What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A remote MCP server URL is the HTTPS address an MCP client uses to reach a hosted Model Context Protocol server. In the current Streamable HTTP transport, the URL normally points to one endpoint, such as https://example.com/mcp. The client sends JSON-RPC messages to that endpoint with HTTP POST, and the server returns either a JSON response or an optional Server-Sent Events (SSE) stream.

What a remote MCP server URL identifies

The URL identifies the network location where an MCP server accepts protocol traffic. It is an address, not a list of tools and not an access credential. A client still has to initialize the MCP session, negotiate capabilities, authenticate, and then request tools or resources.

A typical modern URL looks like https://host.example/mcp. The path is chosen by the server operator; /mcp is a common example, not a reserved path that every server must use. A deployment might instead use /api/mcp, /services/agent, or another route.

Use HTTPS for an internet-facing endpoint. The client sends each JSON-RPC message in its own POST request. The response may have the application/json content type and contain one JSON-RPC object, or it may use text/event-stream to deliver a streamed response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the URL does not contain

  • It does not automatically grant permission to call tools.
  • It does not describe which tools are available; the client learns capabilities and tools through MCP messages after initialization.
  • It does not replace an API key, OAuth token, cookie, or other authentication mechanism required by the server.
  • It does not guarantee that the endpoint uses the current transport. A URL ending in /sse may indicate a legacy HTTP+SSE deployment.

How a modern remote MCP connection works

  1. The user supplies a URL. The MCP client receives an endpoint such as https://example.com/mcp, along with any required credentials or headers.
  2. The client sends initialize. It POSTs a JSON-RPC initialization message to that URL and advertises an Accept header containing both application/json and text/event-stream.
  3. The server selects a response form. It can return one JSON-RPC object as JSON or stream the response as SSE. A client that supports Streamable HTTP must handle both advertised response types.
  4. The client continues on the same endpoint. Subsequent JSON-RPC requests are separate POST requests to the same MCP URL. They can negotiate capabilities, list tools, read resources, and invoke tools.
  5. The client handles compatibility when necessary. If the endpoint does not support modern Streamable HTTP and returns a compatibility-triggering 4xx response, a client that supports older servers can issue a GET, read the legacy endpoint event, and then use the older SSE-plus-POST arrangement.

This design means the URL is stable even when individual responses are streamed. Your client should inspect the response status and Content-Type rather than assuming every request produces a single JSON document.

Modern Streamable HTTP versus legacy HTTP+SSE

Characteristic Streamable HTTP Legacy HTTP+SSE
Endpoint count One MCP endpoint supports POST and GET. Separate SSE and POST endpoints are normally exposed.
Message pattern Each JSON-RPC message is sent as its own POST. Client messages use POST while server messages use a persistent SSE connection.
Streaming A response can be a JSON object or an SSE stream scoped to the request. SSE is the continuing server-to-client channel.
Typical route examples https://host.example/mcp https://host.example/mcp/sse plus a documented POST route
Compatibility behavior Preferred by current clients. Requires a client fallback after modern support is not available.
Deployment model Supports newer stateless remote patterns and infrastructure routing. Often requires coordination between the SSE connection and POST endpoint.

The official transport specification dated 2025-11-25 describes the modern requirement this way: “The server MUST provide a single HTTP endpoint path … that supports both POST and GET methods.” The exact path remains an operator decision.

Connect to a remote MCP URL with cURL

Replace the example host with the URL supplied by the server operator. The initialization payload below uses JSON-RPC and requests protocol version 2025-11-25.

curl -i -X POST "https://example.com/mcp" 
  -H "Accept: application/json, text/event-stream" 
  -H "Content-Type: application/json" 
  --data '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"curl-client","version":"1.0.0"}}}'

