01Bearer token authentication with optional IP allow-listing and CORS origin control
02Configurable rate limiting for inbound requests
03JSON-RPC 2.0 endpoint accessible on both site and administrator contexts
04Response caching via Joomla's cache layer
050 GitHub stars
06JSON Schema validation for tool inputs