Skip to content
Esc
↑↓navigate↵open⌘Jpreview

MCP transport (no event stream)

The transport is stateless — every request gets its own server — so nothing is ever pushed to a client. A request for the server-to-client event stream is declined with 405 and an Allow: POST, DELETE header, which MCP clients read as “no stream offered”.

GET/mcp
Responses
400The body is not a valid JSON-RPC message, or names an unsupported MCP protocol version.
jsonrpcstringrequired
errorobjectrequired
Show properties
codeintegerrequired
min -9007199254740991 · max 9007199254740991
messagestringrequired
dataany
idstring | nullrequired
401No bearer token, or it is invalid, expired or revoked. The `WWW-Authenticate` header names the protected-resource metadata.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
errorstringrequired
RFC 6750 error code, e.g. `invalid_token` or `insufficient_scope`.
error_descriptionstring
Human-readable explanation.
403The token lacks the grant the transport requires.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
errorstringrequired
RFC 6750 error code, e.g. `invalid_token` or `insufficient_scope`.
error_descriptionstring
Human-readable explanation.
405No event stream is offered; the `Allow` header lists POST and DELETE.
406The `Accept` header must allow both `application/json` and `text/event-stream` (`GET` needs `text/event-stream`).
jsonrpcstringrequired
errorobjectrequired
Show properties
codeintegerrequired
min -9007199254740991 · max 9007199254740991
messagestringrequired
dataany
idstring | nullrequired
429Too many rejected authentication attempts.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
errorstringrequired
RFC 6750 error code, e.g. `invalid_token` or `insufficient_scope`.
error_descriptionstring
Human-readable explanation.
500Unexpected server error. The body never carries internal detail.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
503Token verification is temporarily unavailable. Retry later.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
errorstringrequired
RFC 6750 error code, e.g. `invalid_token` or `insufficient_scope`.
error_descriptionstring
Human-readable explanation.
Request
curl -X GET "https://api.varsafe.dev/mcp"
Response
{
  "jsonrpc": "2.0",
  "error": {
    "code": 0,
    "message": "string",
    "data": "string"
  },
  "id": 0
}