SpeakEasy MCP
Your MCP doors, unlisted.
A small WordPress plugin that hides your site’s AI doors from strangers, so only the guests you invite even know they’re there.
Your site has new doors. Everyone can see them.
WordPress sites now open MCP endpoints (Model Context Protocol), doors that let AI assistants like Claude work with your site, for example through the WordPress MCP Adapter and the Abilities API.
Those doors are publicly listed and easy to find, so bots and scanners come sniffing. Even with a login in place, a door that answers “login required” has just told them it exists.
“Login required.”
Polite, and exactly what a scanner was hoping to hear.No sign on the door. Just a knock.
A stranger knocks
A bot or scanner tries one of your site’s MCP doors.
Nobody’s home
SpeakEasy answers with a standard “not found”, exactly like a page that doesn’t exist. The door is also gone from your site’s public list of API routes.
Guests walk right in
Addresses on your guest list, or clients that send your secret knock, get through as normal.
Choose how each door behaves.
Open
Just like today. The door is listed and works as usual.
Unlisted
Hidden from the public list. It still works if you know the address and have a login.
Lights out
“Not found” for everyone, except your guest list and anyone with the secret knock.
Covers the WordPress MCP Adapter, the Abilities API, and the Astra theme’s MCP door.
Only the people you invite.
- The guest list. Trusted internet addresses, such as the published range Claude.ai connects from, or your own automation server.
- The secret knock. A private key your own connectors send with each request. Anyone who sends it gets in.
- You, in wp-admin. Logged-in admins work exactly as before.
A second lock, not a replacement
SpeakEasy doesn’t replace your logins. Once a guest is through the door, app passwords still apply. It simply keeps strangers from finding the door in the first place.
Small, quiet, easy to leave.
- One small plugin. No extra server to run.
- No external calls. Nothing phones home.
- Nothing stored in your database.
- Works behind Cloudflare.
- Easy to turn off. Just click Deactivate on the Plugins screen.
Coming soon to the WordPress plugin directory.
SpeakEasy MCP is in testing now on its author’s own sites. Check back here for the release.
Until then, the door stays unmarked.