You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat!: retire /sse and upgrade to workers-oauth-provider 1.2.1
/sse answers every request with a 410 naming /mcp. The OAuth protected
resource is <origin>/mcp. Consent, Cloudflare sign-in state and remembered
consent move to the provider's consent and upstream helpers.
Retire the `/sse` URL and upgrade to `@cloudflare/workers-oauth-provider` 1.2.1.
24
+
25
+
- Every request to `/sse` now returns `410 Gone` with an `application/problem+json` body naming the server's `/mcp` URL, before any authentication. `/sse` used to serve Streamable HTTP as an alias of `/mcp`; clients configured with it must switch to `/mcp`. MCP SDK v1 and v2 clients show the message in their connection error. It is not a redirect, because OAuth clients that follow one reject the `/mcp` protected resource metadata with an error that never mentions `/mcp`.
26
+
- The OAuth protected resource is now `<origin>/mcp`, and every token is bound to it. Grants bound to `/mcp` keep working. Grants bound to `/sse` fail their next refresh with `invalid_grant`, and the client signs in again at `/mcp`.
27
+
- The consent page uses the provider's consent helpers. The authorization request stays server-side and the page posts only a single-use handle bound to the browser. Cancel now sends `access_denied` back to the MCP client. The page shows the redirect URI, the publishing domain of a Client ID Metadata Document client, and a warning when the tokens go to a local app.
28
+
- Cloudflare sign-in uses `beginUpstream()` / `finishUpstream()` in place of the hand-rolled KV state and session cookie. Two tabs can authorize at once, and declining at Cloudflare sends `access_denied` back to the MCP client.
29
+
- Remembered consent uses `isConsentRemembered()`. Approvals made before this change aren't carried over, so each browser sees the consent page once more.
30
+
- Direct Cloudflare API tokens are validated for the `/mcp` resource.
Copy file name to clipboardExpand all lines: README.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ Model Context Protocol (MCP) is a [new, standardized protocol](https://modelcont
4
4
5
5
These MCP servers allow your [MCP Client](https://modelcontextprotocol.io/clients) to read configurations from your account, process information, make suggestions based on data, and even make those suggested changes for you. All of these actions can happen across Cloudflare's many services including application development, security and performance.
6
6
7
-
Every server in this repository exposes the same stateless Streamable HTTP handler at `/mcp`and `/sse`through a fresh SDK v2 server factory. `/sse`remains as a URL compatibility alias; it does not use the deprecated HTTP+SSE transport. A legacy SSE `GET /sse`request receives a `410 Gone` Problem Details response with two migration options: configure the existing URL to use Streamable HTTP, or switch to the recommended `/mcp` URL for future compatibility. Modern 2026 requests and stateless 2025 requests share the same request-scoped implementation without an MCP protocol session. OAuth, credentials, account selection, application caches, and product Durable Objects remain application/security state where required.
7
+
Every server in this repository exposes a stateless Streamable HTTP handler at `/mcp` through a fresh SDK v2 server factory. The retired `/sse` URL answers every request with a `410 Gone` Problem Details response that names the `/mcp` URL; MCP clients show its message in their connection error. Modern 2026 requests and stateless 2025 requests share the same request-scoped implementation without an MCP protocol session. OAuth, credentials, account selection, application caches, and product Durable Objects remain application/security state where required.
8
8
9
9
Cloudflare offers the following MCP servers. The domain-specific servers are included in this repository, while the recommended Code Mode server is maintained in [`cloudflare/mcp`](https://github.com/cloudflare/mcp):
Copy file name to clipboardExpand all lines: apps/ai-gateway/README.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ connections, with Cloudflare OAuth built-in.
6
6
It integrates tools powered by the [Cloudflare AI Gateway API](https://developers.cloudflare.com/ai-gateway/) to search
7
7
your AI Gateway logs, inspect prompts and responses, and get details about gateway usage.
8
8
9
-
The `/mcp`and `/sse` URLs use the same stateless SDK v2 handler and create a fresh server with request-scoped auth/account context for every request. `/sse`is not the deprecated HTTP+SSE transport. OAuth grants and token validation remain durable security state; the server stores no MCP protocol session.
9
+
The `/mcp`URL uses a stateless SDK v2 handler that creates a fresh server with request-scoped auth/account context for every request. The retired `/sse`URL returns `410 Gone` pointing at `/mcp`. OAuth grants and token validation remain durable security state; the server stores no MCP protocol session.
Copy file name to clipboardExpand all lines: apps/auditlogs/README.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -29,7 +29,7 @@ connections, with Cloudflare OAuth built-in.
29
29
30
30
Audit logs summarize the history of changes made within your Cloudflare account. Audit logs include account level actions like zone configuration changes. The tool is powered by the [Audit Log API](https://developers.cloudflare.com/api/resources/accounts/subresources/logs/subresources/audit/methods/list/).
31
31
32
-
The `/mcp`and `/sse` URLs use the same stateless SDK v2 handler and create a fresh server with request-scoped auth/account context for every request. `/sse`is not the deprecated HTTP+SSE transport. OAuth grants and token validation remain durable security state; the server stores no MCP protocol session.
