MCP Limits
ON THIS PAGE
OpenSolar MCP enforces per-organisation quotas so agents cannot exhaust API capacity. These limits are separate from REST API throttle limits.
Token model
MCP uses two windows:
| Window | Unit | Purpose |
|---|---|---|
| Daily | Weighted tokens | Caps productive tool usage |
| Burst | Request count | Caps short spikes |
- One
tools/callmay trigger several OpenSolar API HTTP requests, but it is charged as a single tool invocation against the daily budget. - Burst always costs 1 per throttled MCP method, regardless of tool weight or duration.
- Daily windows are fixed 24-hour epochs (not calendar midnight).
Current limits for your organisation are shown in the OpenSolar app under Control → Integrations → MCP.
Daily weighting
Each tool call uses a share of your organisation's daily MCP budget. Heavier or longer-running tools typically use more of that budget than simple reads. MCP reserves budget before the tool runs, then settles the final cost after the call completes.
Exact weights and remaining budget can change. For up-to-date values, visit Control → Integrations → MCP in the OpenSolar app, or ask the agent to read opensolar://docs/throttles.
What counts
| Activity | Daily tokens | Burst |
|---|---|---|
Successful / failed tools/call that pass preflight and reach OpenSolar API | Yes (weighted) | Yes (+1) |
| Over-limit attempts (denied) | Counted | Counted |
whoami and other burst-only local tools | No | Yes (+1) |
prompts/list, prompts/get, resources/list, resources/read | No | Yes (+1) |
initialize, ping, notifications/initialized, tools/list | No | No |
Unknown tools, insufficient scope, and missing confirm on deletes do not consume daily tokens (they fail preflight).
Over-limit responses
When a limit is exceeded, MCP returns error MCP_0012 with HTTP 429 and a Retry-After header when available.
Check remaining budget in Control → Integrations → MCP → Overview, or ask the agent to read opensolar://docs/throttles.
Best practices
- Prefer read tools and prompts for exploration before running expensive writes.
- Batch agent workflows; avoid tight loops of heavy tools (document generation, auto-design).
- Grant only the OAuth scopes you need so agents cannot invoke write/delete tools accidentally.
- Monitor usage in the MCP Overview; non-admins see only their own events.
Relationship to API throttles
Direct REST calls still use the existing per-user / per-org DRF throttles documented in Throttle Limits. MCP daily/burst budgets are enforced only on MCP tool calls and do not replace those API limits on the underlying endpoints.