Skip to main content

fastmcp.cli.apps_dev_security

Browser session, Host, and Origin checks for the fastmcp dev apps host.

Classes

DevSessionMiddleware

Require a browser session started from the private startup URL. GET /?token=... with the startup token sets an HttpOnly, SameSite=Strict cookie and redirects to /. Every other request needs that cookie. The cookie holds a separate session secret: browsers send cookies to every port on the host, and the startup token must not reach other services. Every request must also name this server in its Host header, and browser requests must come from this origin: cookies do not distinguish ports on the same host, so the Origin and Fetch Metadata headers are checked too.