Imagine telling an AI coding agent “Create a new custom post type called ‘Projects’ with fields for client name, year, and a project URL” — and having it done in seconds, not hours. That’s what EmDash’s built-in MCP server enables. Cloudflare released EmDash (v0.1.0) in April 2026, calling it the spiritual successor to WordPress. Under the hood, it ships with a Model Context Protocol (MCP) server that gives AI agents programmatic control over your CMS. Here’s exactly how to connect them and what you can accomplish.
The MCP server in EmDash is a built-in endpoint that lets AI agents like Claude, Cursor, and GitHub Copilot read and write content, manage plugins, create content types, and migrate themes — all through natural language commands. To connect an agent, you point it to your EmDash instance’s MCP endpoint and provide the agent skills files that tell the agent what operations are available.
Imagine telling an AI coding agent 'Create a new custom post type called Projects with fields for client name, year, and a project URL' — and having it done in seconds, not hours.
What Is the MCP Server in EmDash?
Cloudflare’s lead engineer for EmDash, Matt Cain (an Astro core team member), built the MCP server as a core part of the CMS. It’s not a plugin or an afterthought. Every EmDash instance includes three components that make AI integration native:
- An MCP server that exposes tools for agents to call. Agents can list posts, create content types, update settings, and more.
- A CLI that agents can use to run commands directly. The CLI supports operations like
emdash content:createcodecodecode andemdash plugin:installcodecodecode. - Agent skills files — structured documentation files that tell AI agents exactly how to operate the CMS. No custom prompting needed.
The MCP server uses the standard Model Context Protocol created by Anthropic. That means any MCP-compatible agent can connect to your EmDash instance. The agent reads the skills files first, learns the available operations, and then executes tasks within the permissions you’ve granted.
How to Connect AI Agents to EmDash: Step-by-Step
Before you start, you need a running EmDash instance. You can spin up a playground at emdashcms.com/playgroundcodecodecode (it lasts one hour) or deploy to your own Cloudflare account using the npm create emdash-latestcodecodecode command.
Step 1: Find your MCP endpoint and agent skills files
After installation, the MCP server runs at http://localhost:4321/api/mcpcodecodecode (or your deployed URL). The agent skills files are in the agent-skills/codecodecode directory of your EmDash project. Open one to see the available tools:
“`json
{
“tool”: “create_content_type”,
“description”: “Create a new content type with custom fields”,
“parameters”: {
“label”: “string”,
“plural”: “string”,
“slug”: “string”,
“fields”: “array”
}
}
“`
Step 2: Point your AI agent to the MCP server
If you’re using Claude Desktop, add the MCP server to your claude_desktop_config.jsoncodecodecode:
“`json
{
“mcpServers”: {
“emdash”: {
“command”: “npx”,
“args”: [“-y”, “@emdash/mcp-client”],
“env”: {
“EMDASH_URL”: “http://localhost:4321”,
“EMDASH_API_TOKEN”: “your_token_here”
}
}
}
}
“`
For Cursor or Copilot, you can use the built-in MCP support by providing the same endpoint.
Step 3: Authenticate and authorize
EmDash uses passkey-based authentication by default (WebAuthn). For AI agents, you’ll generate an API token with scoped permissions. Go to Settings → API Tokens and create a token with content:writecodecodecode and content:readcodecodecode permissions. Paste that token into your agent’s configuration.
Step 4: Give your agent a task
Now you can ask your agent to do something. Example prompt:
“Connect to my EmDash CMS and create a new content type called ‘Portfolio Project’ with fields: client_name (text), year (number), project_url (URL). Then add two sample projects.”
blockquoteblockquoteblockquote
The agent will call the MCP tool create_content_typecodecodecode, then create_contentcodecodecode twice. Each operation runs through the MCP server, respecting the scoped permissions.
Real-World Examples: What You Can Do with MCP
Here are specific tasks that EmDash’s MCP server enables, drawn from the launch materials and developer demos:
1. Port a WordPress theme to EmDash
Matt Cain demonstrated this directly. Feed your WordPress theme’s functions.phpcodecodecode and template files to an MCP agent, and ask it to generate Astro-compatible components. The agent reads the skills files, understands how EmDash themes work (components, layouts, CSS with scoped styles), and produces a working theme. The creator of Yoast SEO, Joost de Valk, called this approach “a brilliant strategy” in his review of EmDash.
