Repository navigation
feat(mcp): serve MCP over Streamable HTTP with of mcp --http - #55
Merged
Merged
Conversation
`of mcp` only spoke stdio, so agents on other machines couldn't reach it. `--http [port]` serves stateless Streamable HTTP at http://127.0.0.1:<port>/mcp (default 3939), building a fresh McpServer per request so concurrent clients stay isolated. It binds to loopback only and accepts loopback Host names plus any `--allow-host` names, compared as host[:port] authorities, so a local browser can't reach it through DNS rebinding while a proxy such as `tailscale serve` can. Paths are matched without URL parsing so a malformed request target can't throw, and at most 16 requests run at once, since tool calls finish even after a client disconnects. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Merged
stephendolan
added a commit
that referenced
this pull request
Oct 7, 2026
Minor release: `of mcp --http` serves the MCP server over Streamable HTTP on loopback, with a Host allowlist for publishing it through a proxy such as `tailscale serve` (#55). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
of mcponly spoke stdio, so agents on other machines couldn't reach it.of mcp --http [port]serves stateless Streamable HTTP athttp://127.0.0.1:<port>/mcp(default 3939), building a freshMcpServerper request so concurrent clients stay isolated. Tool registration moves intocreateMcpServer()for that; the rest ofserver.tsis indentation.It binds to loopback only. The Host allowlist (loopback names plus
--allow-host) blocks DNS rebinding from local browsers while letting a reverse proxy through, so publishing it on a tailnet is:An adversarial Codex review found a request target like
POST //[crashed the process through a synchronousnew URL(); paths are now matched without URL parsing. It also flagged unbounded concurrent tool runs (now capped at 16 with 503 +Retry-After) and loose Host parsing (now stricthost[:port], normalized on both sides). Tool calls still run to completion if a client disconnects.Bun's HTTP server never reports a client that disconnects mid-request, so the cap test runs the built CLI under Node, the shipped runtime; it fails if the slot isn't released. The official MCP client completes initialize,
tools/list, and tool calls throughtailscale serve.🤖 Generated with Claude Code