by default. Grant it to other roles for MCP access without full admin. |
manage_options |
Always grants MCP access as a fallback. Administrators have this capability. |
Always-on protections
A few protections are not settings; they always apply:
- Only Application Passwords authenticate; account passwords are refused outright.
- Five failed authentication attempts for the same username and IP within ten minutes locks that pair out temporarily.
- Every authentication or permission failure is written to the event log with the username, IP, and reason.
- The endpoint speaks JSON-RPC 2.0 over POST only. There are no sessions and no state to hijack.