Docs

Security & privacy

How AI connections are secured, what an AI can access, how changes are confirmed and undone, and where your data goes.

On this page

Connecting an AI app to your site is like giving a capable assistant a login. Urmi keeps that login narrow: the AI acts as a real WordPress user, gets only the permissions you allow, and every change is logged and can be undone. This page explains each safeguard and what data goes where.

Off until you turn it on

The MCP server is off on a new site. An administrator turns it on under Urmi → AI & MCP and confirms what AI apps will be allowed to do. Until then, every AI request is refused. See Turn on the MCP server.

AI apps connect straight to your site. There is no Urmi service in between.

The AI acts as a WordPress user

Every request runs as the WordPress user who created the API key or approved the app. Urmi checks that user's capabilities for each action, exactly like in the editor:

  • An Editor's connection can change pages, but not the Design System.
  • A user who cannot publish cannot publish through AI either.
  • If Urmi's role setting in Settings → Access & roles gives a role Content only, AI can only read for that role. With No access, it cannot connect at all. See Roles & access.

Only roles ticked under Allowed roles in Server settings may connect AI apps. By default that is administrators only.

No administrative rights

While an AI tool runs, Urmi removes every administrative capability from the connected user, whatever their role, administrators included:

  • installing, activating, updating, editing or deleting plugins and themes
  • creating, changing or deleting users
  • WordPress core updates and editing files on the server
  • changing site options (the rights behind Settings in WordPress and Urmi)
  • posting unfiltered HTML

So an AI works on content and design only. Everything it writes is filtered like content from a user who may not post unfiltered HTML: scripts and event handlers are removed.

Permissions (scopes)

On top of the user's own rights, each connection has up to four permissions: Read, Content, Design and Site. Read is always included. Site, which covers menus, caches and form submissions, is off unless you tick it. See What each permission allows.

A connection never gets more than its user may do, whatever permissions it asks for.

How connections sign in

Apps that sign in (OAuth), such as the Claude app and ChatGPT:

  • You approve each app on your own site, logged in to WordPress, and choose its permissions.
  • The app gets short-lived access (one hour) that it renews automatically. Unused access runs out after 30 days.
  • Each renewal replaces the previous token. If an old token is used again, which suggests it was copied, Urmi disconnects that app for that user.
  • Apps can only register themselves while Dynamic client registration is on. Turn it off to freeze the list of apps.
  • You can disconnect any app under Connected apps.

API keys:

  • A key is shown once. Urmi stores only a scrambled fingerprint (a hash) of it, so nobody can read keys from the database.
  • Keys can expire after 30, 90 or 180 days or a year, and you can revoke them at any time. See API keys & scopes.
  • Keys are sent in a request header. Accepting keys in the address (?token=) is off by default, because addresses end up in logs.

Clients can also sign in with a WordPress application password of an allowed user. An application password carries all four permissions, so prefer an API key with only the permissions the app needs.

Warning

Use HTTPS. Connectors like the Claude app and ChatGPT require it, and keys should never travel over plain http on the internet. The optional @wpurmi/mcp bridge refuses to send a key over http except to local addresses.

Limits on what an AI can do

  • Rate limit. Each key or app may make 120 tool calls per minute by default. See Server settings.
  • Web pages on other sites cannot call your server unless you add their address under Allowed origins. Desktop apps, terminal apps and connectors are not affected.
  • No deleting. Urmi's AI tools cannot delete pages, posts, templates or media files. An AI can remove elements from a page, and that change can be undone.
  • Urmi's tools stay inside content and design. An AI cannot change WordPress or Urmi settings, add code, or read API keys and passwords. See What AI cannot do.
  • ChatGPT also asks you to confirm each change before it runs.

Every change is logged and can be undone

  • The activity log lists every request: which app, which user, which tool, the result and a short summary. The full content an AI sends is never stored. Entries are kept for 30 days by default.
  • Before an AI changes a page, a template, a popup or the Design System, Urmi saves the previous state. Undo it from the activity log, ask the AI to undo it, or use Undo in the editor if the page is open.
  • The last 15 saved versions are kept per page.

Turn everything off at once

If something looks wrong, turn off Server enabled at the top of Urmi → AI & MCP. Every AI app is disconnected immediately. Keys and connected apps are kept, so you can turn the server back on after you have checked the activity log. To cut off one app for good, revoke its key or disconnect it.

What data goes where

FeatureWhat leaves your siteWhere it goes
AI apps over MCPWhatever the app asks for with its permissions: page content, settings, media details, and form submissions if it has Site.Straight from your site to the AI app, which sends it to its AI provider (for example Anthropic for Claude, OpenAI for ChatGPT) as part of your conversation. That provider's terms apply.
Image searchThe search words.From your server to Openverse (opens in a new tab). Imported images are downloaded to your media library. Turn it off under Server settings → Image search.
Images from a web addressNothing: your server downloads the image the AI points to.Into your media library.
AI writingThe text of the field you work on, or the image you chose for alt text, only when you click an AI action.From your server to the AI provider set up in WordPress under Settings → Connectors. See AI writing.
AI imagesThe description you type, when you click Generate.From your server to the AI provider set up in WordPress under Settings → Connectors. See AI images.

Urmi does not send your content, keys or activity to its makers. Urmi stores no keys for AI writing and AI images: WordPress keeps the provider's key under Settings → Connectors.

When you remove Urmi

If you turn on Remove all data on uninstall in Advanced settings and then delete the plugin, the API keys, connected apps, OAuth registrations and the activity log are deleted too. Without that setting they stay in the database, unused.