Skip to main content

evoMCP or a custom API and SQL access

When each approach fits

A custom API and SQL access (calls to Joomla's REST API, direct database queries, scripts of your own) fits when the task is specific and repeatable, your technical team runs it, and you want to control every line. It also fits when you need something so particular that no general tool covers it. Joomla's REST API is a solid base for simple integrations.

evoMCP fits when the one operating is an AI assistant that decides what to do and you want rules around it: what it may touch, what needs a person, what gets recorded. The assistant connects over the MCP standard, so you do not have to write a client for each task.

Comparison

Criterion evoMCP Custom API and SQL
Getting started Install the package, create a connection and connect the assistant with a token or OAuth 2.1. You write, test and host the scripts and manage the tokens.
Data stored The audit of every call (retention configurable, 90 days by default), usage per connection and approvals. Whatever you choose to log.
Permissions A per-component matrix (none, read, write, full) that never exceeds what the Joomla user can do in the administrator. Those of the token or database account you use; tightening them is up to you.
Human approval Built in: writes are held pending and reviewed with the exact arguments. You build it, if you want it.
Audit A hash chain that detects edits or deletions of the log. Whatever you implement.
Maintenance Extension updates with the licence. You maintain it whenever Joomla or YOOtheme changes.
Control Predefined tools: Joomla entities, YOOtheme, system and, optionally, SQL and files. Total: you can do exactly what you program.
Licence cost One-off payment with 12 months of updates; see pricing. No licence; the cost is development and maintenance.
Limits See below. Those of what you program. Direct SQL bypasses Joomla's logic (forms, ACL, workflow) unless you replicate it.

What evoMCP does not do

  • It does not update Joomla core, and it does not update itself from the assistant.
  • It does not touch credentials, sessions or component permissions (rules), and the SQL layer cannot read credential or session tables, or evoMCP's own.
  • It has no tools for the YOOtheme builder library or page templates.
  • Anything that changes the site may be held for a person; if you want a fully automatic process, the "no approval" mode exists but is not the recommended one.
  • The advanced SQL and files layer ships disabled and takes three locks to switch on.
  • System tools are for super users only.
  • It does not decide for you: the quality of what the assistant does depends on the assistant and on whoever reviews it.

If a custom access suits you, evoMCP does not get in the way: Joomla's REST API is still there. More detail: evoMCP page, reference and the agency use case.

Related products