Settings for evoMCP
evoMCP is configured in two places: the component options, which apply to the whole site, and the form of each connection. The names on this page are the ones you see in the English panel.
Component options
Open them under Components → evoMCP → Options (the screen title is "evoMCP: Options").
Server tab
| Setting | What it does | Default |
|---|---|---|
| Endpoint enabled | When off, /mcp answers 404 and no agent can connect. |
Yes |
| Requests per minute per connection | Applies to each connection. Accepts 10 to 6000. There is also a fixed per-IP limit of 600 requests per minute that cannot be configured. | 120 |
| Allowed origins (optional) | One origin per line, for example https://claude.ai. The site itself is always allowed. Requests without an Origin header (servers) are not affected. |
Empty |
| Email for approval alerts | Whenever an agent leaves an action pending approval, this address is notified. If empty, the site email is used. | Empty |
| Audit retention (days) | After this period, entries are deleted automatically. Accepts 7 to 3650. | 90 |
System operations tab
| Setting | What it does | Default |
|---|---|---|
| Advanced layer (SQL and files) | Lets connections with "full" permission on the "advanced" component query and change the database and the allowed files. The plugin "evoMCP - Advanced layer" must also be enabled. Anything that changes data requires human approval. | No |
| Hosts allowed for installing | One host per line or comma separated; supports *.domain. Added to the hosts of the update sites already installed. HTTPS only and public hosts only. |
Empty |
License tab
Shows the licence status. The Download ID goes into Joomla's update site, in the "Download Key" field. The details are in Licences and updates.
Permissions tab
This is Joomla's standard permissions tab for the component (administer, manage, create, edit, delete).
The Server tab also carries a note linking to the connection guide, under Components → evoMCP → Connect.
Connection settings
You edit them under Components → evoMCP → Connections → New connection or Edit connection.
| Setting | What it does | Default |
|---|---|---|
| Name | Identifies the connection in the panel and on the OAuth consent screen. Required. | |
| Description | Free text. | Empty |
| Joomla user | Tools run with this user's identity and permissions. The connection can never do more than the user can. Required. | |
| Expires on | Date after which the connection stops working. | No expiry |
| Monthly call quota | Cap on calls per month. Once reached, the connection gets a 429 error until the next month. At 80% an email alert is sent, once a month. | No limit |
| Allowed IPs (one per line) | If any are set, the connection only works from those addresses. | Empty (any) |
| Human approval | See the table of modes below. | Every write needs approval (recommended) |
| Permissions by component | Level for each area and, where needed, for each resource. | Content set to Read; everything else None |
Permission levels
| Level | What it allows |
|---|---|
| None | Nothing. The area's tools are not even listed. |
| Read | Read tools. |
| Write | Create, change and delete, without being able to read. |
| Full | Read and write. |
| Inherit from area | For a resource: uses the area's level. |
Permissions can only narrow what the Joomla user is already allowed to do. A tool outside the connection's permissions is indistinguishable from one that does not exist.
Only a Super User can grant the administration areas: users, extensions, configuration, system, the advanced layer and the generic entities. Someone who edits a connection without being a Super User cannot bind it to another Super User.
Human approval modes
| Mode | What happens |
|---|---|
| Every write needs approval (recommended) | Any write tool is held until an administrator approves it. |
| Only destructive or sensitive actions | Tools flagged as destructive or sensitive ask for approval; other writes run. |
| No approval (except actions flagged as sensitive) | Ordinary writes run without approval. Actions that always require it still do. |
The approved action runs as the connection's Joomla user. Actions on users and extensions always need approval. The reference has a column that says, tool by tool, when approval is requested.
Approving actions on users, extensions, configuration, system, the advanced layer and generic entities requires a Super User.
Other actions on a connection
- Revoke: the token stops working at once. You can reactivate it.
- Regenerate token: the previous one stops working and the client must be updated.
- Delete: the connection disappears and the audit log is kept.
- Revoke access for an application connected through OAuth, from the "Connected applications (OAuth)" section of the connection.
Fixed values
These values cannot be configured:
| Value | Amount |
|---|---|
| Maximum request size | 256 KB |
| Maximum response size | 1 MB |
| Pending approvals per connection | 50 |
| Lifetime of a pending approval | 24 hours |
| Lifetime of the OAuth authorisation code | 10 minutes |
| Lifetime of the OAuth access token | 1 hour |
| Lifetime of the OAuth refresh token | 30 days |