Streamable HTTP
The MCP transport for servers reached over the network, where the client sends each message to an HTTP endpoint.
Streamable HTTP lets a server run anywhere and serve many clients: each message is an HTTP request to a single endpoint, and the server can stream its replies back. It replaced the older transport built on server-sent events.
Once a server listens on a network port, who may call it becomes a real question. The MCP specification describes authorisation for HTTP transports based on OAuth, and a server that skips it answers anybody who can reach the port.
The rubric run by hand on this site found two servers whose network mode listened on every interface with no authentication, acting with the operator's own credentials.
Switching a server to HTTP to share it without asking what it listens on and who it lets in. A local tool becomes a network service with your token behind it.
Related terms
See Streamable HTTP on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue