Early access · In testing now

SpeakEasy MCP

Your MCP doors, unlisted.


A small WordPress plugin that hides your site’s AI doors from strangers, so only the guests you invite even know they’re there.

The problem

Your site has new doors. Everyone can see them.

WordPress sites now open MCP endpoints (Model Context Protocol), doors that let AI assistants like Claude work with your site, for example through the WordPress MCP Adapter and the Abilities API.

Those doors are publicly listed and easy to find, so bots and scanners come sniffing. Even with a login in place, a door that answers “login required” has just told them it exists.

“Login required.”

Polite, and exactly what a scanner was hoping to hear.
How it works

No sign on the door. Just a knock.

1

A stranger knocks

A bot or scanner tries one of your site’s MCP doors.

2

Nobody’s home

SpeakEasy answers with a standard “not found”, exactly like a page that doesn’t exist. The door is also gone from your site’s public list of API routes.

3

Guests walk right in

Addresses on your guest list, or clients that send your secret knock, get through as normal.

Three modes

Choose how each door behaves.

Open

Just like today. The door is listed and works as usual.

Unlisted

Hidden from the public list. It still works if you know the address and have a login.

Lights out

“Not found” for everyone, except your guest list and anyone with the secret knock.

Covers the WordPress MCP Adapter, the Abilities API, and the Astra theme’s MCP door.

Who gets in

Only the people you invite.

  • The guest list. Trusted internet addresses, such as the published range Claude.ai connects from, or your own automation server.
  • The secret knock. A private key your own connectors send with each request. Anyone who sends it gets in.
  • You, in wp-admin. Logged-in admins work exactly as before.

A second lock, not a replacement

SpeakEasy doesn’t replace your logins. Once a guest is through the door, app passwords still apply. It simply keeps strangers from finding the door in the first place.

Light by design

Small, quiet, easy to leave.

  • One small plugin. No extra server to run.
  • No external calls. Nothing phones home.
  • Nothing stored in your database.
  • Works behind Cloudflare.
  • Easy to turn off. Just click Deactivate on the Plugins screen.
Early access

Coming soon to the WordPress plugin directory.

SpeakEasy MCP is in testing now on its author’s own sites. Check back here for the release.

Until then, the door stays unmarked.

© 2026 SpeakEasy MCP · speakeasywp.com · Also at speakeasymcp.com

A WordPress plugin by Graham Ahern.