Skip to content

MCP Log

MCP Log records the requests connected AI clients send to this site, so you can see what a client actually did and why a call failed. Open EMCP Tools → Safety → MCP Log (admin.php?page=emcp-tools-mcp-log). It is free.

EMCP Tools MCP Log with request, error and timing stats, the search, status and time zone filters, and the request table with Time, Request, Status, Duration and Request ID columns

  • Every routed JSON-RPC request, on every transport: HTTP (direct, the Node proxy, OAuth apps) and the WP-CLI stdio server (wp mcp-adapter serve). That includes initialize, tools/list, tools/call and notifications.
  • HTTP requests that never reached a tool. Requests refused before routing also get a row: an invalid or expired session, an unsupported MCP-Protocol-Version, a body that is not valid JSON-RPC (logged as invalid), and a wrong Application Password.
  • The newest 500 requests. Older rows drop off as new ones arrive.
  • Requests with no signed-in user are rate-limited to one row per client address every 30 seconds, so a scanner hammering the endpoint cannot push real requests out of the log. A burst of failed sign-ins therefore shows as a single row.

Nothing a client sends as tool arguments is stored, and full error messages are kept only while WP_DEBUG is on.

Four figures at the top cover every stored request, not just the current page:

  • Requests: how many are stored.
  • Errors: how many failed.
  • Median: the median duration.
  • Slowest: the longest duration, with the tool or method that took it.
  • Search requests matches the method, tool name, client, request ID and failure reason (and the error text while WP_DEBUG is on).
  • Status: All, Success or Errors.
  • Time zone changes only how times are shown: Site time (with its offset, for example “+00:00”), UTC or Browser time. The choice is remembered in this browser.

The MCP requests table shows 50 requests per page, newest first, with these columns:

ColumnShows
TimeWhen the request arrived, in the chosen time zone
RequestThe tool name, with the JSON-RPC method (for example tools/call) under it
StatusSUCCESS or ERROR
DurationMilliseconds, with a bar scaled to the slowest request on the page
Request IDThe JSON-RPC request ID, with Copy request ID
DetailsShow more / Show less

Show more opens the details of one request. Only fields that have a value appear:

FieldMeaning
ClientThe OAuth app name, the Application Password name, “HTTP” or “WP-CLI”
SessionThe MCP session ID for HTTP, or an identifier for the WP-CLI process
CredentialWhich credential signed the request: app: with the Application Password’s ID, oauth: with the app, or cli: for WP-CLI
StageFor a failed request, where it failed, for example transport for a request rejected before it reached a tool
Failure reasonThe short reason a request failed, for example “Post not found.”
ErrorThe full error message, only while WP_DEBUG is on
History entryThe ID of the History entry the call recorded, or not_recorded if its change could not be added

The MCP requests table with one tools/call row for emcp-tools-get-post expanded: Client emcp-log-smoke, the Session and Credential values blurred for this screenshot, Stage transport and Failure reason "Post not found."

Session and credential values identify a connection. They are not passwords, but blur or remove them before sharing a screenshot.

Export CSV downloads the requests that match the current status filter and search, newest first. Columns: time_utc, method, tool, status, ms, request_id, client, session, credential, stage, failure_reason, plus error while WP_DEBUG is on. Times in the file are always UTC, whatever time zone the screen shows.

The file is safe to open in a spreadsheet: any cell that starts with =, +, -, @, a tab or a carriage return gets a leading apostrophe, and so does such a character after a ; inside a cell, so a spreadsheet never runs a value as a formula.

Clear log asks “Clear the MCP log?” and then deletes every stored request. This cannot be undone. It does not touch History.

Reading a failed call. Reproduce the problem once, set status to Errors and search for the tool or method. Show more on the row gives the failure reason; with WP_DEBUG on you also get the full error. Match the row to your client’s error by time (set Time zone to your client’s clock) or with Copy request ID.

What the pattern tells you:

  • No rows at all for your attempt: the request never reached WordPress. Check the URL, HTTPS and any proxy, firewall or CDN in front of the site. See No tools appearing.
  • initialize fails, or every request fails with no signed-in user: an authentication problem. See Auth errors. Remember that unsigned-in requests appear at most once per 30 seconds per address.
  • initialize and tools/list succeed, then one tools/call fails: the connection is fine; the failure reason explains the tool’s own error (missing post, missing permission, invalid input).
  • A write you expected is missing from History: check the row’s History entry field.

When you ask for support, share the request ID and the failure reason rather than a screenshot of the details, or blur the session and credential first.