feat(mcp): HTTP server transport with bearer auth - #28
Merged
Merged
Conversation
Add an HTTP server mode to the Alpaca MCP CLI alongside the default stdio transport. `--http` (or `SERVER_HTTP=1`) serves the MCP Streamable-HTTP transport over node:http at `/mcp`, with stateful per-session servers built from the configured toolsets (honors ALPACA_TOOLSETS). - packages/mcp/src/http.ts: session routing + optional bearer-token guard (SERVER_HTTP_TOKEN / --token), constant-time compare, 401 on mismatch. - mcp.ts: --http/--port/--host/--token via node:util parseArgs; refuses to bind a non-loopback host without a token; SERVER_PORT/SERVER_HOST env. - Bump @modelcontextprotocol/sdk to ^1.30.0; engines.node >=20 (parseArgs). - http.test.ts: end-to-end HTTP client, auth 401/200, 404, no-session paths. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- mcp.ts: print the "ready" line on the server's 'listening' event and add an 'error' handler, so a failed bind (EADDRINUSE/EACCES) reports cleanly and exits 1 instead of throwing unhandled after already claiming readiness. - mcp.ts: treat a set-but-empty SERVER_PORT/SERVER_HOST as unset (was parsing to port 0 / an empty wildcard host); reject port < 1. - http.ts: fix stale ALPACA_HTTP reference in the header comment (it's SERVER_HTTP). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
yagop
force-pushed
the
feat/mcp-http-server
branch
from
August 22, 2026 16:51
7eb8694 to
fec8662
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds an HTTP server mode to the
alpaca-mcpCLI, alongside the existing stdio transport. This lets the MCP server be reached remotely / by multiple clients instead of only as a local stdio subprocess.npx -y @alpaca-open-api/mcp --http --port 3000 # endpoint: http://127.0.0.1:3000/mcpHow
packages/mcp/src/http.ts— serves the MCP Streamable HTTP transport overnode:http(portable across Node and Bun). Stateful sessions: aninitializePOST spins up a freshbuildServer()bound to aStreamableHTTPServerTransport, keyed by the generatedmcp-session-id; later requests reuse it. Only/mcpis served (else 404).SERVER_HTTP_TOKEN(or--token) requiresAuthorization: Bearer <token>on every request (constant-time compare,401+WWW-Authenticateon mismatch). As a safety net, the server refuses to bind a non-loopback host without a token, so the keys-bearing endpoint can't be exposed unauthenticated by accident.mcp.ts— flag parsing moved tonode:utilparseArgs(--http/--port/--host/--token,-h/-v); envSERVER_HTTP/SERVER_PORT/SERVER_HOST. HonorsALPACA_TOOLSETSper session.@modelcontextprotocol/sdkto^1.30.0;engines.node→>=20(required for stableparseArgs).stdio remains the default; nothing changes for existing stdio clients.
Config
SERVER_HTTP1/trueto serve over HTTP (same as--http)SERVER_PORT3000SERVER_HOST127.0.0.1SERVER_HTTP_TOKENTests
packages/mcp/src/http.test.tsdrives a realStreamableHTTPClientTransporton an ephemeral port: default 101-tool surface, an end-to-end tool call, 404 for other paths, no-session rejection, and auth (401 without/with wrong token, 200 + full session with the right one). Full suite: 27 pass, typecheck clean.Notes
requireBearerAuthpath) would be the move for a public multi-user deployment.docs/tool-count-256.🤖 Generated with Claude Code