
ChargeForms MCP Server: The Complete Tool Reference (2026)
ChargeForms ships a real, working MCP (Model Context Protocol) server — not a roadmap item, something you can turn on today. The conceptual guide covers what MCP is and why the safety model works; this is the detailed reference — every tool it exposes, exactly what each one does, and how to actually connect one.
Turning it on
Global Settings → Advanced → MCP for AI Agents. It's off by default — until the toggle is on, the endpoint responds to any request with an explicit "not enabled" error, regardless of credentials. Flip it on and the screen shows your site's real endpoint URL directly:
https://yoursite.com/wp-json/chargeforms/v1/mcp
Connecting a client
Authentication uses WordPress's own built-in Application Passwords — not a separate ChargeForms login system. From your WordPress user profile page, generate a new Application Password (WordPress core has had this built in for years; it's the same mechanism any external API integration to WordPress uses). Your MCP client authenticates with your WordPress username and that generated password, not your real account password.
From there, add the endpoint URL as a custom MCP connector in Claude, ChatGPT, or any other MCP-compatible client — check your specific client's current setup flow for adding a custom connector, since that UI lives on the client's side.
The full tool reference
Read tools (9) — safe to call anytime, no confirmation needed
| Tool | What it does | Parameters |
|---|---|---|
get_forms_context | A quick site overview: total/published forms, total/unread entries. Good first call to orient. | None |
list_forms | Lists forms, paginated. | status (all/published/draft), search, page, per_page |
get_form | One form's full definition — title, status, fields, settings. | form_id (required) |
list_submissions | Lists submitted entries, paginated. | form_id, status, search, page, per_page |
get_submission | One submission's full values, status, and metadata. | submission_id (required) |
get_form_stats | Entry counts for one form — total and unread. | form_id (required) |
list_integrations | Every integration module and whether it's connected site-wide. | None |
get_payment_summary | Total payment revenue, optionally within a date range. | date_from, date_to (both YYYY-MM-DD) |
get_activity_log | Recent site activity — forms created/updated/deleted, entries deleted, settings changed. | page, per_page |
Write tools (6) — every one requires preview-then-confirm
| Tool | What it does | Parameters |
|---|---|---|
create_form | Creates a new form with a title and optional field list. | title (required), fields (array, same shape the builder saves) |
update_form_fields | Replaces a form's field list wholesale. | form_id, fields (both required) |
update_submission_status | Marks one submission read, unread, or spam. | submission_id, status (both required) |
bulk_update_submission_status | Marks multiple submissions read, unread, or spam in one call. | submission_ids (array), status (both required) |
delete_submission | Permanently deletes one submission. Cannot be undone. | submission_id (required) |
add_submission_note | Adds an internal note to a submission — visible to admins only, never the submitter. | submission_id, note (both required) |
How the preview-confirm flow actually works
This is the mechanism that makes the write tools safe to expose to a model at all. Take delete_submission as a concrete example:
- The agent calls
delete_submissionwith asubmission_id. Instead of deleting anything, this returns a preview — a plain description of exactly what would happen ("This will permanently delete submission #4821 from 'Contact Form'") plus a short-lived, server-generated confirmation token. - The agent shows you that description (a well-behaved client does this before proceeding; the model itself never sees a reason to skip it since the tool only proceeds with the token).
- Only a second call, echoing that exact token back, actually performs the deletion.
The token is generated server-side, bound to the specific tool, its exact arguments, and the calling user — nothing in the request itself (including something a malicious actor might hide inside form submission data an agent happens to read) can produce a valid token on its own. That's what specifically defends against prompt injection: a hidden instruction can describe a write, but it can't also forge the token required to execute it.
What this actually looks like in practice
A few real prompts, using the tools above:
- "Give me a summary of this site's forms and unread submissions" →
get_forms_context - "Show me the last 20 unread submissions on the Contact form" →
list_submissionswithform_idandstatus: unread - "How much has the Donation form collected this month?" →
get_payment_summarywith a date range - "Mark submissions 401, 402, and 405 as spam" →
bulk_update_submission_status(previews the exact three IDs and the change before it executes) - "Build me a simple event RSVP form" →
create_form(previews the title and field list before creating anything)
Permission scope
An MCP-connected agent can never do more than the WordPress user it's authenticated as could already do through the admin screens — every tool gates on the same chargeforms_manage_forms capability the admin UI and REST API already enforce. There's no separate, broader "AI access level"; it's the exact same permission boundary, reached through a different door.
Where this fits
Free on every plan, no license required — same as the rest of ChargeForms' core functionality. If you're evaluating whether AI-agent access matters for your site at all, see the conceptual guide for the bigger picture of where WordPress and MCP are heading; this page is the one to bookmark once you've actually connected a client and want the exact tool list in front of you.
Frequently asked questions
How many tools does ChargeForms' MCP server expose?
15 total — 9 read-only tools (listing forms, submissions, stats, integrations, payments, activity log) and 6 write tools (creating forms, updating fields, managing submission status, deleting a submission, adding notes). Every one calls the same underlying methods the admin screens and REST API already use — it's a new way to reach existing functionality, not a separate system.
Do I need a paid ChargeForms plan to use MCP?
No. MCP access is free on every plan — it's not one of the four features gated behind a license. It's off by default and requires a single toggle in Global Settings to turn on.
What authentication does the MCP server use?
WordPress's own built-in Application Passwords — the same core WordPress feature used for any other external API integration, not a separate ChargeForms-specific auth system. You generate one under your WordPress user profile, and the MCP client authenticates with it.
Can an AI agent accidentally delete my forms or submissions through MCP?
Not in a single call. Every write tool is split into a preview step (returns exactly what would happen plus a short-lived signed token) and a separate execute step that requires that exact token back. A model can't guess or forge the token, so a write can't happen from a single instruction alone, including one hidden inside form data via prompt injection.
What's the actual MCP endpoint URL?
{your-site}/wp-json/chargeforms/v1/mcp — visible directly on the Global Settings > Advanced > MCP for AI Agents screen once you're looking at your own site, alongside the enable toggle.
Related posts


Contact Form 7 Is in Maintenance Mode: What That Actually Means
Contact Form 7's creator confirmed at WordCamp Asia 2026 that version 6.2 is the last feature release — the plugin now gets security patches only. Here's what changes, what doesn't, and what to actually do about it.
