BROKABROKA
Sign inDownload CommunityRequest a demo
MCP serverCommercial · Off until an administrator turns it on

An AI assistant, under the console’s rules.

BROKA Commercial serves the Model Context Protocol at /api/mcp, on the address the console already uses. Claude Code, Claude Desktop, Cursor or another MCP client reads your estate through it — and, once an administrator allows it, changes it — as the owner of an API token: with that person’s permissions, inside the same environment guards, on the same audit trail.

The rule the design turns on

Every tool is a call to a console route. MCP is a way to call BROKA, never a way around it.

Each tool calls the route a console screen calls, with the caller’s own token. So the permission, the environment’s write policy, the resource grants, the masking rules and the audit record that apply to a person in the console apply to the assistant unchanged.

01Connect an assistant

Off until somebody turns it on.

Settings › MCP has three modes, and an installation starts with the server off. Allowing writes asks for confirmation, because an assistant then acts with the authority of its token’s owner: what they may change, it changes. Every change of mode is recorded.

  • OffThe default. The endpoint answers 404 to everybody, as if it were not there
  • Read onlyAssistants read. Every tool that changes something is hidden, and refused if called
  • Read and writeAssistants also change things — previewed first where the console previews, refused where the token’s owner could not
Claude Code, as Settings › MCP gives it
claude mcp add --transport http broka https://<host>/api/mcp --header "Authorization: Bearer <token>"
The token

An API token from Profile › API tokens, sent as a bearer token — a console session is not accepted. It needs the mcp.use permission, held across the installation, which only the built-in Admin role has until an administrator grants it. For an AI assistant (MCP) makes a token that can do only what you tick. The same screen gives the configuration for Claude Desktop and Cursor.

Still applies
  • —A read-only environment refuses every change; a guarded one asks a reason for each
  • —Resource grants: what the token’s owner cannot see does not exist for the assistant
  • —Message contents need messages.read, and data masking rules apply to what it reads
  • —A degraded licence refuses its writes on the Commercial platforms, as it refuses the console’s
02What it reaches

Read the estate. Change what the console changes.

Tools are grouped by area, and a token sees only those it can use: none that change anything in Read only, none for a platform the installation does not serve, none whose permission its owner lacks.

Estate

Environments, connections with their health and supported features, a connection test, the global search

reads only

Kafka

Cluster health, brokers, live metrics, topics, messages, consumer groups and their lag, ACLs, quotas, transactions

changes · Create and delete topics, change configuration, add partitions, produce, reset offsets, delete groups

Schema Registry and Connect

Subjects, versions, diffs and compatibility checks; connectors, their tasks and failures

changes · Register a schema, set compatibility, soft-delete a subject; pause, resume, stop, restart and reconfigure a connector

Redis

The instance, keys and their values, a sampled analysis, diagnostics, streams and pending entries, search indexes

changes · Set, expire and delete keys; add, acknowledge and claim stream entries

RabbitMQ

The cluster, queues, exchanges and bindings — and where a routing key leads — shovels, federation, policies, stream messages

changes · Publish, purge, create and delete queues, exchanges and bindings, restart a shovel; peek at a queue, which requeues

Apache Artemis

The broker, addresses, queues and browsed messages, clients, diverts, bridges and connections, in-doubt transactions

changes · Send; purge, pause and resume a queue

Memcached

Nodes, memory and slabs, keys and their values

changes · Set and delete a key

Operations and insights

The audit trail, access review, applications, metadata; topics, groups, queues and keys worth a look

reads only

Never through MCP

These decide who may do what, or act on a whole cluster. They stay in the console whatever the mode and whatever the token holds, so an assistant acting on a token cannot widen its own reach.

Every tool, by area →
  • Users, teams, roles and grants, API tokens and sessions
  • Settings of every kind, the licence and first-run setup
  • Adding, changing or removing connections and environments, and connection credentials
  • Alerting — rules, incidents and silences, neither read nor written
  • Changing Kafka ACLs, quotas and SCRAM credentials, or users and permissions on the brokers
  • Whole-cluster operations — broker configuration, failover, rebalance, flush, record deletion
03A change you see first

Preview, plan, apply.

Where the console previews a change — a topic’s configuration, an offset reset, a schema, a connector’s configuration, a pattern delete on Redis — an assistant previews it too, and applies only what it was shown.

  • 01Preview. The change is checked with the server and nothing is written. The answer shows what would change, and a plan id.
  • 02Plan. Good for ten minutes, applied once, bound to the token that previewed it. A restart drops it — nothing was applied.
  • 03Apply. Takes only the plan id, so what is applied is what was shown — and every check runs again.
A reason for every destructive tool

Deleting a topic, a group, keys, a queue or a binding, purging a queue, stopping a connector, adding partitions, peeking at a RabbitMQ queue — each requires a reason, in every environment. A call without one is refused before its arguments are read, and the refusal is recorded.

Annotations

Every tool tells the client whether it only reads, whether it is destructive and whether a second identical call changes anything more — so a client that honours them can ask you before a destructive call.

04On the record

Every call is in the audit trail.

A tool call produces the record its console route produces, and names the channel it came through. Changes and refusals are always recorded; reads follow the installation’s read tier. In the audit log those rows carry an MCP badge, and a channel filter answers what the assistant did on Tuesday.

  • operationThe one the console route records: a topic deleted through MCP is a topic deleted
  • actorThe API token’s owner
  • channelMCP, with the tool that was called
  • clientThe assistant’s name and version, from the MCP handshake
  • tokenThe token’s prefix, never the token
  • reasonRequired on every destructive tool, and recorded with the change
Contents are data, not instructions

A message body, a key’s value, a stack trace or a label was written by somebody else. Each answer keeps it apart from BROKA’s own sentence and marks it as untrusted, and no tool runs anything a payload says: a change is always its own call, with its own arguments.

Limits
  • 60 / minTool calls per token, by default
  • 30 / minLive broker reads, from the token owner’s own allowance — the one the console draws on
  • 100Rows per page, and messages per read
  • 64 KiBPer value; a longer one is cut, and the answer says so
  • 1 MiBPer answer; past it the longest list is cut, and the answer says so
  • 60 sPer tool call, by default; a slow broker answers timed out

Wherever something is cut, the answer says what and by how much, so an assistant never mistakes part for all.

BROKA Commercial

An assistant on the estate, and on the record.

The MCP server is part of BROKA Commercial: off until an administrator turns it on, acting only as an API token’s owner, and recording every call it serves under the MCP channel.

Contact salesCommercial — join the waitlistMCP documentation →