Codex desktop app + WordPress MCP

Connect Codex desktop app to WordPress, with boundaries.

Connect the OpenAI Codex desktop app to WordPress over a remote MCP endpoint, with no config file to edit.

Connection profile

Codex desktop app

OAuth routeNative remote OAuth
MethodsOAuth 2.1

Open Settings from your account menu, add WPPilot as a remote MCP server, and approve the browser sign-in.

Connection sequence

A clean Codex desktop app setup in six steps.

Use the configuration generated by your own WordPress site. It contains the endpoint shape and selected authentication route appropriate to the installed WPPilot instance.

  1. 01

    Install the foundation

    Activate WPPilot Free on a supported WordPress and PHP version, then open its Connect screen.

  2. 02

    Choose the client

    Select Codex desktop app; WPPilot presents the supported connection methods and client-specific guidance.

  3. 03

    Choose authentication

    Codex desktop app can use the native remote OAuth route. A dedicated Application Password is another listed option where supported.

  4. 04

    Add the generated config

    Open Settings from your account menu, add WPPilot as a remote MCP server, and approve the browser sign-in.

  5. 05

    Authorize deliberately

    Use a dedicated WordPress identity with the smallest role and WPPilot safety profile the workflow needs.

  6. 06

    Verify read-only

    Discover tools, inspect one schema, read a non-sensitive object, and review the result before enabling writes.

Authentication detail

Direct remote OAuth is supported.

Codex desktop app is in WPPilot's native OAuth client group. It can complete a browser-based authorization against the remote MCP endpoint through its supported flow.

Connection methods in the registry

  • OAuth 2.1

Codex desktop app specifics: In the Codex desktop app open Settings from your account menu, add WPPilot as a remote MCP server, and approve the browser sign-in.

Do not copy a generic secret from a public guide. Generate the connection on your site, keep credentials out of source control, and revoke unused credentials in WordPress.

First useful test

Ask Codex desktop app for evidence, not broad authority.

A short read-only exercise proves the endpoint, credentials, tool discovery, schema lookup, permissions, and response path without changing the site.

  • Report the active WPPilot safety profile
  • List the abilities currently available to this credential
  • Inspect the schema for one read-only content ability
  • Read one non-sensitive page or post
  • Name the WordPress object and fields used in the answer
  • Do not write, publish, delete, or invoke developer tools
  • Report any connection or permission error exactly

Codex desktop app WordPress MCP FAQ

The setup questions that matter.

Connection behavior reflects the current WPPilot client registry reviewed August 9, 2026. Client releases can change; use the generated in-product guidance.

Can Codex desktop app connect to WordPress through MCP?

Yes. WPPilot includes a Codex desktop app-specific connection path. Open Settings from your account menu, add WPPilot as a remote MCP server, and approve the browser sign-in. In the Codex desktop app open Settings from your account menu, add WPPilot as a remote MCP server, and approve the browser sign-in.

Which authentication methods are available for Codex desktop app?

OAuth 2.1 are represented in the current WPPilot client registry. The Connect screen generates the path and configuration that match the selected method.

Does connecting Codex desktop app give it full WordPress access?

No. The dedicated WordPress user's capabilities, WPPilot safety profile, enabled abilities, rate limits, and critical confirmations are enforced on the site.

Can Codex desktop app use WPPilot Pro integrations?

Yes, when WPPilot Free is active, the Pro licence is active, the relevant companion plugin is present, integration health is usable, and the live ability is permitted.

What should the first test be?

Use staging or Read Only. Ask the client to discover abilities, inspect one ability schema, read a non-sensitive page, and explain exactly which site evidence it used. Do not begin with a broad write.

Your site · your policy · your AI client

Put Codex desktop app to work on WordPress, carefully.

Start with WPPilot Free, a dedicated credential, Read Only, and one inspectable task. Add authority only when the workflow and recovery path are proven.