Estate
Environments, connections with their health and supported features, a connection test, the global search
reads only
Settings › MCP has three modes, and an installation starts with the server off. Allowing writes asks for confirmation, because an assistant then acts with the authority of its token’s owner: what they may change, it changes. Every change of mode is recorded.
claude mcp add --transport http broka https://<host>/api/mcp --header "Authorization: Bearer <token>"An API token from Profile › API tokens, sent as a bearer token — a console session is not accepted. It needs the mcp.use permission, held across the installation, which only the built-in Admin role has until an administrator grants it. For an AI assistant (MCP) makes a token that can do only what you tick. The same screen gives the configuration for Claude Desktop and Cursor.
Tools are grouped by area, and a token sees only those it can use: none that change anything in Read only, none for a platform the installation does not serve, none whose permission its owner lacks.
Environments, connections with their health and supported features, a connection test, the global search
reads only
Cluster health, brokers, live metrics, topics, messages, consumer groups and their lag, ACLs, quotas, transactions
changes · Create and delete topics, change configuration, add partitions, produce, reset offsets, delete groups
Subjects, versions, diffs and compatibility checks; connectors, their tasks and failures
changes · Register a schema, set compatibility, soft-delete a subject; pause, resume, stop, restart and reconfigure a connector
The instance, keys and their values, a sampled analysis, diagnostics, streams and pending entries, search indexes
changes · Set, expire and delete keys; add, acknowledge and claim stream entries
The cluster, queues, exchanges and bindings — and where a routing key leads — shovels, federation, policies, stream messages
changes · Publish, purge, create and delete queues, exchanges and bindings, restart a shovel; peek at a queue, which requeues
The broker, addresses, queues and browsed messages, clients, diverts, bridges and connections, in-doubt transactions
changes · Send; purge, pause and resume a queue
Nodes, memory and slabs, keys and their values
changes · Set and delete a key
The audit trail, access review, applications, metadata; topics, groups, queues and keys worth a look
reads only
These decide who may do what, or act on a whole cluster. They stay in the console whatever the mode and whatever the token holds, so an assistant acting on a token cannot widen its own reach.
Every tool, by area →Where the console previews a change — a topic’s configuration, an offset reset, a schema, a connector’s configuration, a pattern delete on Redis — an assistant previews it too, and applies only what it was shown.
Deleting a topic, a group, keys, a queue or a binding, purging a queue, stopping a connector, adding partitions, peeking at a RabbitMQ queue — each requires a reason, in every environment. A call without one is refused before its arguments are read, and the refusal is recorded.
Every tool tells the client whether it only reads, whether it is destructive and whether a second identical call changes anything more — so a client that honours them can ask you before a destructive call.
A tool call produces the record its console route produces, and names the channel it came through. Changes and refusals are always recorded; reads follow the installation’s read tier. In the audit log those rows carry an MCP badge, and a channel filter answers what the assistant did on Tuesday.
A message body, a key’s value, a stack trace or a label was written by somebody else. Each answer keeps it apart from BROKA’s own sentence and marks it as untrusted, and no tool runs anything a payload says: a change is always its own call, with its own arguments.
Wherever something is cut, the answer says what and by how much, so an assistant never mistakes part for all.