Skip to content

basalt / mcp/src / DEFAULT_FORWARDED_HEADERS

Variable: DEFAULT_FORWARDED_HEADERS ​

> const DEFAULT_FORWARDED_HEADERS: readonly string[]

Defined in: mcp/src/tools.ts:45

Request headers a tool call inherits from its caller. Credentials and the tenant travel (so a tool honours the same auth/tenancy as a direct request), cookie included because session-cookie auth is a supported way to call /mcp (the route's Origin/Content-Type checks keep it CSRF-safe). Everything else is dropped — x-request-id/x-correlation-id (the tool mints its own), conditional headers (if-none-match would turn a tool result into a 304), content-length/content-type (describe the JSON-RPC envelope, not the tool's input), hop-by-hop and forwarding headers (the client ip travels as ip). Extend it with mcpPlugin({ forwardHeaders }).

Released under the MIT License.