Skip to main content

Parameters

See plugin common configurations for configuration options available to all plugins.

  • rules

    array[object]

    required


    An array of access control rules evaluated in order. The first rule whose expr conditions are all met (or that has no expr) is applied; remaining rules are skipped. Each rule must contain exactly one of allow_tools or deny_tools.

    • allow_tools

      array[string]


      Allowlist of MCP tool names the consumer is permitted to call and see in tools/list. Matching is exact and case-sensitive. An empty array ([]) denies all tools.

      Exactly one of allow_tools or deny_tools must be configured per rule; they cannot be used together in the same rule.

    • deny_tools

      array[string]


      Blocklist of MCP tool names the consumer is not permitted to call. Denied tools are also hidden from tools/list. Matching is exact and case-sensitive.

      Exactly one of allow_tools or deny_tools must be configured per rule; they cannot be used together in the same rule.

    • rejected_code

      integer

      default: 403

      vaild vaule:

      200 to 599


      HTTP status code returned when a tools/call request is rejected by this rule.

    • rejected_msg

      string

      default: MCP tool is not allowed

      vaild vaule:

      non-empty string


      Message returned in the response body when a tools/call request is rejected by this rule.

    • expr

      array


      An array of one or more matching conditions in the form of APISIX expressions. The rule is applied only when all expressions evaluate to true. If omitted, the rule matches unconditionally (catch-all).

  • max_resp_body_size

    integer

    default: 67108864


    Maximum response body size in bytes buffered into memory for tool filtering. Larger responses are truncated. Available in API7 Enterprise from version 3.9.17 on the 3.9 line and from version 3.10.4 on the 3.10 line.