API7 Docs

MCP Tools ACL Configuration

Parameters

See plugin common configurations for configuration options available to all plugins.

  • rulesarray[object] · required

    An array of access control rules evaluated in order. The first rule whose expr conditions are all met (or that has no expr) is applied; remaining rules are skipped. Each rule must contain exactly one of allow_tools or deny_tools.

    • allow_toolsarray[string] · optional

      Allowlist of MCP tool names the consumer is permitted to call and see in tools/list. Matching is exact and case-sensitive. An empty array ([]) denies all tools.

      Exactly one of allow_tools or deny_tools must be configured per rule; they cannot be used together in the same rule.

    • deny_toolsarray[string] · optional

      Blocklist of MCP tool names the consumer is not permitted to call. Denied tools are also hidden from tools/list. Matching is exact and case-sensitive.

      Exactly one of allow_tools or deny_tools must be configured per rule; they cannot be used together in the same rule.

    • rejected_codeinteger · optional · default: 403

      Valid values: 200 to 599

      HTTP status code returned when a tools/call request is rejected by this rule.

    • rejected_msgstring · optional · default: MCP tool is not allowed

      Valid values: non-empty string

      Message returned in the response body when a tools/call request is rejected by this rule.

    • exprarray · optional

      An array of one or more matching conditions in the form of APISIX expressions. The rule is applied only when all expressions evaluate to true. If omitted, the rule matches unconditionally (catch-all).

  • max_resp_body_sizeinteger · optional · default: 67108864

    Maximum response body size in bytes buffered into memory for tool filtering. Larger responses are truncated. Available in API7 Enterprise from version 3.9.17 on the 3.9 line and from version 3.10.4 on the 3.10 line.