fix: whitelist /rpc endpoint for server-scoped tokens#2646
Merged
crivetimihai merged 1 commit intomainfrom Feb 7, 2026
Merged
Conversation
Member
|
Clean one-liner fix with a test. Server-scoped tokens need LGTM — ready to merge. |
2eaca5e to
d852e04
Compare
Signed-off-by: Shoumi <shoumimukherjee@gmail.com>
5 tasks
d852e04 to
895d572
Compare
crivetimihai
approved these changes
Feb 7, 2026
crivetimihai
approved these changes
Feb 7, 2026
kcostell06
pushed a commit
to kcostell06/mcp-context-forge
that referenced
this pull request
Feb 24, 2026
Signed-off-by: Shoumi <shoumimukherjee@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🐛 Bug-fix PR
📌 Summary
Server-scoped tokens cannot access the
/rpcendpoint, preventing SSE transport and WebSocket relay from functioning. This PR adds/rpcto the general endpoints whitelist to allow server-scoped tokens to make MCP protocol requests.🔗 Related Issue
Closes #2192
🐞 Root Cause
In
mcpgateway/middleware/token_scoping.py, the_check_server_restrictionfunction:/rpcmatches any server path pattern → NO/rpcis ingeneral_endpoints→ NO (not listed)False→ HTTP 403The
/rpcendpoint is a core JSON-RPC endpoint used for:/rpc)Without
/rpcin the whitelist, server-scoped tokens are denied access despite needing it for MCP protocol operations.💡 Fix Description
Added
/rpcto thegeneral_endpointslist inmcpgateway/middleware/token_scoping.py(line 328):