How to Connect AI Clients to WordPress with Novamira on xCloud

Updated October 7, 2026 · 4 min read

Novamira is a free, open-source WordPress plugin that runs a Model Context Protocol (MCP) server on your own site. With it connected, an AI client — Claude Desktop, Claude Code, Cursor, VS Code and other MCP clients — can work on your WordPress directly: edit content, manage files, run PHP and query the database, with no server in between.

This guide shows how to connect an AI client to a Novamira-powered WordPress site that is hosted on xCloud. xCloud gives the site the two things Novamira needs — a free, auto-renewing SSL certificate (OAuth requires HTTPS) and a one-click WordPress deploy.

Novamira is not the same as xCloud’s own MCP. xCloud MCP (at app.xcloud.host) manages your servers and sites; Novamira runs on a single WordPress site and manages that site’s content and code. You can use both.

What you need

  • A WordPress site hosted on xCloud, with its domain attached and SSL issued (HTTPS).
  • WordPress 6.9 or newer.
  • The Novamira plugin installed and activated on that site (get it from novamira.ai).
  • An MCP-capable AI client, and a browser for the OAuth sign-in.

Step 1: Install Novamira on your WordPress site

Install and activate the Novamira plugin on your xCloud-hosted WordPress site the same way as any plugin. Novamira also publishes a setup guide specific to xCloud — Novamira on xCloud — worth a look alongside this page. Because Novamira runs on your live domain, make sure the site is already serving over HTTPS — on xCloud that means a domain is attached and the SSL certificate has been issued.

OAuth lets you authorize the client from your own WordPress login in the browser — no password to generate, copy or paste, and you can revoke it anytime. Novamira’s OAuth endpoint is:

https://your-site.com/wp-json/mcp/novamira-oauth

Claude Desktop — open Settings → Connectors → Add custom connector, give it a recognizable name, paste the endpoint URL, leave the OAuth Client ID and Secret empty, and save. Claude opens your browser to authorize with your WordPress login.

Claude Code — run:

claude mcp add novamira-your-site --transport http https://your-site.com/wp-json/mcp/novamira-oauth

Then authorize in the browser when prompted.

Cursor, VS Code and other MCP clients — add the same endpoint URL as a Streamable HTTP MCP server in the client’s MCP settings; OAuth starts on first use.

Application-password alternative

For a client that cannot do browser OAuth, Novamira also exposes an application-password endpoint:

https://your-site.com/wp-json/mcp/novamira

Create a WordPress application password (under Users → Profile) and supply it as the client’s credential. Treat it like a secret.

On xCloud OpenLiteSpeed sites: if OAuth sign-in fails

If your xCloud site runs OpenLiteSpeed and the OAuth sign-in fails — a 404 on /.well-known/oauth-*, or a 403 on the login/authorize page — the site’s generated OLS config and firewall were intercepting the OAuth flow. Fix it in two steps: regenerate the OpenLiteSpeed config, and if the 7G/8G firewall is on, toggle it off and on. Full details and background: Fix MCP OAuth Connection Failures on OpenLiteSpeed Sites. New OLS sites already include the fix.

Security note

A connected client can run PHP and query your database through Novamira, so it effectively has administrator-level reach into the site. Connect only clients you trust, prefer OAuth over application passwords, and remove the connection from your WordPress Users → Application Passwords screen when you no longer need it.

Still stuck? Contact our support team.