fastmcp/docs/deployment
Jeremiah Lowin 6330655809
Apply Host/Origin protection settings to the SSE transport (#5427)
`host_origin_protection`, `allowed_hosts`, and `allowed_origins` (and their `FASTMCP_HTTP_*` settings) now configure the legacy SSE transport the same way they configure Streamable HTTP. `create_sse_app()` accepts the three options, `http_app(transport="sse")` and `run(transport="sse")` forward them, and the request guard covers both the SSE connection endpoint and the message endpoint. `True`, `False`, and `"auto"` mean the same thing on both transports, so a server's Host/Origin policy is the same on either one.

Both app factories now build the guard through one shared helper, and the SSE transport passes explicit SDK security settings that leave Host/Origin validation to FastMCP, matching Streamable HTTP. The default stays `False`, so servers that don't opt in see no change. The deployment and settings docs now say the options apply to both transports.

```python
from fastmcp import FastMCP

mcp = FastMCP("My Server")

app = mcp.http_app(
    transport="sse",
    host_origin_protection=True,
    allowed_hosts=["mcp.example.com"],
)
```

Co-authored-by: Claude <noreply@anthropic.com>
2026-10-04 10:14:50 -04:00
..
http.mdx Apply Host/Origin protection settings to the SSE transport (#5427) 2026-10-04 10:14:50 -04:00
prefect-horizon.mdx Add Prefect Horizon account commands (#4786) 2026-08-17 20:11:19 -07:00
running-server.mdx docs: refresh sidebar tags and fix audit findings across servers/clients pages (#4965) 2026-08-31 15:17:03 -05:00
sandboxed-agents.mdx Add a sandboxed-agents deployment guide (#4027) 2026-04-25 11:40:56 -04:00
server-configuration.mdx Improve the v4 docs (#4707) 2026-07-29 09:51:13 -04:00