MCP-HDR-001
Missing Mcp-Method rejected with 400 + HeaderMismatch
“Mcp-Method | method | All requests. These headers are REQUIRED for compliance.” — spec anchor
How to fix this
Reject a request that arrives without an `Mcp-Method` header, using HTTP 400 and JSON-RPC error `-32020`. The header is required on every request.
Check your own server against this rule
The validator makes real protocol requests and reports this rule as pass, warn or fail alongside the other 78. Validate a server or read how the check works.
Other Request metadata headers rules
- MCP-HDR-002Missing Mcp-Name on tools/call rejected with 400 + HeaderMismatch
- MCP-HDR-003Mcp-Name header must match the request body
- MCP-HDR-004Missing MCP-Protocol-Version rejected (modern-only servers)
- MCP-HDR-005MCP-Protocol-Version header must match _meta.protocolVersion
- MCP-HDR-006Header names compared case-insensitively
- MCP-HDR-007Base64 sentinel-encoded header values decoded before comparison
- MCP-HDR-008Mcp-Param-{Name} validated against body when x-mcp-header is declared
- MCP-HDR-009Mcp-Param-{Name} containing invalid characters is rejected
- MCP-HDR-010Header validation runs before method dispatch