# Settings for evoMCP

> The evoMCP component options, the settings of each connection, approval modes, limits and default values, named as they appear in the English panel.

# Settings for evoMCP

evoMCP is configured in two places: the component options, which apply to the whole site, and the form of each connection. The names on this page are the ones you see in the English panel.

## Component options

Open them under Components → evoMCP → Options (the screen title is "evoMCP: Options").

### Server tab

| Setting | What it does | Default |
| --- | --- | --- |
| Endpoint enabled | When off, `/mcp` answers 404 and no agent can connect. | Yes |
| Requests per minute per connection | Applies to each connection. Accepts 10 to 6000. There is also a fixed per-IP limit of 600 requests per minute that cannot be configured. | 120 |
| Allowed origins (optional) | One origin per line, for example `https://claude.ai`. The site itself is always allowed. Requests without an Origin header (servers) are not affected. | Empty |
| Email for approval alerts | Whenever an agent leaves an action pending approval, this address is notified. If empty, the site email is used. | Empty |
| Audit retention (days) | After this period, entries are deleted automatically. Accepts 7 to 3650. | 90 |

### System operations tab

| Setting | What it does | Default |
| --- | --- | --- |
| Advanced layer (SQL and files) | Lets connections with "full" permission on the "advanced" component query and change the database and the allowed files. The plugin "evoMCP - Advanced layer" must also be enabled. Anything that changes data requires human approval. | No |
| Hosts allowed for installing | One host per line or comma separated; supports `*.domain`. Added to the hosts of the update sites already installed. HTTPS only and public hosts only. | Empty |

### License tab

Shows the licence status. The Download ID goes into Joomla's update site, in the "Download Key" field. The details are in [Licences and updates](https://evoaddons.com/en/documentation/licences-and-updates).

### Permissions tab

This is Joomla's standard permissions tab for the component (administer, manage, create, edit, delete).

The Server tab also carries a note linking to the connection guide, under Components → evoMCP → Connect.

## Connection settings

You edit them under Components → evoMCP → Connections → New connection or Edit connection.

| Setting | What it does | Default |
| --- | --- | --- |
| Name | Identifies the connection in the panel and on the OAuth consent screen. Required. |  |
| Description | Free text. | Empty |
| Joomla user | Tools run with this user's identity and permissions. The connection can never do more than the user can. Required. |  |
| Expires on | Date after which the connection stops working. | No expiry |
| Monthly call quota | Cap on calls per month. Once reached, the connection gets a 429 error until the next month. At 80% an email alert is sent, once a month. | No limit |
| Allowed IPs (one per line) | If any are set, the connection only works from those addresses. | Empty (any) |
| Human approval | See the table of modes below. | Every write needs approval (recommended) |
| Permissions by component | Level for each area and, where needed, for each resource. | Content set to Read; everything else None |

### Permission levels

| Level | What it allows |
| --- | --- |
| None | Nothing. The area's tools are not even listed. |
| Read | Read tools. |
| Write | Create, change and delete, without being able to read. |
| Full | Read and write. |
| Inherit from area | For a resource: uses the area's level. |

Permissions can only narrow what the Joomla user is already allowed to do. A tool outside the connection's permissions is indistinguishable from one that does not exist.

Only a Super User can grant the administration areas: users, extensions, configuration, system, the advanced layer and the generic entities. Someone who edits a connection without being a Super User cannot bind it to another Super User.

### Human approval modes

| Mode | What happens |
| --- | --- |
| Every write needs approval (recommended) | Any write tool is held until an administrator approves it. |
| Only destructive or sensitive actions | Tools flagged as destructive or sensitive ask for approval; other writes run. |
| No approval (except actions flagged as sensitive) | Ordinary writes run without approval. Actions that always require it still do. |

The approved action runs as the connection's Joomla user. Actions on users and extensions always need approval. The [reference](https://evoaddons.com/en/documentation/evomcp-reference) has a column that says, tool by tool, when approval is requested.

Approving actions on users, extensions, configuration, system, the advanced layer and generic entities requires a Super User.

### Other actions on a connection

- Revoke: the token stops working at once. You can reactivate it.
- Regenerate token: the previous one stops working and the client must be updated.
- Delete: the connection disappears and the audit log is kept.
- Revoke access for an application connected through OAuth, from the "Connected applications (OAuth)" section of the connection.

## Fixed values

These values cannot be configured:

| Value | Amount |
| --- | --- |
| Maximum request size | 256 KB |
| Maximum response size | 1 MB |
| Pending approvals per connection | 50 |
| Lifetime of a pending approval | 24 hours |
| Lifetime of the OAuth authorisation code | 10 minutes |
| Lifetime of the OAuth access token | 1 hour |
| Lifetime of the OAuth refresh token | 30 days |

---

https://evoaddons.com/en/documentation/evomcp-settings
