AI agents can now create and edit content on our Drupal 11 site. They connect through MCP (Model Context Protocol), a standard way for AI tools to call a system. We built it on contrib modules.
The real work is deciding what an agent may touch:
- One role with the privileges.
- Landing pages and product pages stay in editorial workflow. The agent can't reach them at all.
- The agent gets 10 write tools. Delete is off.
- Sign-in uses OAuth with PKCE, a check that stops a stolen sign-in code from being used. Access tokens last one hour.
Two config traps nearly opened more than we meant:
- A tool with no setting of its own is on by default. Without an explicit "off" for delete, all 11 tools would have gone live.
- The roles setting on the MCP plugin looked like the gate, but it did nothing. The real gate is the route permission.
Then we tried to break it. We tried to delete content, and to edit a landing page, a product, a user and a media item. Every attempt was refused.
You'll get a checklist for opening your own Drupal site to AI agents.
For: developers, architects and site owners who are thinking about MCP.