# Public MCP with JWT authorization now checks the host

> An AgentOS with authorization=True and PublicSurface(mcp=True) now applies the localhost-only host check to anonymous MCP requests. Add your domain to MCPConfig(allowed_hosts=[...]) before you upgrade.

- Published: 2026-09-16
- Author: Ashpreet Bedi
- Categories: Changelog
- Canonical: https://www.agno.com/articles/public-mcp-with-jwt-authorization-now-checks-the-host
- Markdown: https://www.agno.com/articles/public-mcp-with-jwt-authorization-now-checks-the-host.md

This is a breaking change. Once you upgrade, an Agno AgentOS with `authorization=True` and `PublicSurface(mcp=True)` answers anonymous MCP requests to your deployed domain with `400` until you list that domain in `allowed_hosts`. With no host allowlist, AgentOS MCP accepts only `localhost`, `127.0.0.1` and `[::1]`, the same way it protects other open MCP servers.

Set it on `MCPConfig`:

```python
agent_os = AgentOS(
    ...,
    authorization=True,
    public=PublicSurface(agents=[assistant], mcp=True),
    mcp=MCPConfig(
        tools=[search_help_center],
        default_tools=False,
        stateless=True,
        allowed_hosts=["your-product.example"],
    ),
)
```

![Anonymous MCP requests by Host, before and now. localhost is accepted both times. Your domain without allowed_hosts was accepted and is now rejected with 400. Your domain listed in allowed_hosts is accepted both times. The server card no longer asks for a bearer token.](https://www.agno.com/images/v3-0-10-public-mcp-host.png)

### Why did AgentOS skip the host check?

AgentOS decided whether MCP was open by looking at REST authentication. With JWT authorization on, AgentOS treated MCP as authenticated even though the public surface accepted anonymous calls. So AgentOS skipped host validation, which is its protection against DNS rebinding. For the same reason, the server card told clients they needed a bearer token.

AgentOS MCP now follows the same public and JWT policy as the rest of AgentOS. The server card no longer asks for a token. An explicit `allowed_hosts` list still decides which hosts AgentOS accepts. MCP OAuth and invalid-credential handling stay the same.

Learn more about [transport security](https://docs.agno.com/agent-os/mcp/mcp#transport-security) and [serving a public MCP API](https://docs.agno.com/agent-os/public-surface#serve-a-focused-mcp-api) in the documentation.
