Comment by 1vuio0pswjnm7
4 days ago
I don't use "AI" but I'm using "MCP" to remotely control software running on another computer on the local network by sending JSON-RPC with netcat
I send an Authorization header with a Bearer token but the procedure calls are sent in cleartext. Is this how "MCP" server is typically implemented (no encryption)
NB. I didn't write the aforementioned software implementing "MCP" server, that's someone else's work
> Is this how "MCP" server is typically implemented (no encryption).
No idea. The boring (in a positive sense) answer I'd expect for any backend API server is that encryption in transit is handled by TLS. So I'd expect either the MCP server in question can be configured to support TLS connections & refuse plaintext HTTP connections, or that for a production-like deployment it expects to be deployed behind a reverse proxy that is responsible for terminating TLS.