Adds opt-in URL authentication to the Site Agent MCP endpoint for compatible clients that cannot send custom Authorization headers.
Enable URL authentication under Tools > Site Agent, save, then use the converter's new Copy authenticated endpoint button. The URL's auth query parameter contains Base64-encoded username and Application Password credentials. Standard and URL-safe Base64 are accepted; the copy action handles URL encoding and existing plain-permalink query parameters.
Authentication uses WordPress's native Application Password validator on every request. Administrator and enabled-tool checks remain enforced; account passwords, invalid/revoked credentials, conflicting identities and unrelated REST routes are rejected. The mode defaults off, respects emergency disable and HTTPS requirements, and marks MCP responses private/no-store.
Base64 is reversible. Credential-bearing URLs may appear in browser history, proxy/server logs or client configuration. Use a dedicated, revocable Application Password and keep the complete URL private. The client must support Streamable HTTP/MCP and preserve the query on each request. This is not an OAuth implementation or a guarantee of compatibility with every client.
Validation: 33 WordPress integration tests / 144 assertions, 7 converter tests, real headerless local HTTP initialization and tool discovery, route isolation, invalid-credential rejection, cache headers, session termination, coding standards and package checks.