sandywp / plugins / abilities-bridge

Abilities Bridge

5.0 out of 5 stars. 5.0 1 reviews

MCP server for WordPress. Connect Claude AI or OpenAI to execute WordPress Abilities with configurable permissions.

Launch a sandbox with this plugin → No signup.
Ready in seconds.

v1.4.0 80+ installs WP 6.2+ PHP 7.4+

your-sandbox.sandywp.com/wp-admin
Abilities Bridge running inside a SandyWP sandbox

What you get inside

6 screens
  • Built-in Chat settings with API-billing labels, API key configuration, and WP AI Client integration

  • Connect ChatGPT account setup with endpoint URL and 9-step connection guide

  • Connect ChatGPT account setup before configuration

  • Admin chat with model selection, conversation management, and AI response

  • Authorize Ability form with 7-gate permission controls

  • Ability permissions list with core read-only abilities and authorized abilities

About this plugin

Making Connections Possible | Now with the Claude 5 family (Opus 5, Sonnet 5, Fable 5) and durable background chat: long AI conversations survive page reloads, closed tabs, and slow hosts

Abilities Bridge connects AI to your WordPress site. Use the built-in admin chat, connect via MCP to Claude Desktop, or integrate with other MCP-compatible applications. Supports both Anthropic (Claude) and OpenAI models.

Key Features

  • Admin chat interface for direct AI interaction
  • Image attachments in chat — upload images or capture a browser-approved screenshot (can be disabled in settings)
  • MCP server for Claude Desktop, ChatGPT, and other MCP clients
  • Persistent memory storage across conversations
  • Abilities execution with 7-gate permission controls
  • Integrated Connected Plugins — discover and approve AI abilities that other plugins register, with per-ability permission controls
  • Claude and OpenAI model support
  • OAuth 2.0 authentication for MCP connections

Four Ways to Connect

  1. Built-in Chat – API Billing – Uses the Anthropic or OpenAI API key stored on this site and is billed directly by that API provider
  2. Claude Account Connection – Connect Claude Desktop through MCP and OAuth using your Claude account; it does not use the built-in chat’s Anthropic API key
  3. ChatGPT Account Connection – Connect ChatGPT developer mode through MCP and OAuth using your ChatGPT account; it does not use the built-in chat’s OpenAI API key
  4. Other MCP Clients – Connect Claude Code and compatible apps using the WordPress MCP credentials shown in setup

Requirements

  • WordPress 6.2+, PHP 7.4+
  • An Anthropic or OpenAI API key for the built-in chat, or the corresponding Claude/ChatGPT account for an MCP account connection
  • HTTPS required for MCP OAuth 2.0 connections

External Services

This plugin connects to external API services.

This plugin communicates with Anthropic’s Claude API (https://api.anthropic.com) and/or OpenAI’s API (https://api.openai.com) to provide AI functionality. Data is only sent when you actively use the chat interface or MCP tools. No background data collection or telemetry occurs.

Durable OpenAI chat jobs use Responses API background mode with response storage enabled so the plugin can poll and recover an answer after the browser closes. Under OpenAI’s standard data controls, stored Responses application state is retained for at least 30 days. For OpenAI organizations approved for Zero Data Retention, OpenAI treats storage as disabled and temporarily stores background response data for roughly 10 minutes to support polling.

Data Sent

  • Chat messages and prompts
  • Memory contents
  • Abilities execution requests and results

Legal & Privacy

  • Anthropic Privacy Policy: https://www.anthropic.com/legal/privacy
  • Anthropic Terms: https://www.anthropic.com/legal/consumer-terms
  • OpenAI Privacy Policy: https://openai.com/policies/privacy-policy
  • OpenAI Terms: https://openai.com/policies/terms-of-use
  • Abilities Bridge Privacy Policy: https://aisystemadmin.com/privacy-policy
  • Abilities Bridge Terms: https://aisystemadmin.com/terms-and-conditions/

By using this plugin, you acknowledge that data will be transmitted to your selected AI provider for processing.

Privacy & Security

Data Transmission

This plugin sends data to Anthropic’s API (https://api.anthropic.com) or OpenAI’s API (https://api.openai.com) when you interact with the AI. This includes chat messages, memory contents, and abilities execution requests. You control what data is sent – the AI only accesses data when you use it.

Security

  • Permission controls with explicit consent for all write capabilities
  • 7-gate ability authorization system
  • Isolated memory storage with size limits (50MB total)
  • Full activity logging and audit trails
  • OAuth tokens encrypted with AES-256-CBC
  • MCP access requires authentication for every method, including discovery (initialize, tools/list, ping); unauthenticated requests receive an HTTP 401 OAuth challenge
  • All admin actions protected with nonce verification and capability checks

Data Retention

Conversations and logs are stored in your WordPress database until manually deleted. Background chat jobs also store status, timing, provider/model, tool-checkpoint, and error metadata; terminal job metadata is automatically removed after 30 days. Durable OpenAI jobs enable Responses API storage for polling and recovery; OpenAI normally retains that application state for at least 30 days, while approved Zero Data Retention organizations use temporary background storage instead. Refer to your provider’s privacy policy and account data controls for current retention practices.

No Telemetry

This plugin does NOT send usage statistics, telemetry, or analytics to the plugin developer.

Support

For support, visit https://aisystemadmin.com

License

This plugin is licensed under the GPL v2 or later.

Questions

Do I need an API key?

For the built-in chat, yes – an Anthropic or OpenAI API key is required and API usage is billed to that provider account. Connecting Claude uses your Claude account instead and does not use the Anthropic API key. Connecting ChatGPT uses your ChatGPT account with developer mode and does not use the OpenAI API key.

Where do I get an API key?

  • Anthropic: https://console.anthropic.com/
  • OpenAI: https://platform.openai.com/

Do I need the Abilities API?

Yes. The Abilities API is the official WordPress API for AI. It comes standard with WordPress 6.9 and is also available as a plugin.

Is this safe to use?

All capabilities require explicit consent. Abilities use a 7-gate permission system with rate limits, risk levels, and admin approval. All actions are logged.

What data is sent to external services?

Chat messages, memory contents, and abilities execution requests are sent to your selected AI provider. Data is only sent when you actively use the plugin. No telemetry or usage statistics are collected.

What is the Memory Tool?

An optional feature that lets AI store persistent notes in the WordPress database across conversations. Limited to 1MB per entry, 50MB total. Enable in Settings > Memory.

What are Abilities?

AI-callable WordPress functions (creating posts, managing users, etc.) that must be individually authorized. Each ability is controlled by rate limits, risk levels, and approval requirements.

What is Beacon Campaign Sender?

Beacon Campaign Sender is a separate plugin that connects to Abilities Bridge as an Integrated Connected Plugin. When it is installed and active, it registers its tools with Abilities Bridge and they appear on the Integrations page. Approve them with one click to let AI agents use Beacon’s tools, with the same per-ability permission controls as every other ability. Nothing is enabled until you approve it.

5.0

1 reviews

  • 5 ★ 1
  • 4 ★ 0
  • 3 ★ 0
  • 2 ★ 0
  • 1 ★ 0

Ratings come from WordPress.org. SandyWP does not collect its own reviews.

sandywp / also on the shelf

Try another plugin

Spin up a real WordPress site in seconds.

Test plugins, build a demo, hand a client a link — then squash it and start again. No local setup, no Docker.