Class McpServer
- All Implemented Interfaces:
HttpServer.Handler
The server's Model Context Protocol endpoint: JSON-RPC over MCP's Streamable
HTTP transport, at cn1.mcp.path (/mcp by default).
It serves two kinds of tools. The application's own -- every
@McpTool method, registered by the generated entry point -- and, on a
development profile of a development build, the DevTools: the routes,
the beans, the database, the jobs and the metrics of the running server, so an
agent building the backend can inspect and exercise it.
claude mcp add --transport http backend http://127.0.0.1:8080/mcp
Security
Outside a development profile the endpoint needs
Authorization: Bearer and the server refuses to start
without a token, because a tool anyone can call is a vulnerability. On a
development profile the token is optional. Either way a request whose
Origin is not a loopback address or one listed in
cn1.mcp.allowedOrigins is refused -- including a page the server
serves itself, which has to be listed -- which is what the MCP
specification asks for against DNS rebinding: a web page in the developer's
browser must not be able to drive the server.
The endpoint answers POSTed JSON-RPC with a JSON body. It keeps no session and opens no event stream, so a GET is answered 405, as the transport allows.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic interfaceExtra tools installed when the server starts; the development tools are one. -
Field Summary
Fields -
Method Summary
Modifier and TypeMethodDescriptionvoidCalled once the server is listening.static McpServerfromConfig(Config config, McpServer.Extension devTools, String serverName, List tools) The endpoint this configuration asks for, or null when it is off or there would be no tool on it.getPath()The path the endpoint answers on.handle(HttpServer.Request request) booleanWhether the development tools are installed on this endpoint.booleanhasToken()Whether requests must present a bearer token.voidAdds a tool to this endpoint, replacing one of the same name.tools()Every tool on this endpoint.
-
Field Details
-
ENABLED
- See Also:
-
PATH
- See Also:
-
TOKEN
- See Also:
-
ALLOWED_ORIGINS
- See Also:
-
DEV_TOOLS
- See Also:
-
-
Method Details
-
fromConfig
public static McpServer fromConfig(Config config, McpServer.Extension devTools, String serverName, List tools) throws IOException The endpoint this configuration asks for, or null when it is off or there would be no tool on it.
Parameters
-
devTools: the development tools, which the build passes only in a development build; they are installed only on a development profile or withcn1.mcp.devTools=true -
tools: the application's tools, the ones its server registered
- Throws:
IOException
-
-
register
Adds a tool to this endpoint, replacing one of the same name. -
tools
Every tool on this endpoint. -
hasDevTools
public boolean hasDevTools()Whether the development tools are installed on this endpoint. -
getPath
The path the endpoint answers on. -
attach
Called once the server is listening. -
handle
- Specified by:
handlein interfaceHttpServer.Handler- Throws:
Exception
-
hasToken
public boolean hasToken()Whether requests must present a bearer token. Without one -- a development profile's default -- the server binds its listener to loopback, since this endpoint reaches the database and every handler.
-