To test an MCP server with curl, first confirm it exposes an HTTP transport and identify its protocol version. Then send a request shaped for that version and inspect both the HTTP status and headers and the JSON-RPC response. Curl can test a Streamable HTTP endpoint; it cannot test a server that communicates with an AI client over local stdin/stdout (stdio).
First check whether the server has an HTTP endpoint
MCP standardizes both stdio and Streamable HTTP transports. Curl is useful for an HTTP endpoint, but a stdio server is launched as a local subprocess and exchanges messages through standard input and output; it has no HTTP endpoint for curl to probe. Check the server’s launch configuration and documentation before sending a request. The MCP transport specification describes Streamable HTTP, while the 2025-11-25 transport specification documents an earlier transport generation.
For an HTTP server, establish its actual endpoint path, supported protocol revision, authentication requirements, and whether it uses Streamable HTTP or the older HTTP+SSE transport. Do not assume every server uses /mcp or accepts the same request body.
Send a request that matches the protocol version
For the 2026-07-28 request format
This example, adapted from Google Cloud’s MCP server codelab, sends a tools/list request to an example local endpoint. Replace the URL with the path configured for your server. The version in the header and request metadata must agree. This lists tools; it does not invoke one.
#1 Best Overall
curl -i -X POST 'http://localhost:8080/mcp'
-H 'Content-Type: application/json'
-H 'Accept: application/json, text/event-stream'
-H 'MCP-Protocol-Version: 2026-07-28'
-H 'Mcp-Method: tools/list'
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/list",
"params": {
"_meta": {
"io.modelcontextprotocol/protocolVersion": "2026-07-28",
"io.modelcontextprotocol/clientInfo": {
"name": "curl-test",
"version": "1.0.0"
},
"io.modelcontextprotocol/clientCapabilities": {}
}
}
}'
The codelab shows an HTTP 200 response with a JSON-RPC result containing a tools array. That is an example, not a guarantee: another server may use a different path, not implement this method, or return a request-scoped SSE response instead of a JSON object.
For an earlier protocol generation
Do not send the July 2026 request unchanged to a server that implements an earlier revision. The 2025-11-25 transport uses an initialize handshake. A server may return an MCP-Session-Id, which must accompany later requests; after negotiation, requests use MCP-Protocol-Version. The July 2026 revision changes request metadata and removes the initialize/session pattern.
Rank #2
For a legacy server, send the version-appropriate initialize request first, then use the negotiated version and any returned session ID in subsequent requests. Confirm the exact payload, endpoint path, and supported revision in that server’s documentation; there is no single legacy payload that applies to every implementation.
Read the HTTP exchange and MCP response separately
The -i option includes response headers and status in curl’s output. Check those alongside the response body: HTTP success only tells you about the HTTP exchange, not whether the requested MCP method returned the intended result. Streamable HTTP can respond with a JSON object or request-scoped SSE, so inspect the content type and body rather than assuming one response format.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
- Expected JSON-RPC result: A valid result for
tools/listindicates the request reached a handler that returned the method result. The Google codelab’s HTTP 200 response is one example. - HTTP 400: In the current transport, an unsupported protocol version produces HTTP 400. Check that the server supports the version sent in both the header and request metadata.
- HTTP 404: An unimplemented RPC method can produce HTTP 404 with a JSON-RPC method-not-found error. A plain 404 or HTML error may instead come from endpoint routing or a proxy. Use the response body and configured path to distinguish them.
- HTTP 401 or 403: Authentication or origin policy may be blocking the request. The specification requires rejecting a supplied invalid
Originwith 403; do not disable security merely to make a probe succeed. - Connection, TLS, or timeout error: Curl did not receive a useful MCP response. Check the hostname, port, path, DNS or network access, TLS trust, server process, and proxy settings. The exact cause depends on the curl output and deployment configuration.
Why curl can work while the AI client still fails
A successful curl exchange shows that a particular request reached an HTTP endpoint and received a response. It does not establish that the AI client is using the same transport, protocol revision, endpoint path, credentials, or handshake. Compare the client’s configuration and version with the request that succeeded.
The official TypeScript SDK connection guide describes legacy initialize behavior as the default and says its auto version-negotiation mode probes server/discover for the 2026-era protocol before falling back to initialize for a 2025-era server. A pinned version era does not fall back. Record the client or SDK version and server protocol revision when comparing behavior; their expected handshakes can differ.
Rank #4
If the endpoint is an older SSE-only server, a successful GET to an arbitrary URL does not prove it supports modern Streamable HTTP: modern client messages use POSTs to the MCP endpoint. The SDK guide recommends trying Streamable HTTP and retrying with its SSE client transport when needed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Keep the endpoint secure while testing
The 2026-07-28 MCP specification states: “Servers MUST validate the Origin header on all incoming connections to prevent DNS rebinding attacks.” It also says local servers SHOULD bind only to 127.0.0.1, rather than 0.0.0.0, and SHOULD implement proper authentication. MUST and SHOULD express different levels of normative force; do not weaken endpoint protections to get a curl response.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

