Skip to content

Environment variable MCP_ALLOWED_ORIGINS

No value of this variable is held in this registry. The registry knows only the name the source states.

Entries naming MCP_ALLOWED_ORIGINS as an ordinary environment variable

Entries naming MCP_ALLOWED_ORIGINS as an ordinary environment variable
ccu-mcp in namespace io.githubio.github.claymore666/ccu-mcpMCP server for controlling HomeMatic smart home devices via the CCU JSON-RPC API
debmatic-mcp in namespace io.githubio.github.claymore666/debmatic-mcpMCP server for controlling HomeMatic smart home devices via the CCU JSON-RPC API
ead-enterprise-suite in namespace io.githubio.github.g-digital-by-Garrigues/ead-enterprise-suiteMCP server for EAD Enterprise Suite - signatures, evidence, notifications, dossiers via AI agents.
ead-factory in namespace io.githubio.github.g-digital-by-Garrigues/ead-factoryMCP server for EAD Factory: qualified evidence, signature, notifications and chat via AI agents.
gocertius in namespace io.githubio.github.g-digital-by-Garrigues/gocertiusMCP server for GoCertius: certified evidence, dossiers, notifications and chats via AI agents.
gaggiuino-mcp in namespace io.githubio.github.ljcl/gaggiuino-mcpRemote MCP server for your Gaggiuino espresso machine's shots and profiles
kubeview in namespace io.githubio.github.mikhae1/kubeviewRead-only Model Context Protocol MCP server enabling code-driven AI analysis of Kubernetes clusters.

Start of the description from the source registry (first sentence, at most 160 characters), untranslated and unverified

Entries naming MCP_ALLOWED_ORIGINS as a secret required variable

No entry.

What the sources write about this name

What the sources write about this name
ccu-mcp in namespace io.githubComma-separated allowlist of browser origins. Unset = no cross-origin browser access (default-deny). An allowlisted origin is reflected exactly in Access-Control-Allow-Origin (never '*'); the list also drives DNS-rebinding origin checks
debmatic-mcp in namespace io.githubComma-separated allowlist of browser origins. Unset = no cross-origin browser access (default-deny). An allowlisted origin is reflected exactly in Access-Control-Allow-Origin (never '*'); the list also drives DNS-rebinding origin checks
ead-enterprise-suite in namespace io.githubComma-separated allowed browser Origins (DNS-rebinding defense). Empty = reject any request carrying an Origin header; non-browser clients (CLI/SDK) send no Origin and are always allowed. Use '*' to allow all.
ead-factory in namespace io.githubComma-separated allowed browser Origins (DNS-rebinding defense). Empty = reject any request carrying an Origin header; non-browser clients (CLI/SDK) send no Origin and are always allowed. Use '*' to allow all.
gocertius in namespace io.githubComma-separated allowed browser Origins (DNS-rebinding defense). Empty = reject any request carrying an Origin header; non-browser clients (CLI/SDK) send no Origin and are always allowed. Use '*' to allow all.
gaggiuino-mcp in namespace io.githubComma-separated browser origins allowed to call /mcp, or * to allow any (unsafe). Requests with no Origin header are unaffected
kubeview in namespace io.githubComma-separated Origin allowlist for HTTP mode.

Taken verbatim from the source, one line per entry. The text is a vendor's own statement and is neither checked nor shortened.

To the environment variable index

Version of the extraction rule: 1.1. The names are formed by splitting the stored original data at the separator this registry set when reading it in. Counted across the 41,867 published entries.

tracevero · https://tracevero.com/variable/MCP_ALLOWED_ORIGINS