Server settings
Allowed roles, rate limit, connections, undo snapshots, image search and other MCP server options.
The Server settings tab controls who may connect AI apps, how fast they may work and which safety features are on. The defaults suit most sites: only administrators can connect, every change is saved for undo, and deleting needs a confirmation.
Go to Uncoder → AI & MCP → Server settings. After changing something, a bar appears at the bottom of the screen: click Save changes, or Discard to put back the saved values.

Server
| Setting | What it does |
|---|---|
| MCP server | Turns the server on or off. When it is off, every AI request is refused. API keys and connected apps are kept. This is the same switch as Server enabled at the top of the screen. On by default. |
| Allowed roles | Which WordPress roles may connect AI apps. Administrator is always allowed. What a user can change still follows their WordPress role: an Editor who connects an app can edit pages, but not the Design System or site settings. |
| Rate limit | The most tool calls each API key or connected app may make per minute, from 10 to 2000. The default is 120. When an app goes over it, it has to wait and the call shows as Rate limited in the activity log. |
Allowed roles
Tick a role to let its users create API keys and approve AI apps. For example, allow Editor so your content team can connect Claude to write and edit pages.
Two other settings also limit what AI can do for a role:
- The permissions of each key or app (Read, Content, Design, Site). See API keys & scopes.
- Uncoder's own role setting in Settings → Access & roles. A role set to Content only can connect, but AI can only read for it. A role set to No access cannot use AI at all. See Roles & access.
Rate limit
A full site build makes many calls in a row, so the default of 120 per minute leaves room for fast work while stopping a runaway script. Raise it if an app often hits the limit during large builds.
Connections
| Setting | What it does |
|---|---|
| Dynamic client registration | Lets new OAuth apps, such as Claude and ChatGPT connectors, register themselves with your site the first time you connect them. Turn it off to allow only the apps that have already connected. On by default. |
| Allowed origins | Web addresses of browser-based AI apps that may call your site, one per line (for example https://app.example.com). Desktop apps, terminal apps and connectors are not affected. Leave it empty unless an app's documentation asks you to add its address. |
| Connection links | Accepts connection links: one address with its own key, the simplest way to connect apps such as the ChatGPT desktop app. Only keys created as links work in an address, never normal API keys or sign-ins, and only over HTTPS. Turn off to refuse every link. On by default. |
Safety

| Setting | What it does |
|---|---|
| Undo snapshots | Saves the previous state before every AI change to a page, template, popup or the Design System, so it can be undone from the activity log. On by default. Without it, AI changes cannot be undone from the log. |
| Confirm destructive actions | Tools that delete content need an explicit confirmation from the AI app. In practice, an AI has to ask you before it moves a page, post or template to the trash. On by default. |
| Image search | Lets AI apps search openly licensed photos on Openverse (opens in a new tab) and import them into your media library, with their license and credit. Turn it off if you only want your own images on the site. On by default. |
| Keep activity for | How long activity log entries are kept, from 1 to 365 days. Older entries are deleted once a day. The default is 30 days. |
Turning off Undo snapshots or Confirm destructive actions makes AI mistakes harder to fix. Keep them on unless you have a reason and a recent backup.
Turn the server off
To stop all AI access at once, for example while you investigate something, turn off Server enabled at the top of the AI & MCP screen and confirm with Turn off. Every AI app is disconnected. Keys and connected apps are kept, and they work again as soon as you click Turn on.