Limited time Limited time
Start the Season With Better Forms
Up to 40%Off
Up to 40%Off
Grab Now
documentation-logo
Menu
  • Guides
  • Integrations

What is IvyForms MCP and how do I turn it on or off

Imagine asking an AI assistant to “list my forms, then add a phone field to the contact form” and watching it happen without you clicking through the admin yourself. That’s what MCP (Model Context Protocol) brings to IvyForms; it lets an AI assistant work with your forms through conversational tools that run on the same REST API as the admin interface. The main in-product use is with Angie, Elementor’s AI assistant, which can call IvyForms tools while you’re in the WordPress admin. This article explains what MCP can do, how to turn it on or off, and where its limits are.

What do I need to use IvyForms MCP?

A few things have to be in place before MCP will work:

  • WordPress 6.9 or newer, which bundles the WordPress Abilities API that MCP relies on.
  • IvyForms installed and active.
  • A WordPress user with the right IvyForms permissions. Administrators have full access, and other users can use the tools their permissions allow.
  • MCP turned on, which is the default. You can turn it off at any time in settings.
  • For in-browser use, the Angie plugin active (WordPress 6.5 or newer); Angie is Elementor’s free AI agent, currently in beta.

The first time you activate Angie it sends you to an Elementor login, but that account is free to create, so you don’t need a paid Elementor license to use Angie with IvyForms. Angie runs on daily-renewing credits during its beta.

How do I turn IvyForms MCP on or off?

IvyForms MCP is turned on by default, so you can start using it with Angie right away. To turn it off, go to IvyForms → Settings → General, switch off Enable MCP for AI assistants, and save. To turn it back on, switch the option on again and save. While MCP is off, the MCP endpoint isn’t registered and any agent that tries to reach it gets a 404 (not found) error. For more on this screen, see the general settings documentation.

MCP integration toggle in IvyForms general settings

Developers can override the stored setting with the ivyforms/mcp/enabled filter to force MCP on or off, but the toggle in settings is the normal way to do it.

How does IvyForms MCP connect to Angie?

When Angie is active, IvyForms loads a small script on its admin screens that connects to the WordPress MCP endpoint at /wp-json/mcp/ivyforms-mcp-server and registers a server named IvyForms. From then on, when you ask Angie to manage your forms, it calls IvyForms tools that run through the same REST API as the admin interface, with the same permissions as your logged-in WordPress user, so Angie can only do what that user is allowed to do in IvyForms. You need to be logged into WordPress in the browser for this to work, since the connection uses your logged-in WordPress session. If you’d rather drive IvyForms from an external assistant like Claude Desktop, Cursor, or Claude Code, that’s a separate and more technical setup; see the connecting an external MCP client documentation.

Angie assistant showing available IvyForms in the WordPress admin

Who can use IvyForms MCP and what can they do?

Administrators can use every IvyForms MCP tool, and other users can use the tools that match the IvyForms permissions they have been given. You assign these permissions in IvyForms → Settings → Permissions; see how permissions work in IvyForms for the full setup. Users without any IvyForms permission can’t use MCP.

Each permission unlocks a group of tools:

  • View forms list: list and open forms, browse templates, and get a link to the form builder.
  • Add and edit forms: create, duplicate and update forms, fields, pages and statuses, and manage notifications.
  • View entries from the admin area: list, view, count, and star entries.
  • Access this settings page: read plugin settings and integrations (sensitive values stay masked).

If a permission rule is limited to specific forms, the AI can work with only those forms.

What can the AI do once MCP is enabled?

With MCP on, the assistant can use a fixed set of tools across these areas:

  • Forms – list forms, open form details, create or duplicate forms, update settings and status, and add, reorder, or duplicate fields.
  • Entries – list entries, view a summary, count them, and star or unstar.
  • Notifications – list, view, create, update, duplicate, and search (available to users who can add and edit forms).
  • Permissions – administrators can view access rules and grant or revoke permissions for roles and users.
  • Settings – read only; view plugin settings, with sensitive values masked.
  • Templates – list and view available templates.
  • Integrations – list integrations and view their status.
  • Navigation – get admin links that jump you straight to the form builder or a specific entry.

What can't IvyForms MCP do?

MCP deliberately leaves some actions out, both for safety and for privacy:

  • No deleting – there are no tools to delete forms, entries, or notifications.
  • No saving plugin settings – plugin settings are read-only over MCP; the only exception is access permissions, which administrators can grant or revoke.
  • No confirmation-message editor – confirmation flows aren’t exposed as tools.
  • Submission data is masked – entry field values, IP addresses, user agents, and similar data are redacted in MCP responses; use the admin links to view full submissions in WordPress.
  • Secrets are masked – API keys, tokens, passwords, and SMTP secrets show up as masked values.
  • Permission-based access – visitors, guests, and users without IvyForms permissions can’t use MCP, and everyone else is limited to the tools their permissions allow.
  • Permission management is for administrators – other users can’t view or change permissions through MCP, even if they can access the settings page.

How do I keep IvyForms MCP secure?

Because the assistant acts with the permissions of the logged-in user, you keep MCP secure by controlling who holds those permissions. Follow these practices:

  • Review which roles and users have IvyForms permissions, and give each only what they need.
  • Review any form changes the AI suggests before you publish them.
  • Turn off Enable MCP for AI assistants in IvyForms → Settings → General if you don’t want AI assistants working with your forms.
  • Don’t share the application passwords used for external MCP clients with anyone you don’t trust.

The assistant can change live forms, fields and notifications, not just read them, within the permissions of the logged-in user. Be careful about who you give those permissions to.

Why aren't IvyForms tools showing up in Angie?

If Angie isn’t listing IvyForms tools, check that Enable MCP for AI assistants hasn’t been turned off, that you’re on WordPress 6.9 or newer, that the Angie plugin is active, and that you’re on an IvyForms admin page. A 404 on the MCP URL means MCP is turned off in settings. A permission error usually means you’re not logged in, or your user doesn’t have the IvyForms permission that tool needs, so check IvyForms → Settings → Permissions. If tools went missing right after a deploy, the front end build may not have run, so the bridge script isn’t present.