Class McpServer

java.lang.Object
com.codename1.backend.mcp.McpServer
All Implemented Interfaces:
HttpServer.Handler

public final class McpServer extends Object implements HttpServer.Handler

The server's Model Context Protocol endpoint: JSON-RPC over MCP's Streamable HTTP transport, at cn1.mcp.path (/mcp by default).

It serves two kinds of tools. The application's own -- every @McpTool method, registered by the generated entry point -- and, on a development profile of a development build, the DevTools: the routes, the beans, the database, the jobs and the metrics of the running server, so an agent building the backend can inspect and exercise it.

  claude mcp add --transport http backend http://127.0.0.1:8080/mcp

Security

Outside a development profile the endpoint needs Authorization: Bearer and the server refuses to start without a token, because a tool anyone can call is a vulnerability. On a development profile the token is optional. Either way a request whose Origin is not a loopback address or one listed in cn1.mcp.allowedOrigins is refused -- including a page the server serves itself, which has to be listed -- which is what the MCP specification asks for against DNS rebinding: a web page in the developer's browser must not be able to drive the server.

The endpoint answers POSTed JSON-RPC with a JSON body. It keeps no session and opens no event stream, so a GET is answered 405, as the transport allows.

  • Field Details

  • Method Details

    • fromConfig

      public static McpServer fromConfig(Config config, McpServer.Extension devTools, String serverName, List tools) throws IOException

      The endpoint this configuration asks for, or null when it is off or there would be no tool on it.

      Parameters
      • devTools: the development tools, which the build passes only in a development build; they are installed only on a development profile or with cn1.mcp.devTools=true

      • tools: the application's tools, the ones its server registered

      Throws:
      IOException
    • register

      public void register(McpTool tool)
      Adds a tool to this endpoint, replacing one of the same name.
    • tools

      public List tools()
      Every tool on this endpoint.
    • hasDevTools

      public boolean hasDevTools()
      Whether the development tools are installed on this endpoint.
    • getPath

      public String getPath()
      The path the endpoint answers on.
    • attach

      public void attach(Backend running)
      Called once the server is listening.
    • handle

      public HttpServer.Response handle(HttpServer.Request request) throws Exception
      Specified by:
      handle in interface HttpServer.Handler
      Throws:
      Exception
    • hasToken

      public boolean hasToken()
      Whether requests must present a bearer token. Without one -- a development profile's default -- the server binds its listener to loopback, since this endpoint reaches the database and every handler.