Two configuration areas
AI Providers — **Path:**T3AF > AI Providers. API keys, models, and defaults. AI Features — **Path:**T3AF > AI Features. Per-site cards for connected extensions. AI Foundation’s own card is Access & Notifications (Basic Auth and quota email alerts). MCP options are on T3AF > MCP Server > Advanced.
enableMcpServer). Prefer T3AF > MCP Server > Advanced for MCP options. These keys live in T3AF settings, not the classic TYPO3 Admin Tools > Settings > Extension Configuration form.
Minimum working setup
- One AI provider with a valid key and model
- Test connection passes
- Provider marked Default
- (Optional) DeepL or Google keys for translation APIs
- (Optional) MCP enabled if you use AI agents
AI Providers (primary)
**Path:**T3AF > AI Providers Connect at least one provider, set a model, run Test connection, and mark exactly one row as Default. Full field reference: Provider fields. Guide: AI ProvidersExtension settings
T3AF stores translation helpers, Basic Auth, notifications, and MCP switches in extension settings (includingenableMcpServer). Prefer T3AF > MCP Server > Advanced for MCP options.
Where a classic Extension Configuration form is still used for optional keys, open Admin Tools > Settings > Extension Configuration and select ns_t3af.
Translation (optional)
deepl_api_key— DeepL translationgoogle_api_key— Google translationdefaultModelForTranslation— Default translation model
OpenAI usage statistics (optional)
openai_admin_api_key— Organization usage charts (not the chat API key)
HTTP Basic Auth (optional)

basicAuthEnabled— Enable helperbasicAuthUsername— UsernamebasicAuthPassword— Password
MCP Server
enableMcpServer— Master switch (default: on)mcpBasePath— HTTP endpoint (default:/mcp)requireAuth— Require login (default: on)accessTokenLifetime— OAuth token TTL
Per-feature providers
**Path:**T3AF > AI Features Override the default provider per task: SEO, Pages, Content, Translation. See AI Features.AI Label
Path: T3AF > AI Label Record, confirm, and disclose AI-generated or AI-modified content for EU AI Act Article 50 workflows. Covers module tabs, settings, visitor labels, bulk actions, and evidence export. Full guide: AI LabelSecurity checklist
- Limit backend admin access
- Use HTTPS in production
- Rotate API keys every 90 days
- Enable AI Permissions for large teams
- Never store keys in Git or email
When to reconfigure
- After key rotation — run Test connection again
- When adding a new child extension — check AI Features
- Before enabling MCP in production — read MCP Server security section
- After license renewal — confirm the extension license is still valid