# Set up MoraWP for your Agent

Help the user connect the current AI app to MoraWP, then verify a read from a WordPress website they choose. Perform supported configuration steps when you have the required tools; hand off sign-in, authorization, and UI steps you cannot operate.

## 1. Establish the environment

Identify the app and surface actually running this session: desktop, IDE, CLI, or hosted web. Also identify the active host and project. A local MCP configuration or OAuth session does not establish that a remote or hosted session can use it.

Ask only for missing context. Do not assume a Workspace or choose a website on the user's behalf.

Read the relevant MoraWP client guide before changing configuration:

- Codex: https://docs.morawp.com/agents/codex
- Claude Code: https://docs.morawp.com/agents/claude-code
- Cursor: https://docs.morawp.com/agents/cursor
- Claude chat: https://docs.morawp.com/agents/claude
- ChatGPT: https://docs.morawp.com/agents/chatgpt
- Other apps: https://docs.morawp.com/getting-started/connect-agent

Use the route for the user's actual surface. Follow any support limitations in that guide. Do not guess a CLI command, configuration key, or OAuth workaround.

## 2. Check the prerequisites

The user needs a MoraWP account, access to the intended Workspace, and a connected WordPress website.

If the website is not connected, guide the user through:
https://docs.morawp.com/getting-started/install-plugin
https://docs.morawp.com/getting-started/connect-website

A website needs recognized HTTPS. Do not disable certificate verification or bypass a browser warning to complete setup. Do not request passwords, tokens, WordPress Application Passwords, or authorization URLs in chat.

## 3. Configure the current app

The MoraWP remote MCP endpoint is:

https://api.morawp.com/mcp

Connections use browser OAuth, without a static MoraWP Agent key or a manually supplied Authorization header.

Inspect existing MCP configuration before editing it. Reuse a correct existing MoraWP entry; do not create duplicates, replace unrelated servers, overwrite the whole configuration file, or silently broaden configuration scope. If a conflicting entry exists, show the difference before replacing it.

Follow the client guide to add the endpoint and begin authentication. Do not install unrelated tools, change account plans, or enable additional Abilities as part of setup. If the client is unavailable, point to its official installation instructions rather than assuming installation permission.

## 4. Let the user approve access

The user completes sign-in and reviews the app, Workspace, and selected websites in MoraWP. For this first check, ask the user to choose only the intended website and Read only.

The user must read and acknowledge the data-access notice themselves. Enabled Integration reads can return sensitive or private fields, including credentials exposed by the Integration. Read only limits changes; it does not redact returned data.

Do not submit approval or acknowledge that notice for the user. Do not change access rules to bypass a refusal. See:
https://docs.morawp.com/getting-started/connect-agent#approve-access-in-morawp

Refresh the client's tools or start a new session only when its guide requires it.

## 5. Verify a real read

A saved server entry or a connected badge alone is not completion.

1. Call list_websites and let the user choose from the returned websites.
2. Call list_abilities for that website.
3. Call describe_ability for the discovered WordPress page-list and page-read Abilities. Its Ability-name field is ability_name.
4. Use execute_read_ability with the returned Ability identifier in ability_id and its validated inputs inside parameters.
5. List existing pages, let the user choose one, then read that page's title and content. Use identifiers returned for the same website.

Do not create, edit, publish, delete, execute PHP, run WP-CLI, or access files during this check. Do not enable high-impact Abilities.

Ask the user to compare the returned page with WordPress and review the actual Ability attempts in MoraWP Activity. Dispatched reads count toward the Workspace's AI Actions allowance; discovery is not a customer Ability action.

If access or a read fails, inspect the response and follow the relevant troubleshooting guide. Do not repeatedly retry a refusal, switch to a more powerful executor, or claim the read passed.

## 6. Report what was verified

State separately:
- Which app, surface, and host you configured.
- Whether OAuth finished.
- Whether the intended website was visible.
- Whether a real page read succeeded, including which page the user selected.
- Anything still requiring user action.

Only report the steps actually verified. Do not print credentials, private configuration, full returned content, or sensitive diagnostics in the summary.

Quickstart: https://docs.morawp.com/getting-started/quickstart
Troubleshooting: https://docs.morawp.com/troubleshooting/agent-connection
Support: support@morawp.com
