How to Enable
ON THIS PAGE
MCP access requires organisation entitlement, a per-user role permission, and (for almost all tools) Raw Data API Access. Complete the steps below before connecting an MCP host.
1. Enable MCP Access
MCP Access is an OpenSolar service. Organisation admins enable it from the OpenSolar app:
- Navigate to Control → Integrations → Integrations & Services → MCP Access
- Enable MCP Access for your organisation
Once active, the Control → Integrations → MCP menu appears. From there you can review OAuth sessions and usage.
Without MCP Access, OAuth consent and introspection fail with an MCP access required error.
2. Grant the role permission
Per-user access is controlled by the MCP Access role permission (View):
- Navigate to Control → Company → Team → Custom Roles
- Edit the permissions role for users who should connect MCP
- Enable MCP Access (view)
The Admin role template includes this permission by default. Other templates do not.
Users without the permission can authenticate to OpenSolar but cannot obtain an active MCP grant.
3. Enable Raw Data API Access
Every MCP tool that calls OpenSolar API — that is, all tools except whoami — requires the organisation to have Raw Data API Access.
- Navigate to Control → Integrations → Integrations & Services
- Enable Raw Data API Access
- Ensure sufficient wallet balance for per-project charges
Without Raw Data API Access, OAuth can still succeed, but tool calls return MCP_0011 with recovery guidance. See API Access Plans and API Access FAQs.
If you already have Raw Data API Access for REST integrations, no extra service is required for MCP beyond MCP Access.
4. Connect your MCP host
After entitlement and permissions are in place:
- Add the production MCP URL in your host (see Connect with Clients)
- Complete OAuth login on the OpenSolar login page
- Select your organisation (if you belong to more than one) and consent scopes: READ, WRITE, and/or DELETE
Checklist
| Requirement | Where to configure | Required for |
|---|---|---|
| MCP Access | Control → Integrations → Integrations & Services → MCP Access | Connecting MCP at all |
Role permission MCP Access (view) | Control → Company → Team → Custom Roles | User-level connect/use |
| OAuth scopes | Consent screen during login | Tool invoke by scope |
| Raw Data API Access | Control → Integrations → Integrations & Services | All tools except whoami |
Managing sessions
Organisation admins can list and revoke MCP OAuth sessions under Control → Integrations → MCP. Each row shows the authorised user and granted scopes (READ / WRITE / DELETE). Non-admin pros see only sessions they authorised.