Skip to content
RankX AI
RankX AI Docs
Integrations

Integrations

What RankX AI connects to, what each connection gives you, and the rules every write obeys. The safeguards are named by platform.

RankX AI connects to two kinds of system. WordPress, WooCommerce and Shopify are read and write: RankX AI can read your content, propose changes and apply them, with every write verified by reading the object back. Google Search Console, Google Analytics and Bing Webmaster Tools feed the Traffic section, and RankX AI also announces each article it publishes live to Bing.

Everything else runs on RankX AI's own measurement, so a Website with no integrations at all still gets AI visibility, rank tracking, AI Shopping, audits and AI Readiness.

What each connection gives you

ConnectionDirectionWhat it gives you
WordPressRead and writeOne-click connection, publishing Content Studio articles, updating pages, SEO metadata, structured data, redirects, media and alt text, taxonomies, and applying fixes from the Tasks board
WooCommerceRead and write, narrowlyProduct listings, thin-description detection, and description and SEO rewrites
ShopifyRead and write, narrowlyProducts nobody can see, SEO and alt-text gaps, choosing the products AI Shopping monitors, Content Studio articles on your Shopify blog, and writes to search metadata, image alt text, redirects and description bodies
Google Search ConsoleRead onlyClicks, impressions, position and index coverage in the Traffic section
Google AnalyticsRead onlySessions, page views, landing pages and realtime visitors
Bing Webmaster ToolsRead, plus URL submissionWeekly clicks, impressions and position, the pages Bing cannot read, keyword ideas, and live URLs announced to Bing when you publish

The rules every write obeys

WordPress, WooCommerce and Shopify are the only places RankX AI changes your site or store, so the guarantees are worth reading before you connect. They apply on every one of them.

Every write is verified by reading the object back and comparing it, never by a 2xx response. Plugins and platforms that return success while persisting nothing are common enough that a status code proves nothing. A write RankX AI cannot confirm is reported as unverified, never as success.

A write starts from a fresh reading, never a cached one. The object is read immediately beforehand, from the site or store itself. A change built on stale bytes silently undoes everything that happened since, and it is the one failure verification cannot catch, because the object then matches exactly what was sent.

Every write can be refused before it is attempted. Pages built by a page builder that stores content outside the page body are listed as not writable, and a body write to one is refused rather than attempted and half-applied. There is no override for that from the MCP server, ever.

Nothing you send is discarded. A body the converter cannot map to native blocks is preserved verbatim in a raw HTML block and reported, rather than dropped with a warning.

Every edit defaults to a dry run. You get the exact before and after first, and applying it is a second, explicit call. Publishing a Content Studio article is the exception, and approval stands in for the dry run: the article must be approved first, and you choose outright whether it is saved as a draft, scheduled or published.

What stays under your control

RankX AI keeps these actions with you by design, so no connection, assistant or token can reach them. Each one names the platform it applies to, because a safeguard on one platform is not a safeguard on all of them:

  • No user writes at all, on WordPress. RankX AI cannot create, change or delete a user, and never creates an application password itself: the only one it holds is the one WordPress issues when you approve the connection, or the one you paste in.
  • No plugin or theme install, activation or update, on WordPress. It can read what is installed and nothing more.
  • No redirect it cannot read back. On WordPress, RankX AI adds a redirect only through a redirect manager it can check (the Redirection plugin, Rank Math or the RankX AI plugin), and only for an address that is genuinely missing. With none of them installed it says so and names the fix rather than writing something unverifiable. On Shopify, redirects are a first-class readable object and RankX AI creates them there. See Shopify.
  • Social metadata stays yours, on every site and store. RankX AI writes the SEO title and meta description that search engines and assistants read; Open Graph and Twitter fields stay exactly as your SEO plugin or theme sets them, and a request to change them is refused.
  • No order, customer or refund writes in WooCommerce. Those are reads only, and there is no write function to call.
  • No permanent deletion, on WordPress. Removing a post moves it to the trash, where you can restore it. There is no flag that changes this.
  • Undo on Shopify comes from RankX AI's own record. Shopify keeps no version history for products, collections, pages or articles, so RankX AI records the previous value before every change so it can be put back, and refuses any change whose current value it could not read first.
  • No theme writes on Shopify. Writing a theme file needs a Shopify permission that additionally requires an exemption Shopify grants separately, so RankX AI does not ask for it, and connecting a store never depends on one.

Google Search Console and Google Analytics

Both connections are read-only, authorised with OAuth, and scoped to reading: Search Console performance and index data, and Analytics traffic data. RankX AI never writes to either.

Two behaviours matter more than the setup:

Search Console publishes on a two to three day delay at source. The last day or two being absent is a healthy connection reporting honestly, and RankX AI marks those days provisional rather than plotting a decline.

Both refuse rather than reporting zero. A connection is in one of four states and only one of them yields figures. See why traffic data is missing for all four, and troubleshooting connections for what to do about each.

Reconnecting keeps your history. If Google asks for either connection to be authorised again, the Website shows Reconnect required, and reconnecting restores the data with nothing lost. Traffic covers connecting both services.

Driving integrations from an assistant

Everything on this page is also reachable over the MCP server, which is how most of it is used in practice: describing a site, listing content, patching a page, uploading media with alt text, and reading Search Console and Analytics.

The MCP surface carries the same rules, and adds one. WordPress and Shopify tools sit behind their own scopes rather than the general write scope, so a token issued before those tools existed reaches none of them. Scopes are fixed when a token is issued, so the alternative would have granted a capability nobody agreed to and which could not be withdrawn. See MCP authentication.

Every Shopify tool needs the same scope, including the three that only read. A token granted read access alone cannot reach a Shopify store at all, because a token that can page a whole catalogue using your stored credential is not a read in the ordinary sense.

Where to go next

Last updated