If the service requires bearer authentication, add -H "Authorization: Bearer YOUR_TOKEN". A JSON response can be read directly. For an SSE response, keep the connection open and process events line by line; do not treat the stream as one JSON document.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Forvencer Server Book, 2 Zipper Pocket, Server Books for Waitress
  • Upgraded Two Zipper Pockets: Forvencer server books feature two secure zipper pockets for better organization of coins, cash, and receipts, ensuring that everything you collect has a safe and secure place
  • Smart Storage & Quick Access: Designed with 8 multi-functional compartments, the right side includes a guest receipt pad, while the left has a money pocket, ticket pocket, and credit card slot. Two small clear pockets store bills, receipts, and other visible items. A stitched pen loop ensures you always have your favorite pen ready
  • High-quality & Easy to Clean: Crafted from high-quality PU leather with heavy-duty stitching, this server book is built to last. It resists tears, scratches, and its waterproof surface makes cleaning easy with just a damp cloth or a non-chlorine sanitizer
  • Perfect Fit for Your Apron: Measuring 5” x 8”, this compact organizer is slightly smaller than other models, making it ideal for bending or sitting while carrying in your server apron. It holds everything a waitress needs—a place for everything
  • What's Included: This server organizer comes with multiple open and zippered pockets to store money, receipts, tips, etc. Clear sleeves are perfect for keeping menus or special lists while serving. Available in a variety of colors, allowing you to express yourself even when in uniform

Connect with Python

This example prints a normal JSON response and shows SSE lines when the server chooses streaming.

import json
import requests

url = "https://example.com/mcp"
payload = {
    "jsonrpc": "2.0",
    "id": 1,
    "method": "initialize",
    "params": {
        "protocolVersion": "2025-11-25",
        "capabilities": {},
        "clientInfo": {"name": "python-client", "version": "1.0"}
    }
}
headers = {
    "Accept": "application/json, text/event-stream",
    "Content-Type": "application/json",
    # "Authorization": "Bearer YOUR_TOKEN",
}

response = requests.post(url, headers=headers, json=payload, timeout=30)
response.raise_for_status()
content_type = response.headers.get("content-type", "")

if content_type.startswith("text/event-stream"):
    for line in response.iter_lines(decode_unicode=True):
        if line:
            print(line)
else:
    print(json.dumps(response.json(), indent=2))

For a production client, add an SSE parser that groups event: and data: lines, enforce a maximum response size, and use a timeout appropriate for long-running tools.

Connect with Node.js

const url = 'https://example.com/mcp';
const payload = {
  jsonrpc: '2.0',
  id: 1,
  method: 'initialize',
  params: {
    protocolVersion: '2025-11-25',
    capabilities: {},
    clientInfo: { name: 'node-client', version: '1.0' }
  }
};

const res = await fetch(url, {
  method: 'POST',
  headers: {
    'Accept': 'application/json, text/event-stream',
    'Content-Type': 'application/json'
    // 'Authorization': 'Bearer YOUR_TOKEN'
  },
  body: JSON.stringify(payload)
});

if (!res.ok) throw new Error(`HTTP ${res.status}`);
const type = res.headers.get('content-type') || '';
if (type.startsWith('text/event-stream')) {
  for await (const chunk of res.body) {
    process.stdout.write(Buffer.from(chunk));
  }
} else {
  console.log(JSON.stringify(await res.json(), null, 2));
}

After initialization, use the same URL for later JSON-RPC POST requests. Preserve any session or routing headers required by that particular server.

Authentication, authorization, and URL security

Authentication is separate from the URL

A public-looking URL may still reject every request without authentication. Servers can require an Authorization header, a session cookie, mutual TLS, or an identity flow implemented by a gateway. Ask the operator which credential type is expected and which headers must be forwarded. Authorization then determines which tools or resources the authenticated identity may use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Validate Origin

The transport specification says servers MUST validate the Origin header on incoming connections to prevent DNS-rebinding attacks. A reverse proxy should not blindly replace or discard this validation. Configure an explicit allow-list for trusted origins where browser-based clients are expected.

Bind local servers narrowly

A locally run MCP server should normally bind only to 127.0.0.1 rather than all network interfaces. Binding to 0.0.0.0 can expose tools to every reachable device unless a firewall and authentication layer protect the listener.

