Skip to content

basalt / mcp/src / mcpRoutes

Function: mcpRoutes() ​

> mcpRoutes(options?): BasaltRoute[]

Defined in: mcp/src/server.ts:295

The MCP HTTP transport as a neutral route() — POST JSON-RPC to /mcp. It runs on the Fastify, Express and Hono adapters unchanged. Credential and tenant headers (see DEFAULT_FORWARDED_HEADERS) and the client ip are propagated into each tool call, so tools honour the same tenancy, auth and rate limits as a direct HTTP request.

Browser-facing hardening: a foreign Origin gets 403 (see allowedOrigins) and the body must be sent as application/json (415 otherwise), so a cross-site "simple" request can never drive a tool with the visitor's cookies. JSON-RPC batches are accepted. Sessions (sessions, default on) let a notifications/cancelled in a later POST of the same session cancel a call; tools/list hides the tools the caller cannot use (listVisibleOnly, default on). With sessions on, a DELETE route on the same path ends a session.

Parameters ​

options? ​

McpRoutesOptions = {}

Returns ​

BasaltRoute[]

Released under the MIT License.