Secure MCP
AI agents your security team can approve
Your developers already use Claude Code, Cursor, and ChatGPT. Now with Secure MCP, those agents can operate WordPress VIP under the same identity, permissions, and governance you control.
Already a customer?


The problem
Enterprise AI outpaced its own governance. Until now.
Your teams build, deploy, and publish with AI agents today. But the way agents reach your infrastructure hasn’t caught up. Raw API keys, custom integrations, third-party tools — each one bypasses the permission model, audit log, and kill switch your enterprise trusts.
Without a way to control MCP access, you’re stuck between rogue agents or no agents at all. Secure MCP changes that.
What it is
Every integration is another credential to govern. This one isn’t.
Secure MCP is the enterprise governance layer, finally caught up to how your teams already work. It replaces the sprawl of keys and integrations with one governed endpoint, api.wpvip.com/mcp. No workarounds, no rebuilds.
Included for VIP customers at no extra cost.

How it works
One endpoint governing two toolsets to start
VIP’s Secure MCP takes the Model Context Protocol (MCP), the open standard for AI agents calling external tools, and builds in governance, per-app control, and audit logging. It’s the gateway that governs two toolsets today, with more to come. Each new MCP routes through the same endpoint under the same identity, controls, and audit.
VIP Platform MCP
Platform operations
Roll back a release, clear the cache, and check the logs in seconds. VIP Platform MCP runs your infrastructure, with 50+ tools across environments, deployments, domains, backups, and WP-CLI.
WordPress MCP
Site operations
Publish a post, create a page, and update a template from a single ask. WordPress MCP manages your content and configuration through the server inside the site.
Who it’s for
For the teams who approve it, and the teams who use it
Whether you’re deploying to production or publishing a post, everyone works under the same identity, controls, and audit.
Developers and platform teams
Connect the agent you already use and put it to work in production. Secure MCP is the gateway agents go through.
Content and editorial teams
Create, update, and publish with AI agents in plain language without needing developer handoff.
Security and compliance leads
No new identity to govern or framework to learn. The same roles, audit trail, and controls you already approved now cover agents.
Platform and engineering leaders
Agent access becomes a platform capability, not a bolt-on. And it’s the foundation your next integrations build on.

Secure MCP governance
Ungoverned agent access doesn’t pass a security review. This does.
Agents connecting to infrastructure today get one of three options: a raw API key with no governance, custom integrations, or a third-party tool that bypasses your controls. None survive a review.
Secure MCP closes the gap. The agent runs as an authenticated VIP Dashboard user and can only do what your login allows. Your security team doesn’t need a new framework for AI; they already have one. It just gained a new kind of user: the agent.
Four controls, governed by default, not by exception
You decide what agents can do. These four controls enforce it.
Deny by default
The gateway denies every action by default, allowing only what you turn on per app, role, and environment.
Production stays off
Writes to production stay off until an Org Admin opts in, one application at a time.
Step Up verification
Sensitive writes pause until someone confirms them in the browser.
Org-wide kill switch
One switch cuts off all agent access instantly, with no ticket and no wait.
Secure MCP audit
What you can’t audit,
you can’t govern
WordPress VIP already logs everything, from the application down to the database and OS. Secure MCP adds one more: the MCP Call Log.
Every call lands there, tied to the person who authorized it and flagged as agent activity. Review it across your whole org or a single environment. Agent actions also appear in your standard audit log, alongside the human ones.

The security model your team approved covers agents too
Platform teams already run Claude Code, Cursor, Claude Desktop, Gemini CLI, and ChatGPT in development. Secure MCP lets those same agents work in your VIP environments without opening a gap in your security.
For beta customers, such as News UK and Pew Research, the first thing they moved onto it was database syncs and error-log pulls that used to be manual.
50
+
tools and growing
60
s
kill switch
Connect
in minutes
$
0
no extra cost
Less time in the dashboard. More time shipping.
Each query saves minutes of dashboard work. A full workflow saves hours. Across a dev team, that compounds.
Core Web Vitals audit
One prompt, and the agent measures your Core Web Vitals, checks server metrics, plugins, and caching, then hands back a fix plan grouped by cause. It only reads data, so it runs on production today. No Step Up needed.

Safe upgrades, with before-and-after proof
The agent spins up a copy of your production site, applies the upgrade, and compares the logs before and after. Only new errors fail the test. Spinning up and tearing down that copy need Step Up approval.

Bug report to fix PR
Tell the agent something’s broken. It reads your production error logs, finds the cause, checks a fix in GitHub, and opens a pull request. Nothing ships until a human approves the merge.


What’s next
Approve the model once for upcoming integrations
New integrations all go through the same gateway, under the same governance. Connect today and get integrations like Parse.ly, GitHub, and Salesforce Agentforce through the connection you already approved. You won’t need new credentials or security reviews. Just one set of controls across everything your agents touch.
Frequently asked questions
Is Secure MCP a chatbot or an AI agent?
No. It generates nothing and makes no decisions. It’s the governed layer between the agent you already use and the infrastructure you already own.
Do we have to install anything?
Secure MCP is built into the VIP Platform. An admin turns it on in the Dashboard.
How do you set up Secure MCP?
First, an admin turns it on. In VIP Dashboard > Integrations, they activate Secure MCP and switch on the toolsets they want, app by app. An app with nothing switched on stays off-limits. Turning on the WordPress toolset configures the site’s MCP server for you — nothing to install on the site, no credentials to copy or store.
Then each person connects their own agent: Claude Desktop, Claude Code, Cursor, ChatGPT, Gemini CLI, or any MCP-compatible client. The first time, they approve access once in the browser. After that, it just works.
How is this different from the WordPress MCP for WordPress.com?
That’s a general tool for the broader WordPress ecosystem. Secure MCP is built for enterprise VIP customers who need the governance, audit, and access controls the general MCP doesn’t provide.
Does it replace VIP-CLI?
No. VIP-CLI is still the right tool for scripted, repeatable automation. Secure MCP is for exploratory, multi-step work driven by an agent.
What can agents do in WordPress today?
Content editing, page creation and deletion, post management, and template and pattern updates. Deeper content workflows arrive in V2.
What if MCP is replaced by another standard?
Secure MCP is built on an adapter pattern. MCP is the current standard, and the architecture adapts if a successor emerges.
What does it cost?
Nothing extra. Access to VIP MCP and WordPress MCP is included for every VIP customer.
Is Secure MCP FedRAMP-covered?
Secure MCP runs on the WordPress VIP platform. For the current compliance scope, contact the team.
Put governed AI agents to work
on WordPress VIP
Secure MCP is included for every VIP customer today, at no additional cost.
Your developers are ready. Now your security team can say yes.