Urgent.News

What's breaking now, across thousands of outlets.

Tech

The remote MCP client config matrix nobody documents (and the three ways type fails silently)

The remote MCP client config matrix nobody documents (and the three ways type fails silently) I maintain a remote MCP server that authenticates with a static Authorization: Bearer header. No OAuth, no device flow, no browser handoff. That is the boring case, and it turned out to be the one where every client has its own opinion. Over a month of connecting the same endpoint to Cursor, Windsurf,…

The author maintains a remote MCP server that uses a static Authorization: Bearer header for authentication. They discovered that different clients have their own way of handling the JSON Transport configuration. The author tested the same endpoint with seven clients and found that the same HTTP transport has four different names. The interesting part is not that the names differ, but that a wrong name fails in three completely different ways.

1. The first way is the endpoint being inaccessible due to transport issues like wrong path, type, proxy, or a client-side bridge eating the request. The client response is not a 200.

2. The second way is when the client treats the request as stdio and omits the type. This can cause clients to either not launch anything or report a spawn failure. The config might look correct, but the error message will point at a nonexistent process. The URL is never dialed.

3. The third way is the most problematic. The client negotiates SSE instead of streamable HTTP, and if the server doesn't support SSE, it will answer 405 or the client will fall back until something half-works. This results in a 401 response on the first call.

The author advises testing the calling path and ensuring that the transport field is validated against a closed set by the client.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Streaks lie. A photo of the minute doesn't.

You have kept a streak before. Somewhere around day nine you started logging the habit after the fact — the tap standing in for the thing itself — and by day twenty the only part still alive was the…

  • One Minute Magic tracks habits in three 60-second tasks
  • Photograph serves as evidence of completed tasks
  • App emphasizes simplicity and transparency

Trusted Timestamps (RFC 3161): How to Anchor a Hash Chain So No One Can Rewrite the Past

A hash chain proves a record was not modified after it was written. It does not prove when it was written, and it does nothing against someone who controls the server and can re-sign the whole chain.

  • Trusted Timestamps (RFC 3161) solve hash chain limitations
  • Time Stamp Authority (TSA) vouches for hash existence at specific time
  • Two anchoring strategies: per-record stamping vs periodic chain-head stamping

More from Sunday 11 October →