How to Set Up the MCP Server in Bit Flows to Let AI Assistants Build and Run Your Flows

Estimated reading: 8 minutes 31 views

In this documentation, we will guide you on how to set up the MCP Server in Bit Flows so that AI clients like Claude, ChatGPT and Cursor can build, run and monitor your automation flows for you. MCP (Model Context Protocol) is an open standard that lets an AI assistant connect to your site and work with Bit Flows directly, using the apps and connections you already have.

In this guide, you will understand how to turn your site into an MCP server, connect an AI client through a secure sign-in, choose exactly what that client is allowed to do, and revoke its access whenever you want. This can be helpful for tasks like asking an AI to draft a new flow from a plain description, activate or debug an existing flow, or look up which apps and triggers are available, all from inside your AI assistant.

By the end of this setup, you will have the MCP Server enabled, at least one AI client connected and approved, and a clear view of every client that can reach your flows.

note-icon-bit-apps Note

Note: The MCP Server is a Bit Flows Pro feature, and it stays switched off until an administrator turns it on. Until you enable Enable AI client access, no AI client can connect to your site.

Overview of the MCP Server

The MCP Server turns your WordPress site into a server that AI clients can connect to. Once connected and approved, an AI assistant can work with your Bit Flows automations on your behalf, within the limits you set. You stay in control of who connects and what they are allowed to do.

Key Features:

  • Connect popular AI clients: Claude.ai, ChatGPT, Grok, Claude Code, Cursor, VS Code and more connect straight to your site.
  • Secure by design: Connections use OAuth 2.1 with an approval screen, and every request runs with the administrator account that approved it.
  • You decide what each client can do: Grant full access, read-only, or a custom set of permissions on the approval screen.
  • AI builds and operates flows: With permission, a client can list, create, update, run and debug flows, browse the app catalogue, and manage webhooks, tags and custom apps.
  • Your secrets stay private: App connection secrets are never exposed to any connected client.

Set Up the MCP Server

Step 01: Open the MCP Server Page

In your WordPress admin, go to Bit Flows → MCP Server. This is the page where you turn the server on and connect your AI clients. The MCP Server is a Pro feature; on the free plugin this page shows an upgrade prompt instead of the settings.

Step 02: Enable AI Client Access

Turn on the Enable AI client access switch. As the page describes it, this lets “AI clients like Claude, ChatGPT and Cursor build, run and monitor your flows. Each client must be approved by a WordPress administrator.” Once it is on, the connection instructions and the list of connected clients appear below.

Two things help connections succeed. Your site should use pretty permalinks (WordPress Settings → Permalinks), which the secure sign-in relies on to discover the server, and web clients such as Claude.ai and ChatGPT need a publicly reachable site over HTTPS.

Step 3: Connect an AI Client

Under Connect an AI client, pick your client from the tabs, Claude.ai, ChatGPT, Grok, Claude Code, Codex CLI, Gemini CLI, Cursor, VS Code, Windsurf, or Other. Each tab lists the exact setup steps for that client, along with a Server URL you copy into it. The server URL looks like this:

https://your-site.com/wp-json/bit-pi/v1/mcp

For example, to connect Claude.ai: open claude.ai → Settings → Connectors → Add custom connector, paste the server URL, and save. Claude then opens a popup to your site, where you log in as an administrator and approve access.

note-icon-bit-apps Note

Note: OAuth is the recommended way to connect. It sends you to your own site to approve access, and every request the client makes runs with the permissions of the administrator who approved it.

Step 04: Approve Access and Choose Permissions

When the client sends you to your site, you land on an approval screen. Sign in as an administrator if prompted, then choose how much access to grant under Access:

  • All: Read and change everything in Bit Flows.
  • Read only: View flows and data without making changes.
  • Custom: Choose exactly what to grant, permission by permission.

In Custom mode, each permission is labelled read or write so you can see what it changes. Click Allow access to approve, or Deny to reject. Approving with nothing selected is treated as a denial.

