Wordfence is the most common cause of connection failures. Two settings to check before contacting support.
1. Disable XML-RPC authentication setting
WordPress for Cowork doesn’t use XML-RPC, but Wordfence sometimes lumps it with REST API protection — turning that setting on can also gate the REST routes the WordPress for Cowork plugin needs.
- Wordfence → Login Security → Settings.
- Find “Disable XML-RPC authentication”. Set it to OFF.
2. Allowlist the MCP route in Live Traffic
- Wordfence → Tools → Live Traffic.
- If you see blocked requests from your own
/wp-json/coworkmcp/*route, click Allow on one. - Create a permanent allowlist rule so Wordfence stops flagging them.
If you’d rather keep it locked down
Allowlist Anthropic’s published outbound range 160.79.104.0/21 under Wordfence → Tools → Allowlisted IPs. That is where Claude’s requests come from — not your own computer, so adding your home or office IP does nothing. Traffic from allowlisted IPs passes regardless of Wordfence’s other rules.
Two-factor authentication
Wordfence’s 2FA protects the wp-admin login form — and that is exactly where you approve Claude, so your 2FA applies to the approval too. After that, Claude uses the access your site issued it and never touches the login form again. Leave 2FA fully on.
