Skip to content

Environment variable MCP_ALLOWED_ORIGINS

No value of this variable is held in this registry. The registry knows only the name the source states.

Entries naming MCP_ALLOWED_ORIGINS as an ordinary environment variable

Entries naming MCP_ALLOWED_ORIGINS as an ordinary environment variable
MCP server in namespace io.githubio.github.claymore666/ccu-mcp
MCP server in namespace io.githubio.github.claymore666/debmatic-mcp
MCP server in namespace io.githubio.github.g-digital-by-Garrigues/ead-enterprise-suite
MCP server in namespace io.githubio.github.g-digital-by-Garrigues/ead-factory
MCP server in namespace io.githubio.github.g-digital-by-Garrigues/gocertius
MCP server in namespace io.githubio.github.ljcl/gaggiuino-mcp
MCP server in namespace io.githubio.github.mikhae1/kubeview

Entries naming MCP_ALLOWED_ORIGINS as a secret required variable

No entry.

What the sources write about this name

What the sources write about this name
MCP server in namespace io.githubComma-separated allowlist of browser origins. Unset = no cross-origin browser access (default-deny). An allowlisted origin is reflected exactly in Access-Control-Allow-Origin (never '*'); the list also drives DNS-rebinding origin checks
MCP server in namespace io.githubComma-separated allowlist of browser origins. Unset = no cross-origin browser access (default-deny). An allowlisted origin is reflected exactly in Access-Control-Allow-Origin (never '*'); the list also drives DNS-rebinding origin checks
MCP server in namespace io.githubComma-separated allowed browser Origins (DNS-rebinding defense). Empty = reject any request carrying an Origin header; non-browser clients (CLI/SDK) send no Origin and are always allowed. Use '*' to allow all.
MCP server in namespace io.githubComma-separated allowed browser Origins (DNS-rebinding defense). Empty = reject any request carrying an Origin header; non-browser clients (CLI/SDK) send no Origin and are always allowed. Use '*' to allow all.
MCP server in namespace io.githubComma-separated allowed browser Origins (DNS-rebinding defense). Empty = reject any request carrying an Origin header; non-browser clients (CLI/SDK) send no Origin and are always allowed. Use '*' to allow all.
MCP server in namespace io.githubComma-separated browser origins allowed to call /mcp, or * to allow any (unsafe). Requests with no Origin header are unaffected
MCP server in namespace io.githubComma-separated Origin allowlist for HTTP mode.

Taken verbatim from the source, one line per entry. The text is a vendor's own statement and is neither checked nor shortened.

To the environment variable index

Version of the extraction rule: 1.1. The names are formed by splitting the stored raw declaration at the separator this registry set when reading it in. Counted across the 24,507 published entries.

tracevero · https://tracevero.com/variable/MCP_ALLOWED_ORIGINS