Abilities API and MCP

Overview

WordPress’s Abilities API lets a plugin publish structured, permission-checked operations that other software can discover and call. Teydea Login Security publishes its password policies through this API, under the “Password Policy” category, so an AI assistant connected through the Model Context Protocol (MCP) — or any other Abilities API consumer — can list, inspect, and manage policies the same way an administrator would from the settings page.

This requires WordPress 6.9 or later, which introduced the Abilities API. Reaching the abilities from an AI assistant also requires the mcp-adapter plugin, which bridges registered abilities to MCP; without it the abilities are registered but nothing exposes them over the protocol.

What an Assistant Can Do

  • List every password policy and its configuration.
  • Look up a single policy.
  • Create a new policy. The free plugin allows only one policy. (PRO) PRO allows any number.
  • Update an existing policy’s settings.
  • Delete a policy.

(PRO) For example, an administrator on a site with mcp-adapter installed can ask a connected assistant to “create a policy for WooCommerce customers with a 12-character minimum and no reuse of the last 10 passwords,” and the assistant carries out the whole request through these abilities.

Every setting an ability can read or write — including PRO-only rules like breach screening and reuse prevention, and PRO’s per-role and per-user targeting — is published with a title and a description, so an assistant can present or reason about each one without a person explaining it first.

Permissions

An assistant can only use these abilities as the WordPress user it is authenticated as, and that user needs the same permissions as accessing the plugin’s own settings page. A user who cannot open Settings → Login Security cannot list, read, or change policies through the Abilities API either.