WPPilot wrote this.
If you look after more than one WordPress site, the boring part is not the writing. It is the doors. Open the shop, check it, open the brochure site, open the client's blog, and try to remember which login is which. Use an AI app as well and you do that job a second time: add this site, sign in, add the next site, sign in again. Two sites and two apps is four connections. Ten sites is an afternoon.
There is an optional way around the pairs. Connect each WordPress site once to a WPPilot Cloud account, then add one link to ChatGPT, Claude, or another app you already use. After that you talk to those sites from that chat. The site still decides what is allowed. Cloud only passes the call on.
This is the setup as the site described it on 4 October 2026. It is not a claim that a chat will run a portfolio while you are away. The first job below is a read. Check the answer before you let anything write.
Why a connection per site gets old
A direct connection is still the right idea for one site. The free plugin makes that site its own server. The app talks to it. There is no relay and no WPPilot account. If you have one blog and one app, stop there. The direct ChatGPT guide is the shorter path.
The mess is the pairs. Each new site needs a connection in each app, and each new app needs a connection on each site. Miss one and you will sit in a chat that sounds sure of itself and is not looking at the site you mean.
Cloud flips that. Each site connects once to your account. Each app connects once to Cloud. Adding a site is one step. Adding an app is one step. The docs say it the plain way: without Cloud, every AI app needs its own connection to every site, which is fine for one site and tedious for ten.
The rules do not move off the site. A call still ends there, under that site's safety profile, confirmations, and change ledger. Undo stays there too. Cloud cannot do more than the site granted when you connected it.
What you are connecting
The account is at app.wppilot.co. Every app uses the same link, https://app.wppilot.co/mcp. You paste it once per app and sign in with OAuth. You do not keep a different URL for the shop and another for the blog.
On each site, install WPPilot Free 1.17 or newer. The free release named on the site is 1.17.0. Pro, where a site has it, is 1.11.0. WordPress has to be 6.9 or newer, and PHP 8.0 or newer. The site needs HTTPS, except a local development environment. PHP needs the sodium extension, because the site creates a signing key for Cloud. If sodium is missing, the host has to enable it.
Switch AI abilities on under WPPilot, then Settings, before you open Connect. Cloud tests the connection before it finishes. A site with abilities off refuses to start and tells you to turn them on.
Be signed in to wp-admin as the WordPress user you want the AI to act as. The confirmation names that user, and later calls run as that user, with that user's capabilities, under the access you picked.
Connect the first site in Read Only
Create the account at app.wppilot.co. Cloud is free for up to three connected sites, with every single-site feature. There is no separate Cloud price.
On the first site, open WPPilot, then Connect, then WPPilot Cloud, and select Connect to WPPilot Cloud. A browser tab opens. Sign in.
Choose Read Only. The access you pick is the most Cloud can ever use on that site. Connecting every site as Production Safe because it is quicker means every AI app you later allow in can write to all of them. Connect in Read Only, prove a read, then reconnect only the sites that need writes.
Read the confirmation. It spells the grant out in one sentence: this site, your Cloud account with the email masked, the access level, and the WordPress user the connection will act as. Cancel leaves the site untouched.
You never see the key and you never copy it. The browser only carries a one-time code. The site creates an access token and sends it server to server. Cloud stores it encrypted, then calls the site back to check the connection. The panel should say the site is connected, with the account and a Site ID. In the Cloud account it appears under Sites, with a heartbeat, a last-check time, the name, the URL, the WPPilot versions, and health.
Do the second site the same way, still Read Only, and leave the third slot until those two answer. Three is the free cap. One site links to one Cloud account. If it is already connected, disconnect first. A request lasts about ten minutes and belongs to the admin who started it.
Add the one link to the app you use
Once per app, not once per site.
In ChatGPT on the web, open Settings, then Security and login, and turn on Developer mode. Open Plugins, select the plus button, and paste https://app.wppilot.co/mcp. Authentication is OAuth. Sign in to the Cloud account when asked. A WPPilot plugin for ChatGPT, with a sites panel, an @-mention for a site, settings inside the chat, and approval forms, is coming to the plugin directory. It is not listed yet. Until it is, Developer mode is the route, and it works through the Cloud account.
In Claude, add a custom connector with the same link on claude.ai. It is then available on desktop and mobile too. In Claude Code the documented command is claude mcp add --transport http wppilot-cloud followed by the link. In Cursor, add the link as a remote MCP server and sign in when Cursor asks.
The same once-per-app sign-in covers Claude Code, VS Code Copilot, Codex, Gemini CLI, Antigravity, Windsurf, Zed, Kiro, and JetBrains Junie. Cline, scripts, and CI jobs cannot use a browser sign-in. For those, create a personal access token, limit it to the sites that job needs, set an expiry, and revoke it when the job ends.
After the app signs in, pick the sites it may reach. You can make that connection read-only even on a Production Safe site, and a read-only connection stays read-only. Revoke the app from the account when you want it gone. Attach one app first. If three apps answer strangely on the same afternoon, you will not know which sign-in failed.
Ask for one job you can check
Do not start with "update every plugin" or "rewrite every homepage." Start with a question you can check yourself.
List the WordPress sites you can reach through WPPilot Cloud.
For each one, give me the name, the URL, and the health you can see.
Do not change anything. If a site is missing, say so. Do not guess.
You should get the sites you allowed that app to reach. If the reply names a site you did not connect, or invents a plugin list without looking, stop. The app is not on the Cloud link yet.
