createmcps.com

MCP-HDR-005

MCP-Protocol-Version header must match _meta.protocolVersion

The header value MUST match the io.modelcontextprotocol/protocolVersion field carried in the request body's _meta. If the values do not match, the server MUST reject the request with 400 Bad Request and a HeaderMismatch JSON-RPC error.spec anchor

How to fix this

Compare the `MCP-Protocol-Version` header against `io.modelcontextprotocol/protocolVersion` in the body's `_meta`. If they differ, reject with 400 Bad Request and a HeaderMismatch error.

Check your own server against this rule

The validator makes real protocol requests and reports this rule as pass, warn or fail alongside the other 78. Validate a server or read how the check works.

Other Request metadata headers rules

  • MCP-HDR-001Missing Mcp-Method rejected with 400 + HeaderMismatch
  • MCP-HDR-002Missing Mcp-Name on tools/call rejected with 400 + HeaderMismatch
  • MCP-HDR-003Mcp-Name header must match the request body
  • MCP-HDR-004Missing MCP-Protocol-Version rejected (modern-only servers)
  • MCP-HDR-006Header names compared case-insensitively
  • MCP-HDR-007Base64 sentinel-encoded header values decoded before comparison
  • MCP-HDR-008Mcp-Param-{Name} validated against body when x-mcp-header is declared
  • MCP-HDR-009Mcp-Param-{Name} containing invalid characters is rejected
  • MCP-HDR-010Header validation runs before method dispatch