Skip to main content

Settings for evoMCP

evoMCP is configured in two places: the component options, which apply to the whole site, and the form of each connection. The names on this page are the ones you see in the English panel.

Component options

Open them under Components → evoMCP → Options (the screen title is "evoMCP: Options").

Server tab

Setting What it does Default
Endpoint enabled When off, /mcp answers 404 and no agent can connect. Yes
Requests per minute per connection Applies to each connection. Accepts 10 to 6000. There is also a fixed per-IP limit of 600 requests per minute that cannot be configured. 120
Allowed origins (optional) One origin per line, for example https://claude.ai. The site itself is always allowed. Requests without an Origin header (servers) are not affected. Empty
Email for approval alerts Whenever an agent leaves an action pending approval, this address is notified. If empty, the site email is used. Empty
Audit retention (days) After this period, entries are deleted automatically. Accepts 7 to 3650. 90

System operations tab

Setting What it does Default
Advanced layer (SQL and files) Lets connections with "full" permission on the "advanced" component query and change the database and the allowed files. The plugin "evoMCP - Advanced layer" must also be enabled. Anything that changes data requires human approval. No
Hosts allowed for installing One host per line or comma separated; supports *.domain. Added to the hosts of the update sites already installed. HTTPS only and public hosts only. Empty

License tab

Shows the licence status. The Download ID goes into Joomla's update site, in the "Download Key" field. The details are in Licences and updates.

Permissions tab

This is Joomla's standard permissions tab for the component (administer, manage, create, edit, delete).

The Server tab also carries a note linking to the connection guide, under Components → evoMCP → Connect.

Connection settings

You edit them under Components → evoMCP → Connections → New connection or Edit connection.

Setting What it does Default
Name Identifies the connection in the panel and on the OAuth consent screen. Required.
Description Free text. Empty
Joomla user Tools run with this user's identity and permissions. The connection can never do more than the user can. Required.
Expires on Date after which the connection stops working. No expiry
Monthly call quota Cap on calls per month. Once reached, the connection gets a 429 error until the next month. At 80% an email alert is sent, once a month. No limit
Allowed IPs (one per line) If any are set, the connection only works from those addresses. Empty (any)
Human approval See the table of modes below. Every write needs approval (recommended)
Permissions by component Level for each area and, where needed, for each resource. Content set to Read; everything else None

Permission levels

Level What it allows
None Nothing. The area's tools are not even listed.
Read Read tools.
Write Create, change and delete, without being able to read.
Full Read and write.
Inherit from area For a resource: uses the area's level.

Permissions can only narrow what the Joomla user is already allowed to do. A tool outside the connection's permissions is indistinguishable from one that does not exist.

Only a Super User can grant the administration areas: users, extensions, configuration, system, the advanced layer and the generic entities. Someone who edits a connection without being a Super User cannot bind it to another Super User.

Human approval modes

Mode What happens
Every write needs approval (recommended) Any write tool is held until an administrator approves it.
Only destructive or sensitive actions Tools flagged as destructive or sensitive ask for approval; other writes run.
No approval (except actions flagged as sensitive) Ordinary writes run without approval. Actions that always require it still do.

The approved action runs as the connection's Joomla user. Actions on users and extensions always need approval. The reference has a column that says, tool by tool, when approval is requested.

Approving actions on users, extensions, configuration, system, the advanced layer and generic entities requires a Super User.

Other actions on a connection

  • Revoke: the token stops working at once. You can reactivate it.
  • Regenerate token: the previous one stops working and the client must be updated.
  • Delete: the connection disappears and the audit log is kept.
  • Revoke access for an application connected through OAuth, from the "Connected applications (OAuth)" section of the connection.

Fixed values

These values cannot be configured:

Value Amount
Maximum request size 256 KB
Maximum response size 1 MB
Pending approvals per connection 50
Lifetime of a pending approval 24 hours
Lifetime of the OAuth authorisation code 10 minutes
Lifetime of the OAuth access token 1 hour
Lifetime of the OAuth refresh token 30 days