2. Migrate content from WordPress
EmDash includes a WordPress migration tool that imports WXR files. But with the MCP server, you can automate the entire process. Example agent command: “Import all posts from my WordPress export file, map Yoast SEO meta fields to EmDash’s built-in SEO fields, and set the featured image for each post.” The agent calls the import tool via MCP, handles field mapping, and reports back.
3. Bulk update content across the site
The EmDash blog post gives this exact scenario: changing a product name that appears in 30 different posts. Instead of editing each one manually, you ask your agent: “Find all instances of ‘OldProductName’ across all content and replace with ‘NewProductName’.” The agent uses the MCP search_contentcodecodecode and update_contentcodecodecode tools to do it in seconds.
4. Create a custom plugin with AI assistance
Because plugins in EmDash run in secure sandboxes (via Cloudflare’s dynamic workers), you can ask an agent to generate a plugin that sends an email when a post is published. The agent writes the plugin code, declares the required capabilities (read contentcodecodecode, send emailcodecodecode), and installs it — all through the MCP interface.
Comparison: MCP vs. Other Integration Methods
The table below compares the three ways to interact with EmDash programmatically. Each method serves different use cases and automation levels.
| Method | Use Case | Automation Level | Setup Time | Skill Required |
|---|---|---|---|---|
| MCP Server | AI agent content management, bulk edits, plugin generation | Fully automated via natural language | 5 minutes (generate API token, configure agent) | Minimal — just a prompt |
| CLI | Scripted deployments, CI/CD pipelines | Scriptable but requires writing commands | 2 minutes (install CLI) | Developer comfort with terminal |
| Admin UI | Manual content editing, visual configuration | Manual only | 0 minutes (built-in) | None |
Key takeaway: MCP is the only method that lets non-technical users automate complex tasks through conversational AI. The CLI is better for repeatable, deterministic workflows. The Admin UI remains the fallback for visual editing.
FAQ
Q: Which AI agents work with EmDash’s MCP server?
A: Any MCP-compatible agent works, including Claude Desktop, Cursor, GitHub Copilot, and OpenAI’s GPT with MCP support. EmDash’s agent skills files are written generically so agents can parse them without custom configuration.
Q: Do I need to pay for Cloudflare’s paid plan to use the MCP server?
A: No. The MCP server runs on any EmDash instance, including local Node.js deployments and the free Cloudflare tier. However, some features like sandboxed plugins (dynamic workers) require the paid Workers plan starting at $5/month. The MCP server itself is not tied to sandboxing.
Q: Can the MCP server expose sensitive data to the AI agent?
A: The agent only has the permissions you grant through the API token. You can scope tokens to read-only or specific content types. Additionally, Cloudflare’s dynamic workers can be used to run agent-generated code in isolated sandboxes, preventing the LLM from directly accessing raw data.
Q: How do I secure the MCP endpoint?
A: The endpoint requires an API token for every request. You can set expiration dates on tokens (e.g., 24 hours for temporary agents). For production, use Cloudflare’s WAF rules to restrict access to known agent IPs.
Limitations and Future Potential
The MCP server in EmDash is a v0.1 feature. It lacks built-in audit logging for agent actions — you won’t see a “Claude modified 47 posts at 3:14 AM” entry in the revisions panel yet. Also, the agent skills files are currently only in English, limiting accessibility for non-English-speaking developers.
But the bigger story is what this architecture enables beyond content management. EmDash also supports the 402 payment protocol, an open standard that lets you charge AI agents for accessing your content on a pay-per-use basis. Imagine a plugin that sells premium content to agents — no subscription plugins, just internet-native monetization. The MCP server is the foundation for that future, where agents become first-class users of your CMS, not just tools for editing it.
- Can the MCP server expose sensitive data to the AI agent?The agent only has the permissions you grant through the API token. You can scope tokens to read-only or specific content types.
- How do I secure the MCP endpoint?The endpoint requires an API token for every request. You can set expiration dates on tokens and use Cloudflare's WAF rules to restrict access.