1. Choose a runtime
WordPress for WooCommerce operations. Local for development work. Cloud only when a remote web client must reach Local.
MCPDO separates execution authority by runtime. Use the smallest setup that completes the job, then keep approvals and verification at the runtime that owns the capability.
WordPress for WooCommerce operations. Local for development work. Cloud only when a remote web client must reach Local.
WordPress uses its site-hosted OAuth/MCP endpoint. Local can be used directly by a compatible local client, or through Cloud for remote web clients.
Inspect first, preview/propose mutations, require exact approval where policy demands it, execute only in the owning runtime, then verify independently.
Use these checks before changing configuration.
/health. Production should report ok:true, the trusted MCP URL, and the configured relay transports.