Detailed view of a backlit laptop keyboard keys with blue LED lighting for tech concepts.

Photo by Castorly Stock on Pexels.

An AI assistant that can act on a website needs more than an address to call. At SimpleWP, that need led to an MCP OAuth connection for the product’s site-management tools: an authorization flow that lets Claude.ai, ChatGPT and other MCP clients reach a user’s sites by signing in and clicking Allow, the same way any other app connects to an account. This is how that MCP OAuth flow was built, from serving the tools themselves to proving the whole exchange against a real client before shipping it.

Serving MCP Tools From SimpleWP’s Main App

Before any sign-in screen existed, SimpleWP already served a Model Context Protocol (MCP) server directly from its main application, giving MCP-aware AI assistants a defined set of site-management tools that run through the exact same code path and the exact same authorization rules as the product’s own API.

That choice was deliberate. The team wanted its six MCP tools and the product’s own API to call the exact same underlying operations, so a fix or a new capability added to one would automatically reach the other, instead of maintaining two versions of the same logic side by side. Two code paths drift apart quietly over time even when nobody intends it; one path cannot.

Making that true meant touching the plumbing underneath, not just the surface. Moving MCP into the main application included upgrading the project’s schema-validation library to a newer release, specifically so the official MCP SDK could be used directly against the product’s existing tooling instead of around it.

The move caught something worth fixing on its own along the way. Two of the six tools’ own descriptions — the text an AI model reads to know how to use a tool — claimed a field the tools did not actually return. The team corrected both descriptions as part of the same work, so what the model is told now matches what each tool does.

And because an MCP endpoint sits exactly where a caller’s own data passes through, the team kept its operational logs free of anything a user would not want logged there: a caller’s API key, the content of a chat message, or an email address never appear in them, so the logs stay useful for watching the service’s health without ever exposing what a user actually sent or who they are. A log built that way can be read freely by anyone debugging a slow day, which is the whole point of writing it that way in the first place.

An MCP OAuth Flow: Sign In, Then Click Allow

Serving MCP tools from the main app solved half the problem. The other half was how a user’s own AI assistant could reach for them in the first place. Before this work, that meant generating a personal API key by hand and pasting it into a connector — workable, but one more secret to copy, store and remember to rotate, and already the pattern behind how a personal API key connects a Custom GPT or the SimpleWP MCP server today.

On top of that existing path, the team added a full MCP OAuth flow. Claude.ai, ChatGPT and other MCP clients can now connect to a user’s SimpleWP sites by signing in and clicking Allow, the same motion as connecting any other app to an account instead of generating and pasting a key by hand.

The personal API key did not go anywhere, and nothing about this flow retires it. OAuth sits next to the key as a second way to connect, for assistants that would rather present a sign-in screen than ask a user to paste a secret. Which route fits better depends entirely on the assistant a user already has open, not on one route being the “right” one.

OAuth for AI Agents, Built to the Protocol’s Own Pattern

Building OAuth for AI agents meant following a pattern the protocol itself already defines on top of the OAuth 2.0 standard, rather than inventing a bespoke one. The MCP OAuth flow follows the Model Context Protocol’s own authorization pattern end to end: dynamic client registration, PKCE, short-lived access tokens with longer-lived rotating refresh tokens, and client-metadata discovery scoped specifically to Claude.ai and ChatGPT’s own domains.

Each piece does a specific job. Dynamic client registration lets a connecting app introduce itself without a person pre-registering it by hand first. PKCE ties one particular sign-in attempt to the token exchange that follows it, so only whoever started that attempt can complete it. Rotating refresh tokens mean a long-lived connection never depends on a single token staying valid forever unchanged. None of these pieces are specific to SimpleWP; they are exactly what the protocol itself already recommends, which is the appeal of following a standard rather than designing a connection flow from scratch.

Client-metadata discovery — the mechanism an MCP client uses to register itself — is restricted specifically so it cannot be redirected into fetching a URL supplied by an untrusted source. Only a client genuinely hosted on Claude.ai’s or ChatGPT’s own domain can register itself as trusted this way.

Connected Apps, Revocation and Shared Limits

Once an assistant is connected, a user can see it. Every connected app is listed in the user’s own account settings — AI assistants, Connected apps — right alongside any personal API keys, each one individually revocable. Revoking the account’s main key revokes every connected app at the same time, so there is one clear lever for shutting everything off together.

Connecting a new app sends the account owner an email notification every time, and an OAuth-connected session answers to the same per-connection request limit and the same shared daily AI-spend ceiling that personal API keys already had — a new way to connect, not a new set of rules. A user who already understands how a personal key behaves does not need to learn a second set of limits for an OAuth-connected app.

Two new chat tools extend that same control into the conversation itself. A user can review and disconnect their own connected AI apps just by asking, under the same confirm-before-apply pattern the product already uses for any other write action, rather than only being able to manage connections from account settings.

Connecting Claude Code to a Real MCP Server

A flow like this is easy to get right on paper and wrong in practice, so before shipping, the team proved it end to end against a real MCP client — Claude Code’s own implementation — rather than only against internal test doubles. Client registration, the consent screen, and a full token round trip were all verified live, connecting Claude Code to a real MCP server the same way an actual user eventually would.

That live testing earned its place. Testing the token exchange found that replaying an already-used authorization code should immediately revoke the access it had already granted, rather than be honored a second time. The team closed that gap before shipping, so a reused authorization code now revokes the connection instead of silently succeeding again. Finding that detail by running the real exchange, rather than only reading the specification describing it, is exactly why the live proof against Claude Code came first.

Two New Chat Tools and a Same-Week Ship

The MCP OAuth connector for SimpleWP shipped to production the same week it was built — merged one day, promoted to production the next. Shipping that quickly only works when the pieces in front of it (the shared code path, the standard-pattern flow, the live proof against a real client) are already solid enough to trust.

None of this changes what a personal API key can already do. A Custom GPT or the SimpleWP MCP server still works exactly as it did before; an MCP OAuth connection just gives an assistant a second way to reach the same tools, built with the same care the team already brought to a production postgres database migration and to everything else SimpleWP’s AI assistant can do. Once an assistant is connected this way, what it can actually build on a site is its own story — turning a chosen template into real Elementor pages is one example, and running a WooCommerce store by chat in four languages is another. If engineering credibility like this is part of how you choose a hosting partner, see SimpleWP’s plans.