Skip to content
Changelog

Public MCP with JWT authorization now checks the host

September 16, 20261 min read

This is a breaking change. Once you upgrade, an Agno AgentOS with authorization=True and PublicSurface(mcp=True) answers anonymous MCP requests to your deployed domain with 400 until you list that domain in allowed_hosts. With no host allowlist, AgentOS MCP accepts only localhost, 127.0.0.1 and [::1], the same way it protects other open MCP servers.

Set it on MCPConfig:

agent_os = AgentOS(
    ...,
    authorization=True,
    public=PublicSurface(agents=[assistant], mcp=True),
    mcp=MCPConfig(
        tools=[search_help_center],
        default_tools=False,
        stateless=True,
        allowed_hosts=["your-product.example"],
    ),
)

Anonymous MCP requests by Host, before and now. localhost is accepted both times. Your domain without allowed_hosts was accepted and is now rejected with 400. Your domain listed in allowed_hosts is accepted both times. The server card no longer asks for a bearer token.

Why did AgentOS skip the host check?

AgentOS decided whether MCP was open by looking at REST authentication. With JWT authorization on, AgentOS treated MCP as authenticated even though the public surface accepted anonymous calls. So AgentOS skipped host validation, which is its protection against DNS rebinding. For the same reason, the server card told clients they needed a bearer token.

AgentOS MCP now follows the same public and JWT policy as the rest of AgentOS. The server card no longer asks for a token. An explicit allowed_hosts list still decides which hosts AgentOS accepts. MCP OAuth and invalid-credential handling stay the same.

Learn more about transport security and serving a public MCP API in the documentation.

Frequently asked questions

An AgentOS with authorization=True and PublicSurface(mcp=True) now checks the host of anonymous MCP requests. Without a host allowlist, AgentOS MCP accepts only localhost, 127.0.0.1 and [::1] and rejects your deployed domain with 400.

Add your domain to MCPConfig(allowed_hosts=[...]), for example allowed_hosts=["your-product.example"]. AgentOS accepts the hosts in an explicit allowed_hosts list, as before.

No. With a public MCP surface, the AgentOS server card no longer tells clients that a bearer token is required. AgentOS handles MCP OAuth and invalid credentials as before.

Shipped around the same time