MCP Tools
Tools are the operations an MCP client can call on your site through the
endpoint described in MCP Server Settings. Each
takes JSON arguments and returns structured JSON. When a client lists
tools it also sees each tool's argument schema, so a capable assistant
can fill in arguments on its own.
Everything here is an operation Torii already performs in the admin. The
endpoint opens it to AI clients, gated by the settings on that screen:
every tool ships disabled, and each must be switched on before a client
sees it. A disabled tool neither appears in the tool list nor answers
calls.
The Tier column matches the badge each tool carries on the settings
screen:
- Read: open read. Available to any authenticated client.
- PII: reads member data. Requires a trusted IP when the gate is
on.
- Write: changes data. Requires a trusted IP when the gate is on.
Tool names below are the machine names clients use.
Members
| Tool |
Tier |
What it does |
check_access |
Read
|
Check whether a member has access to a membership level |
get_member |
PII
|
Retrieve member details by user ID or email address |
get_member_fields |
PII
|
Retrieve custom field values stored for a member |
get_member_tags |
PII
|
Get all tags assigned to a member |
search_members |
PII
|
Search members by login, email, or display name fragment; returns lightweight summaries, paginated |
Membership Levels
| Tool |
Tier |
What it does |
list_membership_levels |
Read
|
List all membership levels, for use with check_access |
Tags
| Tool |
Tier |
What it does |
add_tag |
Write
|
Assign one or more tags to a member by tag ID |
create_tag |
Write
|
Create a tag. Idempotent: returns the existing tag if the name is taken. Optionally matches or creates the linked CRM tag |
create_tags |
Write
|
Create up to 20 tags in one best-effort batch; a single failure does not abort the rest |
delete_tag |
Write
|
Delete a tag. Refuses while the tag is assigned to members or used in membership rules |
list_tags |
Read
|
List all tags, optionally filtered by a partial name with * wildcards |
remove_tag |
Write
|
Remove one or more tags from a member by tag ID |
Pages
| Tool |
Tier |
What it does |
can_access_page |
Read
|
Check whether a specific user can access a specific page, with the reason |
get_page_access |
Read
|
Read the access configuration for one page, post, or CPT |
search_pages |
Read
|
Search pages by title or ID, with optional protection and membership filters |
set_page_access |
Write
|
Update access permissions for one page. Only provided fields change; the full updated configuration is returned |
System
| Tool |
Tier |
What it does |
convert_to_utc |
Read
|
Convert a local date/time to UTC ISO 8601, DST-aware |
get_site_health |
Read
|
Environment, license, CRM connector, and member and module counts in one snapshot |
get_utc_time |
Read
|
Current UTC time plus the site time zone, to anchor phrases like "yesterday" |
list_events |
PII
|
Search the activity log: logins, membership and tag changes, plugin and core updates |
list_extensions |
Read
|
List feature modules and auto-detected integrations with their enabled state |
SSO
These tools appear only when both the SSO and MCP modules are enabled.
| Tool |
Tier |
What it does |
get_sso_config |
Read
|
Report the SSO configuration: providers, toggles, enforcement rules. Secrets never leave; a stored secret appears as a boolean |
get_sso_login_activity |
PII
|
List SSO logins and account-linking changes from the event log, newest first |
test_sso_connection |
PII
|
Run the connection checks for one stored provider. Makes live HTTP calls to the provider and records results in the event log |