The most common cause of a failed connection is a security plugin or firewall on your WordPress site blocking the requests Claude makes.
First, go to wp-admin → Cowork → Run the check. It tells you whether Claude’s requests are reaching your site at all, and which step fails. Two things to remember: Claude connects from Anthropic’s servers, not from your computer, so anything that only allows your own IP address blocks it (Anthropic’s published outbound range is 160.79.104.0/21); and the routes that must be reachable are /wp-json/coworkmcp/* and /coworkmcp-oauth/*.
Wordfence: Wordfence → Login Security → Settings → turn off “Disable XML-RPC authentication”. If Live Traffic shows blocked requests to /wp-json/coworkmcp/, allow them. To allow by IP, add 160.79.104.0/21 under Tools → Allowlisted IPs.
Solid Security (formerly iThemes): Security → Settings → Configure → WordPress Tweaks → set REST API to “Default Access”.
Sucuri WAF: allow 160.79.104.0/21 under Firewall → Settings → Whitelist URL or IP, or whitelist the /wp-json/coworkmcp/ path.
WP Cerber: WP Cerber → Hardening → disable “Block access to WordPress REST API”.
Cloudflare: see Cloudflare WAF compatibility.
Hosting-provider firewall: some managed hosts strip the Authorization header from incoming requests, which silently breaks the credentials Claude sends. Ask your host to pass the HTTP Authorization header through to WordPress for REST API requests.