The gateway tools behind a normal request are dull, which is what you want. sites_list finds the sites the app may reach. site_tools reads one site's tool list and schemas. run calls one tool on one site. The app has to name the site on each call. It does not see every site's abilities as if they all lived in the chat. If a tool list comes back empty, open that site under Sites and use Check now. The gateway caches what the site reported at its last check.
When the list matches, ask for a second read on one site only:
On [the site name you just saw], show the recent changes in the change log.
Do not undo anything. If you cannot see a log, say that and stop.
Those reads are changes and change_detail. Undo is a separate tool, and the site may ask you to confirm it. Do not use it on this pass. Open wp-admin and see whether the log in the chat is the log on the site. That is the test. A chat that names your sites and shows a change you recognise is connected. A chat that writes a smooth status report with no site names is not.
Only after that read checks out should you move a site to Production Safe, and only a site that needs a write. Disconnect it and connect again. You cannot edit the Cloud token's limits on the Connect screen, because Cloud keeps what was agreed at connect time. Revoking the token from the list does the same as Disconnect.
If most apps should only read and one should edit, connect the site as Production Safe and mark the other apps read-only. That applies at once. You do not reconnect the site for it.
ChatGPT can show an approval pop-up before a risky action. Treat it as a pause. The action still runs on the site, under that site's profile and confirmations, and it lands in that site's change ledger. If you need it back, undo is on the site. The undo and rollback page is the longer account of what a restore can put back. Read it before you undo a client site from a chat window.
What stays on each site
"All your sites in one chat" sounds like one big site. It is not.
Each site keeps its own safety profile. Read Only on the brochure site does not loosen because the shop is Production Safe. Production Safe still blocks raw PHP, WP-CLI, filesystem and database access, plugin and theme installation, and temporary administrator access. Developer Full Access is a different profile, for deliberate development or staging. The Cloud choice the docs describe is Read Only or Production Safe. It is not a switch that turns those blocks off.
Confirmations stay on the site. So does the change ledger, and so does undo. Disconnect from the Cloud account or from WPPilot, then Connect, in wp-admin, and the key stops working from either side.
Cloud does keep a few things, and the Cloud page lists them: your email and a hashed password; each site's URL, name, versions, and health; the encrypted key; which apps may reach which sites; a gateway log of tool name, site, outcome, time, and any error, kept 90 days. Bulk runs, if you use them later, keep the tool, the arguments, and each site's result for 30 days. Sign-in sessions store a browser name and a hashed IP address. Cloud does not store WordPress passwords, and it does not keep pages, posts, or products, except what a bulk run returns, which is deleted after 30 days.
You can tell ChatGPT what to do when a site's state changes. The events named on the page are a site going down, coming back, a key revoked, a site connected, and a bulk run finishing. An action started by an event still goes through that site's safety profile and confirmations, and it still lands in the ledger. "Tell me if the shop goes down" is a fair first instruction. "If anything looks wrong, change the settings" is how you get a surprise.
Three sites on the free account, and what Pro adds
Cloud has no price of its own. Free covers three connected sites. A Pro licence linked to the account raises the limit and unlocks bulk actions. The same email links automatically. A different email can be proved from the Cloud account.
The figures on the Cloud page are the Pro plugin prices, in USD before tax. Solo is $39 a year or $59.99 once. It licences Pro on one site and keeps Cloud's three, with bulk actions. Crew is $59.99 a year or $79.99 once, for 10 Pro sites and 10 Cloud sites. Fleet is $79.99 a year or $119.99 once, for 100 and 100. Command is $99.99 a year or $199.99 once, unlimited on both. Pro includes priority support, meaning a faster first reply. Check the pricing page before you pay.
Bulk is the part people mean by "do this on all of them," and it is not on the free Cloud account. On every Pro plan you can run one tool, with the same arguments, on many sites, in the background. bulk_status reports each site. The app needs bulk permission on its connection. Start with a dry run, which shows what would happen before anything does. The Bulk actions screen lists recent runs and can start one by hand. When a run finishes, an event can summarise what changed and what failed. Read it. A dry run you skip is a slower way to make the same mistake on every site.
Pro tools appear in Cloud only where Pro is installed. Putting ten sites on the account does not install Pro on ten sites. On Solo, the other Cloud sites stay on what Free can do unless they are licensed another way. If you are sorting client work, the agencies page is the page written for a portfolio. Use the Cloud page for the site counts. Do not assume a chat can call a Pro tool on a site that only has Free.
If it refuses to connect
A failed connect leaves the site as it was, unless the message says the token was revoked.
No HTTPS, and Cloud cannot be used from the site. No sodium, and the site cannot create the signing key. If the site could not reach Cloud, try again, then check the host's outbound firewall. If Cloud revoked the token, it could not reach the site: a login wall, an IP allowlist, or a private network. "Connection cancelled" means you backed out before Confirm.
After the first read works
Ask one more read on one site, something you already know: the active plugins, or the title of the front page. Compare it with wp-admin. If you need a write, reconnect that one site as Production Safe and ask for one change you can undo.
Add a second app only after the first one has done that, and a third site only after the first two show a heartbeat you trust. Leave a direct connection, with no Cloud account, on any site you do not want on the shared link. The free plugin still works without Cloud.
Keep the connect guide open while you click through. If a label on the screen disagrees with this article, believe the screen and that guide. Menus and plans can move. The installed plugin and the live site are the record.
Top comments (0)