Egenverk Sluice MCPby egenverkPre-release

Let AI agents in. Only as far as you allow.

Sluice runs an MCP server inside WordPress: the agent gets the scopes you choose, every call is logged and every change can be undone.

Sluice: AI client, a gate with scopes, WordPress, log and approvalMCP clientscopesWordPresscontentmediawoo.catalogwoo.ordersLOGIRREVERSIBLE CALLwc_orders_deleteApproveDenyBEFORE / AFTER→Example data

Egenverk Sluice MCP is a WordPress plugin that runs an MCP (Model Context Protocol) server at /wp-json/sluice/v1/mcp. An AI client gets scoped read and write access to WordPress and WooCommerce as a chosen user. Every call is logged, every write can be undone and irreversible calls need human approval. Data does not leave the site.

WP 6.5+WooCommerce 8.2+PHP 7.4+
01Before and after

What happens in WordPress

Before
Before: one REST key that can do everythingAI servicekeyWordPress
A REST key that can do everything, or the site's data sent through a third-party service.
With SluiceSluice MCP
After: scoped permissions, everything loggedMCP clientWordPress
Scopes per area, a log per call and a before/after image of every change.
02Features

What it does, in plain words

  • MCP inside the site

    Endpoint /wp-json/sluice/v1/mcp. No relay service, no external account.

  • Scopes per area

    The connection runs as a WordPress user and never gets more than that user.

  • Log and undo

    Every call is logged. Every write saves a before/after image that can be undone.

  • A person approves

    Irreversible calls, such as permanent deletion, wait for a person.

  • WordPress and WooCommerce

    Posts, pages, media, menus, users, plugins — and products, variations, stock, coupons, orders and reports.

  • Emergency stop

    One constant switches everything off or makes it read-only. Keys are stored hashed and shown once.

03How it works

One connection, scopes per area

You connect an MCP client with an API key or OAuth. The connection runs as a WordPress user and gets scopes per area.

AreaExamples
contentPosts, pages and menus
mediaThe media library
woo.catalogProducts, variations, stock and coupons
woo.ordersOrders and reports

Every call is logged. Every write saves a before/after image that can be undone, and irreversible calls wait for a person. There is no relay service: traffic goes only between the site and the client.

04wp-admin

What it looks like in the admin

Recreated screens in the Egenverk admin kit. Example data.

Sluice MCPby egenverk
ConnectionsLogSettings
ToolRiskConnectionAction
wc_products_updateWriteClient AUndo
posts_listReadClient A
wc_orders_deleteIrreversibleClient BReview
Example data
Sluice MCPby egenverk
ConnectionsLogSettings
Client A · OAuth
content · media · woo.catalog (read/write)
Change
Client B · API key
woo.orders · approval required
Change
New connection
Choose client, scopes and expiry date
Create
Example data
05FAQ

Questions

Does my data leave the site?
No. There is no service in the middle; traffic goes only between the site and the MCP client you connect.
What if the agent gets it wrong?
Every write has a before/after image in the log and can be undone from there. Irreversible calls run only after a person approves them.
Which clients work?
MCP clients with an API key or OAuth.
Can I buy Sluice MCP?
Not today. Sluice MCP is a pre-release that we show as an example of agent-ready WordPress. Contact us if you want to run it in your store.
Related

Babbla

Team chat in wp-admin, with an assistant that answers from WooCommerce using tools that only read.

WC 7.0+ · PHP 7.4+Learn more

Lagom

Cleans the database, slims wp-admin and warns when requests run away. Shows counts before anything is deleted.

WP 6.5+ · PHP 7.4+Learn more

Customer Hub

A withdrawal function, returns and tracking in My Account, and AI suggestions from Egenverk Claims that a person approves.

WC 7.0+ · PHP 7.4+Learn more
Sluice MCPby egenverkContact us