32
+
The `/mcp`URL uses a stateless SDK v2 handler that creates a fresh server with request-scoped auth/account context for every request. The retired `/sse`URL returns `410 Gone` pointing at `/mcp`. OAuth grants and token validation remain durable security state; the server stores no MCP protocol session.
Copy file name to clipboardExpand all lines: apps/autorag/README.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -34,7 +34,7 @@ connections, with Cloudflare OAuth built-in.
34
34
35
35
It integrates tools powered by the [Cloudflare AutoRAG API](https://developers.cloudflare.com/autorag/) to allow you to access and query your account's AutoRAG instances.
36
36
37
-
The `/mcp`and `/sse` URLs use the same stateless SDK v2 handler and create a fresh server with request-scoped auth/account context for every request. `/sse`is not the deprecated HTTP+SSE transport. OAuth grants and token validation remain durable security state; the server stores no MCP protocol session.
37
+
The `/mcp`URL uses a stateless SDK v2 handler that creates a fresh server with request-scoped auth/account context for every request. The retired `/sse`URL returns `410 Gone` pointing at `/mcp`. OAuth grants and token validation remain durable security state; the server stores no MCP protocol session.
Copy file name to clipboardExpand all lines: apps/browser-rendering/README.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ connections, with Cloudflare OAuth built-in.
6
6
It integrates tools powered by the [Cloudflare Browser Run API](https://developers.cloudflare.com/browser-run/) to fetch
7
7
web pages, convert them to markdown, and take screenshots.
8
8
9
-
The `/mcp`and `/sse` URLs use the same stateless SDK v2 handler and create a fresh server with request-scoped auth/account context for every request. `/sse`is not the deprecated HTTP+SSE transport. OAuth grants and token validation remain durable security state; the server stores no MCP protocol session. The Browser Run session tools below manage application-level browser sessions, not MCP protocol sessions.
9
+
The `/mcp`URL uses a stateless SDK v2 handler that creates a fresh server with request-scoped auth/account context for every request. The retired `/sse`URL returns `410 Gone` pointing at `/mcp`. OAuth grants and token validation remain durable security state; the server stores no MCP protocol session. The Browser Run session tools below manage application-level browser sessions, not MCP protocol sessions.
Copy file name to clipboardExpand all lines: apps/cloudflare-blog/README.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
3
3
This is a [Model Context Protocol (MCP)](https://modelcontextprotocol.io/introduction) server that provides tools for searching and reading the [Cloudflare Blog](https://blog.cloudflare.com).
4
4
5
-
The `/mcp`and `/sse` URLs use the same stateless SDK v2 handler and create a fresh server for every request. `/sse`is not the deprecated HTTP+SSE transport. The handler supports modern MCP requests and stateless 2025 compatibility without an MCP protocol session.
5
+
The `/mcp`URL uses a stateless SDK v2 handler that creates a fresh server for every request. The retired `/sse`URL returns `410 Gone` pointing at `/mcp`. The handler supports modern MCP requests and stateless 2025 compatibility without an MCP protocol session.
Copy file name to clipboardExpand all lines: apps/cloudflare-one-casb/README.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
3
3
This [Model Context Protocol (MCP)](https://modelcontextprotocol.io/introduction) server provides tools for inspecting Cloudflare One CASB integrations, assets, and asset categories. It supports Cloudflare OAuth and API-token authentication.
4
4
5
-
The `/mcp`and `/sse` URLs use the same stateless SDK v2 handler and create a fresh server with request-scoped auth/account context for every request. `/sse`is not the deprecated HTTP+SSE transport. OAuth grants and token validation remain durable security state; the server stores no MCP protocol session.
5
+
The `/mcp`URL uses a stateless SDK v2 handler that creates a fresh server with request-scoped auth/account context for every request. The retired `/sse`URL returns `410 Gone` pointing at `/mcp`. OAuth grants and token validation remain durable security state; the server stores no MCP protocol session.
Copy file name to clipboardExpand all lines: apps/dex-analysis/README.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ connections, with Cloudflare OAuth built-in.
5
5
6
6
It integrates tools powered by the [Cloudflare DEX API](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/) to provide visibility into device, network, and application performance across your Zero Trust organization
7
7
8
-
The `/mcp`and `/sse` URLs use the same stateless SDK v2 handler and create a fresh server with request-scoped auth/account context for every request. `/sse`is not the deprecated HTTP+SSE transport. OAuth remains durable security state, and `WarpDiagReader` remains an application cache for downloaded diagnostics; no MCP protocol session is retained.
8
+
The `/mcp`URL uses a stateless SDK v2 handler that creates a fresh server with request-scoped auth/account context for every request. The retired `/sse`URL returns `410 Gone` pointing at `/mcp`. OAuth remains durable security state, and `WarpDiagReader` remains an application cache for downloaded diagnostics; no MCP protocol session is retained.
0 commit comments