🔥 Early bird prices end soon — save up to 51%
This plugin is going to revolutionise the way WordPress websites are made
Get Early Bird Price

Cloudflare
WAF compatibility

Cloudflare in front of WordPress can challenge legitimate the WordPress for Cowork plugin traffic. Two modes to watch.

Under Attack Mode

If you enabled Under Attack Mode, every visitor sees a 5-second challenge — including the WordPress for Cowork plugin requests, which times them out.

Turn it off while you connect Claude. If you genuinely need it afterwards (it’s a heavy mode meant for active attacks), add a bypass for /wp-json/coworkmcp/* and /coworkmcp-oauth/*, because Claude’s requests would otherwise hit the challenge every time.

Bot Fight Mode

Bot Fight Mode challenges traffic Cloudflare’s heuristics flag as bot-like. The WordPress for Cowork plugin’s REST calls can occasionally get flagged. Full walk-through with the surgical bypass rule is in Cloudflare blocking the plugin (Bot Fight Mode).

The fast fix during setup

Cloudflare → Overview → Pause Cloudflare on Site. Copy the connection address from wp-admin → Cowork and add it in Claude as a custom connector. Re-enable Cloudflare once connected. Every request Claude makes still passes through Cloudflare, so it keeps working only if Bot Fight Mode is off or the routes below are bypassed. Claude connects to your site from Anthropic’s servers, not from your computer. If you allow by IP address, allow Anthropic’s published outbound range 160.79.104.0/21 rather than your own IP.

WAF rules

If you’ve written custom WAF rules that block /wp-json/*, add an exception for /wp-json/coworkmcp/* and /coworkmcp-oauth/* using a Skip action.

More posts