Connect an Agent

Kiro

Connect MoraWP in Kiro's IDE or CLI and check web-session authentication.

IDE configuration

Open Kiro's MCP server controls and merge this into .kiro/settings/mcp.json for a project, or ~/.kiro/settings/mcp.json for the user:

JSON
{"mcpServers":{"morawp":{"url":"https://api.morawp.com/mcp","oauthScopes":["morawp:connect"]}}}

Use the server's authentication control to start browser OAuth. The explicit scope avoids requesting unrelated identity scopes.

CLI

Use /mcp to inspect the active servers. Kiro's CLI offers /mcp auth to authenticate a server; select MoraWP and finish the browser approval. Use its logout control when clearing local authorization.

Confirm that your CLI is reading the configuration you edited. Project and user settings can differ.

Kiro Web

The current Web guide supports HTTP/SSE services through the sandbox's MCP server settings → Add server. It separately documents OAuth for installed Powers. That does not establish generic custom-server OAuth compatibility with MoraWP.

Use the IDE or CLI flow above unless your Web session explicitly provides browser OAuth for the custom MoraWP server. A static header or a Power for another service is not a replacement.

If it does not work

Check the active surface and its sign-in controls. Web network policy can also hide MCP settings. An IDE configuration does not prove the cloud sandbox has the same server or credentials.

Approve and check access

First connect a WordPress website in MoraWP. When the client opens sign-in, review the Workspace, websites, and Ability access before approving. Read only limits changes; enabled Integrations may still expose private fields. No static Agent key is needed.

In a new session with MoraWP enabled, ask:

Use MoraWP to list the websites this connection can access.
Do not create, edit, delete, or publish anything.

Check: the intended website appears. Then read one page to check WordPress access. A configured server alone is not proof of a working read.

For missing tools, see Missing Abilities. To stop access, disconnect the Agent in MoraWP and remove its local server entry. Local removal alone is not MoraWP revocation.

Official references

Kiro MCP configuration · Kiro Web MCP and Powers

Vendor instructions reviewed October 9, 2026. Client interfaces and account policies may change.

MoraWP documentation