Skip to main content

MCP Limits

OpenSolar MCP enforces per-organisation quotas so agents cannot exhaust API capacity. These limits are separate from REST API throttle limits.

Token model​

MCP uses two windows:

WindowUnitPurpose
DailyWeighted tokensCaps productive tool usage
BurstRequest countCaps short spikes
  • One tools/call may trigger several OpenSolar API HTTP requests, but it is charged as a single tool invocation against the daily budget.
  • Burst always costs 1 per throttled MCP method, regardless of tool weight or duration.
  • Daily windows are fixed 24-hour epochs (not calendar midnight).

Current limits for your organisation are shown in the OpenSolar app under Control → Integrations → MCP.

Daily weighting​

Each tool call uses a share of your organisation's daily MCP budget. Heavier or longer-running tools typically use more of that budget than simple reads. MCP reserves budget before the tool runs, then settles the final cost after the call completes.

Exact weights and remaining budget can change. For up-to-date values, visit Control → Integrations → MCP in the OpenSolar app, or ask the agent to read opensolar://docs/throttles.

What counts​

ActivityDaily tokensBurst
Successful / failed tools/call that pass preflight and reach OpenSolar APIYes (weighted)Yes (+1)
Over-limit attempts (denied)CountedCounted
whoami and other burst-only local toolsNoYes (+1)
prompts/list, prompts/get, resources/list, resources/readNoYes (+1)
initialize, ping, notifications/initialized, tools/listNoNo

Unknown tools, insufficient scope, and missing confirm on deletes do not consume daily tokens (they fail preflight).

Over-limit responses​

When a limit is exceeded, MCP returns error MCP_0012 with HTTP 429 and a Retry-After header when available.

tip

Check remaining budget in Control → Integrations → MCP → Overview, or ask the agent to read opensolar://docs/throttles.

Best practices​

  • Prefer read tools and prompts for exploration before running expensive writes.
  • Batch agent workflows; avoid tight loops of heavy tools (document generation, auto-design).
  • Grant only the OAuth scopes you need so agents cannot invoke write/delete tools accidentally.
  • Monitor usage in the MCP Overview; non-admins see only their own events.

Relationship to API throttles​

Direct REST calls still use the existing per-user / per-org DRF throttles documented in Throttle Limits. MCP daily/burst budgets are enforced only on MCP tool calls and do not replace those API limits on the underlying endpoints.