Protect credentials and logs

  • Keep tokens out of URLs, shell history, source control, and screenshots.
  • Redact Authorization headers and cookies from gateway logs.
  • Use TLS termination that validates certificates and forwards only intended headers.
  • Set request limits and tool-level authorization so a compromised credential cannot invoke everything.

Gateways, load balancers, and production routing

In production, the URL often points to a gateway or load balancer rather than directly to the process running the MCP server. The gateway may terminate TLS, authenticate users, route by tenant, enforce rate limits, and forward a stable public path to changing backend instances.

Modern remote operation can be stateless, which simplifies horizontal scaling, but your server and client still need to follow the deployment’s session and routing rules. Some infrastructure uses routing metadata or headers so that successive requests reach the right backend. Verify whether your provider requires a session identifier, affinity cookie, or custom routing header instead of assuming the URL alone is sufficient.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

If your goal is to obtain clean website screenshots rather than operate a general-purpose MCP service, ScreenshotNeo provides a website screenshot API and an MCP server for AI agents. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and each response identifies the page verdict and billing result.

One GET request returns a PNG, JPEG, WebP, or PDF. See the parameter reference in the ScreenshotNeo documentation:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo also exposes MCP tools named take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. Every plan includes the full feature set, including full-page lazy-image loading, CSS-selector element capture, device presets, custom CSS and JavaScript, waits, request blocking, cookies and headers, geolocation, PDFs, signed links, asynchronous jobs, bulk capture, and a usage API. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots. Create a free ScreenshotNeo account to try it.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting a remote MCP URL

Symptom Likely cause What to check or change
404 Not Found The path is wrong, or a proxy did not forward it. Copy the exact route from the operator, including any prefix such as /api. Check gateway rewrite rules.
405 Method Not Allowed The endpoint does not support the method used. Modern Streamable HTTP requires POST and GET on one endpoint. Confirm whether you were given a legacy SSE URL instead.
401 or 403 Missing, expired, or unauthorized credentials. Send the required Authorization header or cookie, verify scopes, and check whether the gateway expects a different identity flow.
415 Unsupported Media Type The request lacks the JSON content type. Set Content-Type: application/json and send valid JSON-RPC.
406 Not Acceptable The client did not advertise a supported response type. Include Accept: application/json, text/event-stream.
Initialization succeeds but tools fail Capability negotiation, authorization, or session routing is incomplete. Inspect the initialize result, request the server’s tool list, preserve returned session or routing metadata, and confirm tool permissions.
The client hangs on a response The server returned SSE and the client is waiting for a complete JSON body. Read the stream incrementally and handle event boundaries. Also check proxy buffering and idle timeouts.
Browser requests fail with an Origin error The server rejected the browser’s origin as a DNS-rebinding defense. Use an approved origin or configure the server’s explicit allow-list; do not disable Origin validation in production.
Legacy fallback never starts The client does not implement HTTP+SSE compatibility. Use an MCP client with Streamable HTTP-first detection and legacy fallback, or configure the documented SSE and POST routes manually.

Frequently asked questions

Can an MCP URL contain a query string?

It can, if the server and gateway define query parameters, but credentials should not be placed there because URLs are commonly logged and copied. Prefer headers or a secure session mechanism.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does changing the URL path change the MCP protocol?

No. The path is routing metadata selected by the operator. The protocol behavior comes from the HTTP transport and JSON-RPC messages accepted at that route.

Can one endpoint serve several MCP clients?

Yes, provided the deployment supports concurrent connections and its authentication, authorization, rate limits, and session or routing rules are designed for multiple clients.

Frequently Asked Questions

Can an MCP URL contain a query string?

It can when the server defines query parameters, but credentials belong in secure headers or sessions rather than URLs that may be logged.

Does changing the URL path change the MCP protocol?

No. The operator chooses the route; the transport and JSON-RPC messages determine protocol behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can one endpoint serve several MCP clients?

Yes, if the deployment supports concurrent clients and applies suitable authentication, authorization, rate limits, and routing.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.