Sometimes a software project begins with a grand plan. Ours began with a much simpler frustration: quotas.
I wanted to work with my self-hosted WordPress site through ChatGPT without constantly worrying about the limits of a third-party management service. WPVibe helped demonstrate what was possible, but I wanted a workflow I could maintain and extend myself. That question led to MCP OAuth Companion, a WordPress plugin developed collaboratively by Sol and myself.
What MCP OAuth Companion does
MCP OAuth Companion works alongside the separately installed WordPress MCP Adapter. It does not replace the adapter or WordPress itself. It provides OAuth-enabled connectivity and a focused set of authenticated abilities so an authorized AI client can help manage site content.
- Search, retrieve, draft, revise, and publish WordPress posts.
- Inspect revisions and make carefully scoped edits to existing content.
- Create, update, and publish WordPress pages.
- Search the media library, upload supported images, and edit image alt text.
- Move posts and pages to recoverable Trash, with explicit confirmation.
- List and assign eligible authors, subject to WordPress permissions.
Why focused features matter
We considered adding every feature that a larger WordPress management platform might offer. Then we asked a better question: what do we actually need? I do not run a WooCommerce store, for example, so there is no reason to maintain product-editing code today. If that need arises later, we can consider it then.
One feature we especially wanted was surgical editing. Rather than resending an entire article to change a sentence, the plugin can replace a uniquely matching passage while checking the content’s last-modified timestamp. That is useful when editing long Bible studies or technical tutorials, although the timestamp check is not a fully atomic concurrency guarantee.
Testing it on a real site
During development, we tested creating a temporary page draft, editing its content, publishing it, and moving it to Trash. We also uploaded a small test image, updated its alternative text, and searched for it in the media library. The plugin refused to permanently delete the image when WordPress did not have recoverable media trash enabled. These checks confirmed useful workflows on our installation; they are not a substitute for an independent security assessment.
Now available on GitHub
MCP OAuth Companion is now an open-source GitHub project. Version 0.6.2 is our first publicly shared regular release. This maintenance version tightens JWT expiration validation: normal verification rejects missing, malformed, and expired expiration claims, while token revocation can still inspect expired signed tokens. Focused JWT regression checks passed, and the release package was checked for PHP syntax and ZIP integrity.
You can explore the source, read the installation instructions, and find the release package here:
The plugin requires a compatible WordPress MCP Adapter, PHP 8.2 or newer, and an HTTPS-enabled site. It incorporates upstream work attributed to WP Media; the repository includes security and third-party attribution notes. Anyone considering deployment should review those notes and their OAuth client configuration. This release is not independently security-certified.
Why we built it
For me, the goal was never to recreate every WordPress administration tool. It was to keep control of the workflow, add features when they are genuinely useful, and reduce dependence on a third-party service’s usage limits. Building our own companion plugin turned out to be a practical way to do that—and now others can inspect, use, and improve it too.
And yes, both of us are credited on the project: Jonathan Grice and Sol. I’ll leave the mystery of that second name to the curious.
