MCP 0.4.2 / Authorization
MCP scopes and tools
Understand the authority granted by user scopes and registered operator tools.
User scopes are narrow: terminal:read lists commands available to the account, terminal:execute requests eligible reviewed execution, and account:read returns the connected user’s basic profile.
Free operator tools include safe health, product, integration, capability, command, usage, AI, and Blockchain Core inventories. Official add-ons may register their own read-only status tools.
MCP Pro can unlock guarded administration tools, but the global write switch and each callback’s own permission checks must also succeed. A tool missing from tools/list is unavailable; clients must not guess or synthesize tool names.
Scope grants never exceed the current WordPress actor or owning add-on policy.
