{
  "id": 13740016,
  "title": "The remote MCP client config matrix nobody documents (and the three ways type fails silently)",
  "url": "https://urgent.news/2026/10/11/the-remote-mcp-client-config-matrix-nobody-documents-and-the-three",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-11T15:13:09.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/turingcorp/the-remote-mcp-client-config-matrix-nobody-documents-and-the-three-ways-type-fails-silently-1chg"
  },
  "original_language": "en",
  "account": "The author maintains a remote MCP server that uses a static Authorization: Bearer header for authentication. They discovered that different clients have their own way of handling the JSON Transport configuration. The author tested the same endpoint with seven clients and found that the same HTTP transport has four different names. The interesting part is not that the names differ, but that a wrong name fails in three completely different ways.\n\n1. The first way is the endpoint being inaccessible due to transport issues like wrong path, type, proxy, or a client-side bridge eating the request. The client response is not a 200.\n2. The second way is when the client treats the request as stdio and omits the type. This can cause clients to either not launch anything or report a spawn failure. The config might look correct, but the error message will point at a nonexistent process. The URL is never dialed.\n3. The third way is the most problematic. The client negotiates SSE instead of streamable HTTP, and if the server doesn't support SSE, it will answer 405 or the client will fall back until something half-works. This results in a 401 response on the first call.\n\nThe author advises testing the calling path and ensuring that the transport field is validated against a closed set by the client.",
  "summary": "The remote MCP client config matrix nobody documents (and the three ways type fails silently) I maintain a remote MCP server that authenticates with a static Authorization: Bearer header. No OAuth, no device flow, no browser handoff. That is the boring case, and it turned out to be the one where every client has its own opinion. Over a month of connecting the same endpoint to Cursor, Windsurf,…",
  "key_points": [
    "Different clients handle JSON Transport configuration uniquely",
    "Wrong transport name fails in three distinct ways",
    "Author recommends validating transport field against closed set"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}