Settings
- Role
- —
Sign in with Face ID, Touch ID, Windows Hello or a security key. A passkey can't be phished or reused on another site, and it replaces both the emailed link and your code.
No passkeys yet.
This browser can't create passkeys. Try Safari, Chrome or Edge on a device with a screen lock.
Add a time-based code from an authenticator app. You'll be asked for it after each sign-in link.
- Scan this code with your authenticator app.
- Enter the 6-digit code it shows to confirm.
Can't scan? Enter this key manually:
—Two-factor is on.
— unused recovery codes.
Save your recovery codes now.
Each code works once if you lose your device. This is the only time they're shown — store them somewhere safe.
Connect your identity provider (Okta, Microsoft Entra ID, Google Workspace — any OpenID Connect or SAML 2.0 IdP), then verify each email domain your organization owns. An org uses one protocol at a time.
- Plan
- —
- Connected sites
- —
Connect an MCP client — like Claude — to your Portcullis account. Point it at the server URL below and approve the sign-in once; the client can then act across the WordPress sites you can reach, using short-lived scoped tokens. Portcullis stores no WordPress password or key — only these short-lived, scoped tokens ever reach a client.
Add Portcullis as a connector
Portcullis is itself the MCP server. Point Claude (or any MCP client) at the URL below. Claude will open a sign-in page — approve it once and the client can act across the WordPress sites you can reach.
…In Claude Code (CLI)
Register the server, then run it — Claude opens a browser to sign in and approve.
…On first use Claude Code opens the Portcullis sign-in in your browser. After you approve, the tools are available in that session.
In Claude Desktop or claude.ai
- Open Settings → Connectors.
- Choose Add custom connector.
- Paste the MCP server URL from Step 1 and add it.
- Claude opens the Portcullis sign-in — sign in with your email link and approve.
Custom connectors require a paid Claude plan (Pro, Max, Team, or Enterprise).
Use it
Once connected, Claude has seven tools scoped to your fleet:
- list_sites — the sites you can act on.
- resolve_sites(criteria) — find sites by version, tag, health, or client.
- list_abilities(siteId) — what a site exposes, with input schemas and risk flags.
- run_ability(siteId, ability, input?) — run one.
- run_ability_fleet(siteIds, ability, input?) — run one across many sites at once; a large fan-out is queued and returns a job id.
- get_fleet_job(jobId) — progress and failures for a queued fan-out.
- get_fleet_job_results(jobId, cursor?) — the per-site results of a fan-out, one page at a time.
The reading tools need the read permission you granted at sign-in; running one — on a site or a fleet — needs write. A client you approved read-only can't run anything.
No sites yet? first — until then the tools return an empty fleet. If you re-connect Claude after changing your account, just approve again.
Could not load the team.
Requests to join
They signed up with an email at your organization’s domain. They can’t reach your fleet unless you approve.
Pending invites
Could not load your clients.
The customers behind your fleet. Assign a site to a client from its detail page, then group the fleet board by client.
No clients yet. Add one, then assign sites to it from each site's detail page.
You're over your plan limit — upgrade or remove a site to connect more.
No plans are configured yet.
Only an org admin can change the plan.