Hosted multi-site gateway
The hosted gateway lets you add one MCP connection to your AI client and reach every WordPress site in your EMCP Cloud workspace, with no per-site config and no passwords on your machine. It’s the cloud-hosted counterpart to the proxy site registry, aimed at agencies managing many client sites.
Plans & connected-site limits
Section titled “Plans & connected-site limits”The gateway reaches every site connected to your workspace, up to your plan’s connected-site limit:
| Plan | Connected sites | Multi-site gateway |
|---|---|---|
| Free | 3 | Not included |
| Freelancer | 25 | ✓ |
| Agency | 100 | ✓ |
| Enterprise | 1000 | ✓ |
Connecting a site beyond your plan’s limit is refused: disconnect a site or upgrade to add another.
How it differs from the proxy
Section titled “How it differs from the proxy”| Proxy site registry | Hosted gateway | |
|---|---|---|
| Where it runs | On your machine (npx @msrbuilds/emcp-proxy) | Hosted at gateway.emcptools.com |
| Credentials | You store an App Password per site in env | None on your side: each site self-issues a revocable token |
| Which sites | Whatever you list in EMCP_SITES | Every site connected to your Cloud workspace |
| Setup per client | A JSON registry in each client config | One connector URL + sign in |
| Broadcast to all | Not supported | site: "all" |
Both expose emcp_list_sites. The proxy keeps a session-wide active site (emcp_use_site); the hosted gateway does not. You name the site on each call with a site argument, which is safer when several people or conversations share one workspace.
Requirements
Section titled “Requirements”- An EMCP Cloud account on a paid plan that includes the gateway (Freelancer or Agency).
- Each site you want to reach is running EMCP Tools 3.10.0+, has the EMCP Cloud module on (EMCP Tools → Setup → Modules, on by default) and is connected to that Cloud workspace with gateway access enabled (below).
- An AI client that supports remote MCP servers with OAuth (Claude, Cursor, VS Code, …).
Step 1: Connect each site with the gateway consent
Section titled “Step 1: Connect each site with the gateway consent”On every site, go to EMCP Tools → Connection and switch to the Cloud section. The Cloud account card shows a switch that is on by default:
Let EMCP Cloud manage this site through the gateway
Leave it on and click Connect to EMCP Cloud, then complete the sign-in. The site then self-issues a scoped, revocable “gateway” credential and hands it to EMCP Cloud. No password ever leaves the site: it’s an OAuth token issued by the site’s own server, and you can revoke it at any time (see Revoking access). Switching it off still connects the site for backup/sync, but it won’t appear in the gateway.
Once connected, the card shows a Gateway access switch (“Let AI clients reach this site through the EMCP Cloud gateway, with no site password to paste.”) and a Re-issue credential link, so you can turn gateway access on later without reconnecting. The “EMCP Gateway” entry shows up under Connected apps on the MCP section of the same screen once provisioned.
Step 2: Add the gateway to your AI client
Section titled “Step 2: Add the gateway to your AI client”Add a single remote MCP server pointing at:
https://gateway.emcptools.com/mcpYour client discovers authentication automatically (via /.well-known/oauth-protected-resource) and walks you through signing in to EMCP Cloud. There are no per-site credentials to paste.
For example, in Claude Code:
claude mcp add --transport http emcp-gateway https://gateway.emcptools.com/mcpthen run /mcp and complete the sign-in. Other clients accept the same URL in their “add remote MCP server / connector” flow.
Using it
Section titled “Using it”Once connected, the gateway advertises the standard EMCP tool catalog plus two helpers:
emcp_list_sites: list the sites in your workspace (id, name, URL) and whethersiteis required.describe-site: a site’s fingerprint (Elementor version, Pro, active integrations, tool count) so the agent knows what a specific site supports. Passtools: ["…"]to get those tools’ exact schemas as that site advertises them.
Every proxied tool takes a site argument (the site id or its URL from emcp_list_sites). With one connected site it is optional; with several it is required, because the gateway refuses to guess rather than write to the wrong site:
{ "site": "acme", "post_id": 42 }Every result ends with a Gateway target: … line naming the site it actually ran on, so a transcript always shows where a change landed.
If a tool isn’t available on the targeted site (a Pro tool on a free site, or one you’ve disabled), the gateway returns a clear tool_unavailable instead of failing silently. A site that’s offline returns site_unavailable, and one site being down never breaks the others.
Broadcasting to every site with site: "all"
Section titled “Broadcasting to every site with site: "all"”Pass site: "all" to run a call against every site in the workspace at once. You get back a per-site status array (which succeeded, which were unreachable, which lack the tool):
{ "site": "all" }Reads (list, get, search, audit, …) broadcast freely. Writes are gated twice, on purpose:
- Workspace opt-in: off by default. Enable it in the Cloud dashboard under Account → Sites → “Allow broadcast writes”.
- Per-call confirm: even with the opt-in on, a write broadcast must include
confirm: true.
If either is missing, the gateway refuses the write and calls no sites. Broadcasts are concurrency-capped, so a large workspace fans out in controlled batches.
Security & revocation
Section titled “Security & revocation”- No passwords. The gateway holds a per-site OAuth refresh token, encrypted at rest, that the site itself issued and can revoke. Tokens rotate on use.
- Scoped. A gateway call acts with your site’s normal MCP permissions and honours each site’s per-tool enable/disable grid, so it can’t do more than a direct connection could.
- Entitlement-gated. If a workspace drops below the required plan, the gateway stops serving its sites.
Revoking access
Section titled “Revoking access”Cut a site off from the gateway from either end:
- On the site: EMCP Tools → Connection → Cloud, switch Gateway access off and confirm “Turn off gateway access?”. This revokes the site-issued token locally and asks Cloud to delete its copy. You can also click Sign out next to EMCP Gateway under EMCP Tools → Connection → Connected apps. Both are immediate and work even if Cloud is unreachable.
- From Cloud: Account → Sites → Disconnect. This deletes Cloud’s encrypted copy and makes a best-effort request to revoke the site-issued token. If the site is temporarily unreachable, you can also sign out EMCP Gateway under Connected apps on the site.
Either path immediately stops the hosted gateway from retrieving the credential. Revoking on the site remains the definitive fallback when WordPress cannot be reached during a Cloud disconnect.
Troubleshooting
Section titled “Troubleshooting”emcp_list_sitesis empty. The site isn’t connected with the gateway consent, the workspace isn’t on a plan that includes the gateway, or the site is still provisioning. On the site, check EMCP Tools → Connection → Cloud: Gateway access should be on. If it is on but the gateway still can’t reach the site (for example after a restore or migration), click Re-issue credential.- A write broadcast is refused. Enable Allow broadcast writes in the Cloud dashboard and pass
confirm: true. - One site errors but others work. Expected:
site_unavailable/tool_unavailableare per-site; the rest of the broadcast still runs.
See also
Section titled “See also”- Multiple sites with the proxy: the local, bring-your-own-credentials alternative.
- EMCP Cloud & Marketplace: connecting a site to Cloud, backup, and sync.
