MCP-HDR-005
MCP-Protocol-Version header must match _meta.protocolVersion
“The header value MUST match the io.modelcontextprotocol/protocolVersion field carried in the request body's _meta. If the values do not match, the server MUST reject the request with 400 Bad Request and a HeaderMismatch JSON-RPC error.” — spec anchor
How to fix this
Compare the `MCP-Protocol-Version` header against `io.modelcontextprotocol/protocolVersion` in the body's `_meta`. If they differ, reject with 400 Bad Request and a HeaderMismatch error.
Check your own server against this rule
The validator makes real protocol requests and reports this rule as pass, warn or fail alongside the other 78. Validate a server or read how the check works.
Other Request metadata headers rules
- MCP-HDR-001Missing Mcp-Method rejected with 400 + HeaderMismatch
- MCP-HDR-002Missing Mcp-Name on tools/call rejected with 400 + HeaderMismatch
- MCP-HDR-003Mcp-Name header must match the request body
- MCP-HDR-004Missing MCP-Protocol-Version rejected (modern-only servers)
- MCP-HDR-006Header names compared case-insensitively
- MCP-HDR-007Base64 sentinel-encoded header values decoded before comparison
- MCP-HDR-008Mcp-Param-{Name} validated against body when x-mcp-header is declared
- MCP-HDR-009Mcp-Param-{Name} containing invalid characters is rejected
- MCP-HDR-010Header validation runs before method dispatch