Step 05: Connect with an Access Token (Optional)

Some clients cannot open a browser to sign in. For those, switch to the API key tab and generate an access token. As the page warns, “The token carries full administrator access to your flows, so treat it like a password.” The token is shown only once, “Copy this access token now. It cannot be shown again.”, so copy it right away.

You can Regenerate the token, which replaces the previous one, or Revoke it. Revoking stops any client using that token immediately. Unlike OAuth, an access token skips the approval screen and always carries full access, so use it only when the sign-in flow is not an option.

Step 06: Review and Revoke Connected Clients

Every client that connects appears under Connected clients, showing who authorized it, whether it is Active or Pending, the permissions it was granted, and when it was last used. To cut off a client, click Revoke, it will need to re-authorize to regain access.

What AI Clients Can Do

With permission, a connected client works with Bit Flows through a set of built-in tools. What it can actually do depends on the permissions you granted when you approved it:

  • Flows: list, inspect, create, update, activate, delete and run flows.
  • App catalogue: search the available apps, triggers and actions, and read the flow-authoring guide.
  • Webhooks: list webhooks and their callback URLs, and create new ones.
  • Tags: list, create, rename and delete flow tags.
  • Connections: list your app connections by name and status, never their secrets.
  • Logs: inspect flow runs and each node’s input, output and errors to debug failures.
  • Settings: read and change a few global settings, such as failure notifications and log retention.
  • Custom apps: list, inspect, create and update custom apps.

When an AI creates a flow, it builds the structure, the trigger, the actions and how they connect, and the flow is always created switched off. You then open it in the visual builder (the client gives you a direct link), choose the connections and fill in the fields that pull live options from each app, and activate it. This is by design: only you can safely pick accounts and confirm settings.

Permissions Reference

On the approval screen you grant permissions individually (in Custom mode) or in bulk (with All or Read only). These are the permissions a client can hold:

PermissionWhat it allowsType
Read flowsList and inspect flows and their nodes.read
Manage flowsCreate, update, activate and delete flows.write
Run flowsExecute flows immediately with supplied trigger data.write
Read app catalogueBrowse available apps, triggers, actions and their config schemas.read
Read webhooksList webhooks and their callback URLs.read
Manage webhooksCreate webhooks and connect them to flows.write
Read tagsList flow tags.read
Manage tagsCreate, rename and delete flow tags.write
Read connectionsList app connections by name and status. Secrets are never exposed.read
Read logsInspect flow runs and their per-node input, output and errors.read
Read custom appsList custom apps and their machines.read
Manage custom appsCreate and update custom apps.write
Read settingsRead global Bit Flows settings.read
Manage settingsChange global Bit Flows settings.write

Things to Keep in Mind

  • It is a Pro feature and off by default. Enable AI client access must be on before any client can connect; while it is off, no client can reach your site.
  • Every request runs as the administrator who approved it, and requires administrator rights, which are re-checked on every request. If that account loses administrator access, the client stops working immediately.
  • Access tokens are password-equivalent. An API-key token holds full administrator access and skips the approval screen. Keep it secret, and revoke it at once if it is ever exposed.
  • You are always in control of access. Revoke an OAuth client or an access token at any time. OAuth access tokens also expire on their own after about an hour, and clients refresh them automatically for up to 30 days.
  • Your connection secrets are never shared. Clients can see connection names and status, never the stored credentials.
  • HTTPS and permalinks matter. Web clients need a public HTTPS site, and the secure sign-in relies on pretty permalinks. If connection discovery fails while another MCP plugin is active, temporarily disable that plugin and try again.

info-icon-bit-apps INFO

If you are new to Bit Flows and want to learn how to build a workflow first, please refer to our documentation: Get Started with Bit Flows: A Beginner’s Guide.

Share this Doc

How to Set Up the MCP Server in Bit Flows to Let AI Assistants Build and Run Your Flows

Or copy link

CONTENTS

Subscribe

×
Cancel