The mechanism
Modern Streamable HTTP sends each client message as a POST to the MCP endpoint. The response can be JSON or an event stream associated with that request. A client advertises acceptance of both forms. Do not assume the legacy standalone GET stream or protocol session header still applies.
The current transport requires method and applicable name headers, plus the protocol-version header. These mirror body fields so gateways can route and inspect operations without guessing. A mismatch must be rejected rather than letting a gateway authorize one operation while the handler executes another.
HTTP exposure adds a network boundary. The specification requires Origin validation and recommends localhost binding for local servers. These controls address browser-origin attacks such as DNS rebinding; they do not replace caller authentication or object authorization.
Worked example
This request header fixture belongs with a chapter 3-style JSON body using tools/call, name lookup_incident and the same protocol version. The endpoint hostname is illustrative and must not be used as a real service. No bearer token is included in the book.
POST /mcp HTTP/1.1
Host: parcelops.example
Content-Type: application/json
Accept: application/json, text/event-stream
MCP-Protocol-Version: 2026-07-28
Mcp-Method: tools/call
Mcp-Name: lookup_incident
Practice: predict, inspect, explain
Offline exercise. Pair these headers with a body naming delete_incident. Describe the gateway and server checks that must reject the mismatch before dispatch. Then compare an invalid browser Origin with a missing bearer token: explain why they are different failures.
Expected observation: visible routing metadata helps only when it is validated against the actual request. Create a test matrix for valid JSON, supported event-stream responses, wrong method headers, wrong version headers and a disconnected stream. Keep the local endpoint bound to loopback in any later approved integration lab.
Troubleshooting and trade-offs
A proxy that buffers event streams can make progress appear frozen despite working backend execution. Inspect content type, buffering and timeouts before changing business logic. A 404 may identify a wrong endpoint or unknown method; compare the response body and era. Never fix an Origin failure by disabling validation or exposing a local development server on all interfaces.
Interview practice
Why duplicate method information in headers?
It makes routing and inspection possible at HTTP intermediaries. It remains untrusted input and must match the corresponding JSON-RPC fields.
Does localhost binding remove the need for authentication?
No. It reduces network exposure but does not establish who may invoke operations. Browser-origin and local-process threats still need explicit controls.
Completion check
Specify rejection behavior for a header/body mismatch before any business handler is called.
Sources and version notes
This edition targets MCP 2026-07-28, checked 6 October 2026. SDK examples are version-sensitive and labelled when not executed. Synthetic fixtures are learning material, not protocol conformance evidence.
- Official documentation: Streamable http
- Official documentation: Security best practices
- Official documentation: Client best practices
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.