Skip to content

SitePilot technical documentation

Typed WordPress operations, site-enforced scopes, approval checkpoints, audit records, and rollback data.

Connect safely

Use the read-only quick start and confirm the resulting connection has only site:read.

Operate the plugin

Follow the WordPress operator guide for credentials, permissions, approvals, diagnostics, and revocation.

Understand the boundary

Read the security model and architecture before granting write scopes or approving a change set.

Use a builder

Check the Elementor and Enfold contracts before planning builder-specific work.

Call an operation

Use the MCP API reference for the released operation surface and its risk tiers.

Verify a release

Use current state, release gates, licensing, and third-party notices to verify what is actually shipped.

SitePilot is a guarded bridge between coding agents and WordPress. It does not expose arbitrary PHP, JavaScript, SQL, shell, WP-CLI, secrets, wp-config.php, or filesystem access. WordPress remains the policy-enforcement point for every supported operation.

The marketing and beginner-facing site remains at sitepilot.tools. This documentation origin has its own sitemap and does not add routes to the marketing sitemap.