Environment variable MCP_ALLOWED_ORIGINS
No value of this variable is held in this registry. The registry knows only the name the source states.
Entries naming MCP_ALLOWED_ORIGINS as an ordinary environment variable
| ccu-mcp in namespace io.github | io.github.claymore666/ccu-mcp | MCP server for controlling HomeMatic smart home devices via the CCU JSON-RPC API |
|---|---|---|
| debmatic-mcp in namespace io.github | io.github.claymore666/debmatic-mcp | MCP server for controlling HomeMatic smart home devices via the CCU JSON-RPC API |
| ead-enterprise-suite in namespace io.github | io.github.g-digital-by-Garrigues/ead-enterprise-suite | MCP server for EAD Enterprise Suite - signatures, evidence, notifications, dossiers via AI agents. |
| ead-factory in namespace io.github | io.github.g-digital-by-Garrigues/ead-factory | MCP server for EAD Factory: qualified evidence, signature, notifications and chat via AI agents. |
| gocertius in namespace io.github | io.github.g-digital-by-Garrigues/gocertius | MCP server for GoCertius: certified evidence, dossiers, notifications and chats via AI agents. |
| gaggiuino-mcp in namespace io.github | io.github.ljcl/gaggiuino-mcp | Remote MCP server for your Gaggiuino espresso machine's shots and profiles |
| kubeview in namespace io.github | io.github.mikhae1/kubeview | Read-only Model Context Protocol MCP server enabling code-driven AI analysis of Kubernetes clusters. |
Start of the description from the source registry (first sentence, at most 160 characters), untranslated and unverified
Entries naming MCP_ALLOWED_ORIGINS as a secret required variable
No entry.
What the sources write about this name
| ccu-mcp in namespace io.github | Comma-separated allowlist of browser origins. Unset = no cross-origin browser access (default-deny). An allowlisted origin is reflected exactly in Access-Control-Allow-Origin (never '*'); the list also drives DNS-rebinding origin checks |
|---|---|
| debmatic-mcp in namespace io.github | Comma-separated allowlist of browser origins. Unset = no cross-origin browser access (default-deny). An allowlisted origin is reflected exactly in Access-Control-Allow-Origin (never '*'); the list also drives DNS-rebinding origin checks |
| ead-enterprise-suite in namespace io.github | Comma-separated allowed browser Origins (DNS-rebinding defense). Empty = reject any request carrying an Origin header; non-browser clients (CLI/SDK) send no Origin and are always allowed. Use '*' to allow all. |
| ead-factory in namespace io.github | Comma-separated allowed browser Origins (DNS-rebinding defense). Empty = reject any request carrying an Origin header; non-browser clients (CLI/SDK) send no Origin and are always allowed. Use '*' to allow all. |
| gocertius in namespace io.github | Comma-separated allowed browser Origins (DNS-rebinding defense). Empty = reject any request carrying an Origin header; non-browser clients (CLI/SDK) send no Origin and are always allowed. Use '*' to allow all. |
| gaggiuino-mcp in namespace io.github | Comma-separated browser origins allowed to call /mcp, or * to allow any (unsafe). Requests with no Origin header are unaffected |
| kubeview in namespace io.github | Comma-separated Origin allowlist for HTTP mode. |
Taken verbatim from the source, one line per entry. The text is a vendor's own statement and is neither checked nor shortened.
To the environment variable index
Version of the extraction rule: 1.1. The names are formed by splitting the stored original data at the separator this registry set when reading it in. Counted across the 41,867 published entries.
tracevero · https://tracevero.com/variable/MCP_ALLOWED_ORIGINS