A bakery owner wants to change the opening hours before a holiday, add two products and fix a typo on the contact page. Today that means logging in, finding the right screen or emailing the person who built the site. With an MCP server, the owner can ask an AI agent to do it. This guide looks at whether that is a good idea for a small business with no marketing or IT department.
What MCP is, in one paragraph
The Model Context Protocol is an open standard that lets an AI application call tools offered by another system. A website platform publishes an MCP server, and an agent such as Claude, ChatGPT or Cursor connects to it and can then read or change content through the tools that server exposes. The current protocol version is dated 28 July 2026 (MCP, versioning).
The specification is clear about who stays in charge. For trust and safety, there should always be a human in the loop with the ability to deny tool invocations, and applications should show which tools are exposed and ask for confirmation (MCP specification, tools). Keep that sentence in mind, because the rest of this article is about how to make it true in practice.
What the major platforms offer today
WordPress. The official MCP Adapter plugin is on WordPress.org. It turns abilities registered on your site into tools an agent can discover and run. It needs WordPress 6.9 or newer, and version 0.7.0 was released on 2 October 2026 (WordPress.org, MCP Adapter). By default an ability isn't available over MCP unless it is explicitly marked public, and the user must be logged in with the right capability (WordPress MCP Adapter, default server).
Webflow. Webflow runs a remote MCP server that connects with OAuth. Agents can create elements, styles and pages, manage CMS collections and assets, and read site analytics. Every agent works within your existing Webflow permissions and roles (Webflow, MCP server). Users with any site role except Reviewer can connect (Webflow Help, connect your AI tools).
Shopify. Shopify's MCP servers serve different people. The Dev MCP server helps developers search documentation and validate theme and API code (Shopify AI Toolkit). The storefront servers let shopping agents search a store's catalogue and manage carts (Shopify, Storefront MCP server). Neither is a general tool for a shop owner to edit their store by chat.
Payload. The open source CMS has an official MCP plugin that exposes chosen collections and globals over HTTP, filtered by Payload's access rules and with per-collection switches to disable tools such as delete (Payload, MCP plugin). It suits a site built by a developer who sets it up for you.
When it is worth it
An MCP connection helps most when three conditions hold together. Your changes are frequent and small, such as opening hours, menu items, blog posts or product descriptions. Your platform has an official server with permissions you can limit. And the person asking is the owner who already knows what the page should say.
In that situation the agent removes the part that wastes time: finding the right screen and remembering how the editor works. A Webflow site owner who publishes one blog post a week, or a WordPress site where only posts and pages are exposed, is a reasonable fit.
It also helps with tasks that are tedious by hand. Webflow's own prompt library mentions image optimisation and SEO tasks (Webflow, MCP server). Rewriting fifty image alt texts is exactly the job you would happily review instead of doing.
Start with read-only access
You don't have to choose between full access and nothing. The easiest first step is a connection that can only read. Ask the agent which pages have no meta description, which blog posts mention last year's prices or which products have no image. You get the value of a fast assistant who knows the whole site, and the worst outcome is a wrong answer you can check.
On WordPress that means exposing only abilities that read content. On Payload it means leaving the find tool on for the collections you choose and switching off create, update and delete (Payload, MCP plugin). On Webflow, the agent gets your own role, so a separate account with a limited role is the cleaner route (Webflow, MCP server). After a month of useful answers you will know which writing tasks are worth allowing.
When it isn't
The site is rarely touched. If you change something twice a year, setting up and securing an MCP connection costs more attention than it saves.
Nobody would notice a mistake. An agent that edits a live page can break the layout, remove a legal notice or publish a draft. If nobody checks the site regularly, that error can stay up for weeks. Our checklist for AI-built sites before launch applies to every agent edit too.
The shop takes payments. On an e-commerce site, a wrong price or a deleted product costs real money. Here an agent should prepare changes for a person to publish.
The platform has no official server. Community servers exist for many systems. Each one is code you run with access to your site, and the MCP security guidance warns that local servers without sandboxing and consent can be an attack route (MCP, security best practices).
What it really costs
The software is often cheap or free. The WordPress plugin is free on WordPress.org, Shopify's Dev MCP runs locally without authentication and Payload's plugin is part of the open source project (WordPress.org, MCP Adapter; Shopify AI Toolkit; Payload, MCP plugin). You still pay for an AI tool that supports MCP and for your usual hosting or platform plan.
The real costs are elsewhere:
- Setup. Somebody has to decide which abilities or collections to expose, create a limited user or key and test it.
- Review time. Every change still needs a look before it goes live, at least in the first months.
- Maintenance. Plugins, protocol versions and AI tools change. The WordPress adapter alone changed which MCP versions it supports in its latest release (WordPress.org, MCP Adapter).
- Recovery. You need backups and a way to undo a bad edit quickly.
For a business without IT staff, those hours decide more than the licence price does.
Who should do the setup
Connecting an agent takes minutes. Deciding what it may touch takes longer, and that part is the owner's job, even if someone else clicks the buttons. Write down which pages or collections the agent may change, which it may only read and which it must never open.
The technical part depends on the platform. On Webflow, an owner can connect through the official connector and authorise one site (Webflow Help, connect your AI tools).
On WordPress, exposing abilities safely requires adding a flag when abilities are registered, which is developer work (WordPress developer blog, MCP Adapter). On Payload, the plugin is configured in code. If you don't have that skill in house, budget for a few hours of outside help and a yearly review.
A good readiness test is one question: could you cut the agent's access in five minutes? If you don't know where to revoke the key or the OAuth grant, start there, before the first prompt.
The risks in plain terms
Instructions hidden in content. An agent reads text while it works. A malicious comment, form entry or document can contain instructions meant to steer it. OWASP lists prompt injection as the top risk for applications built on language models (OWASP, LLM01 Prompt Injection).
Too much access. The MCP security guidance describes how tokens with broad scopes widen the damage if they leak and recommends asking only for what a task needs (MCP, security best practices).
Trusting labels. Tools can describe themselves as read-only or safe. The specification says clients must treat those descriptions as untrusted unless they come from a trusted server (MCP specification, tools).
A simple decision
Say yes when you change content weekly, use a platform with an official server, can limit what the agent touches and will review changes before they go live. Say not yet when the site is rarely updated, takes payments without a review step or would need a community server with full access.
The second article in this series turns that into concrete settings for each platform: guardrails before an agent edits your CMS.
If you want a second opinion on your platform, or help setting up a limited connection and a review routine, that is part of our web and digital presence work.