Remote access in version 1.2.3

The only content command endpoint is POST /wp-json/revupnow-mcp/v1/mcp.
OAuth registration/token endpoints issue MCP credentials; they do not create WordPress login sessions.

Authentication identifies an existing WordPress user for content ownership and permissions.
class-remote-access.php restricts capabilities before setting the current user and restores the prior request identity afterward.
Administrative capabilities, unfiltered HTML, and unknown capabilities are denied, including for multisite super administrators. No roles or user capabilities are saved or elevated.

class-tool-registry.php accepts only definitions listed in class-content-tools.php, and checks authenticated context before execution. Administrative tool files are absent.
Only read_only and safe_write are supported permission modes. Legacy administrative mode values are migrated to safe_write; unknown values become read_only. Unsupported scope keys are discarded.

Local administrator actions for plugin configuration and credential management require dashboard capabilities and nonces. Remote tools cannot invoke them.

This document describes the package boundaries; it is not an independent infrastructure security assessment.
