- WooCommerce Development
- Sep 25, 2026
- 8 min read
WooCommerce MCP and Abilities Explained for Store Owners
WooCommerce MCP is a way for AI assistants such as Claude, ChatGPT or Cursor to connect to your store and work with products and orders through a standard interface. It shipped as a beta in WooCommerce 10.3, was rebuilt on the WordPress Abilities API in WooCommerce 10.9, and is still labelled a developer preview. It is for your team and your tools, not for shoppers.
This guide explains the moving parts in plain language, what you can realistically do with them today, and the security rules we apply before connecting any AI tool to a live store.
What is MCP?
MCP stands for Model Context Protocol. Anthropic open-sourced it in November 2024 as "a universal, open standard for connecting AI systems with data sources." In December 2025 governance moved to the Agentic AI Foundation under the Linux Foundation, co-founded by Anthropic, Block and OpenAI.
Think of it as a common plug. Before MCP, every AI tool needed its own custom integration with every system. With MCP, a system publishes a list of tools (what it can do, what input it needs, what it returns), and any MCP-compatible AI client can discover and call them. The AI client is the assistant your team uses. The MCP server is your store.
What are WordPress Abilities?
Abilities are the building blocks that MCP exposes. The Abilities API was introduced in WordPress 6.9 as a registry where plugins describe what they can do in a machine-readable way. Each ability has a name, a description, an input schema, an output schema, a permission callback and the function that runs it.
The permission callback matters most for store owners. It decides whether the current user is allowed to run that ability. An AI assistant connected to your store acts as a WordPress user, so it can only do what that user and each ability's permission check allow.
WordPress 7.0, released on 20 May 2026, added more AI plumbing to core: an AI Client library for calling AI providers, a Connectors admin page for managing those connections, and JavaScript support for abilities. The MCP Adapter, which turns abilities into MCP tools, is a separate package rather than part of core.
What ships in WooCommerce today?
| Version | What changed | Status |
|---|---|---|
| WooCommerce 10.3 | First MCP integration, released as a beta, enabled under Settings > Advanced > Features | Beta, off by default |
| WooCommerce 10.9 (23 June 2026) | Seven canonical abilities exposed through the Abilities API and the shared WordPress MCP Adapter endpoint | Developer preview |
| Extensions (2026) | Subscriptions, WooPayments, Stripe, PayPal, shipping and marketing extensions adding their own abilities, mostly read-only | Rolling out per extension version |
The seven core abilities in 10.9 are:
- products query, create, update and delete
- orders query, update status and add note
The older WooCommerce-specific endpoint still works but is deprecated. WooCommerce says it and the REST-derived abilities "will be removed in a future WooCommerce version." If someone set up MCP on your store in late 2025, plan a small migration.
The official documentation is clear on status: "The MCP implementation in WooCommerce is currently in developer preview. Implementation details, APIs, and integration patterns may change in future releases." It is also explicit that this is not a shopper-facing feature. Your customers do not talk to your store through it.
What can a store team actually do with it?
With the core abilities, a team member can ask an AI assistant questions and give instructions that translate into product and order actions. Useful, low-risk examples:
- Catalogue checks. "List products in the Outdoor category with no sale price and fewer than 3 images." The assistant queries products and summarises.
- Order lookups. "Show processing orders older than 5 days." Support staff get a quick answer without building a report.
- Bulk copy drafts. "Draft shorter descriptions for these 20 products in our tone." The assistant reads products, and a human reviews before any update.
- Order notes. "Add a note to order 1234 that the customer called about delivery." A small, reversible write.
- Extension data. As extensions ship abilities, the same assistant can read subscription statuses or payment summaries, which saves switching between admin screens.
Where it gets more interesting is custom abilities. Your developer can register abilities for your own business logic: B2B price lists, stock from your ERP, return eligibility, or a report your team runs every Monday. The AI assistant then works with your real rules instead of guessing.
What it is not: a finished "AI assistant for WooCommerce". WooCommerce's own agentic commerce page lists a merchant AI assistant as "coming soon". For now, MCP is plumbing that your team or developer connects to the AI client of your choice.
Is WooCommerce MCP safe to use on a live store?
It can be, with the right setup. The risk is not MCP itself. The risk is giving an AI assistant broad write access to products and orders, which contain prices, stock and customer data. WooCommerce's documentation warns that order and customer operations "may expose personally identifiable information (PII) including names, email addresses, physical addresses, and payment details."
These are the rules we follow:
Security checklist
- Start on staging. WooCommerce's own call for testing recommends development or staging environments first. Test every ability you plan to use against a copy of your store.
- Create a dedicated WordPress user for MCP access, with the lowest role that still works. The WordPress MCP Adapter guidance recommends dedicated users with limited capabilities in production.
- Use an Application Password for that user, never a real admin password. WooCommerce MCP uses Application Passwords and enforces HTTPS for remote connections. Revoke and rotate it when staff change.
- Expose only the abilities you need. The MCP Adapter only exposes abilities marked as public for MCP. For access over the internet, WordPress recommends focusing on "read-only diagnostics, reporting, and content access."
- Keep destructive actions behind a human. Product delete and bulk price updates should not run without someone approving them. WooCommerce's experimental commerce agent reference stages merchant changes "behind a human approval gate", which is the right pattern even if you do not use that code.
- Log what the assistant does. Treat MCP clients like logged-in users and keep logs you can review.
- Check your AI provider's data terms. Anything the assistant reads, including customer names and addresses, goes to the AI provider. Make sure you have a data processing agreement and that your privacy notice covers it.
- Pin and test before updates. Because MCP is a developer preview, test each WooCommerce update on staging before production.
Enabling it
On a staging site, the beta can be switched on in the admin under WooCommerce > Settings > Advanced > Features, or with WP-CLI:
wp option update woocommerce_feature_mcp_integration_enabled yes
Then connect your AI client using the endpoint and the Application Password of the dedicated user. Your developer should confirm the current endpoint for your WooCommerce version, since 10.9 moved to the shared WordPress MCP Adapter endpoint.
Should you wait for a stable release?
For read-only use on a staging copy or with a restricted user, we see no reason to wait. The learning is useful, and the risk is low if the user cannot change anything.
For write access on a live store, we would wait for your use case to be clear and the permissions to be designed properly, not for a version number. The APIs may still change, so budget a little time for updates each quarter. Custom abilities are ordinary WordPress code, and when written against the Abilities API they should survive the move from preview to stable with small changes.
Common questions
Do I need to pay for WooCommerce MCP? No. It is part of WooCommerce. You pay for the AI client or API usage on the provider side, and for any development work.
Can customers use it to shop? No. It is merchant and developer facing. Shopper-facing agents are a different project.
Does it work with any AI assistant? Any client that supports MCP can connect. Check that your client supports remote MCP servers with authentication.
Will it replace my admin? No. It is a faster way to ask questions and handle repetitive tasks. Complex setup work still happens in the admin or in code.
When to get help
If you want to use MCP beyond simple queries, the value is in custom abilities for your own processes and in getting permissions and approvals right. Our WooCommerce AI automation service covers custom abilities, secure MCP setup and approval workflows, built and tested on staging first. If you need someone to keep the setup working through WooCommerce updates, that fits into a maintenance plan.