This is the documentation for v2 — looking for the v1 documentation?
Skip to content

MCP TypeScript SDK (V2) / @modelcontextprotocol/hono / hono

hono ​

Interfaces ​

CreateMcpHonoAppOptions ​

Defined in: hono.ts:11

Options for creating an MCP Hono application.

Properties ​

allowedHosts? ​

optional allowedHosts?: string[]

Defined in: hono.ts:26

List of allowed hostnames for DNS rebinding protection. If provided, host header validation will be applied using this list. For IPv6, provide addresses with brackets (e.g., '[::1]').

This is useful when binding to '0.0.0.0' or '::' but still wanting to restrict which hostnames are allowed.

allowedOrigins? ​

optional allowedOrigins?: string[]

Defined in: hono.ts:38

List of allowed origin hostnames for Origin header validation. If provided, Origin validation will be applied using this list (port-agnostic, hostnames only — the same convention as allowedHosts).

When omitted, Origin validation is automatically enabled for localhost-class binds (the same condition as host validation): requests without an Origin header pass, while a present Origin whose hostname is not localhost-class is rejected with 403.

host? ​

optional host?: string

Defined in: hono.ts:16

The hostname to bind to. Defaults to '127.0.0.1'. When set to '127.0.0.1', 'localhost', or '::1', DNS rebinding protection is automatically enabled.

maxRequestBodySize? ​

optional maxRequestBodySize?: number

Defined in: hono.ts:47

Upper bound, in bytes, on a JSON request body the app's body-parsing middleware reads. A larger body is answered 413 before being parsed. Must be a positive number. The counterpart of createMcpExpressApp's jsonLimit.

Default ​
ts
4194304 (4 MiB)

Functions ​

createMcpHonoApp() ​

createMcpHonoApp(options?): Hono

Defined in: hono.ts:78

Creates a Hono application pre-configured for MCP servers.

When the host is '127.0.0.1', 'localhost', or '::1' (the default is '127.0.0.1'), DNS rebinding protection middleware is automatically applied to protect against DNS rebinding attacks on localhost servers.

This also installs a small JSON body parsing middleware (similar to express.json()) that stashes the parsed body into c.set('parsedBody', ...) when the Content-Type media type is application/json. It runs after the Host/Origin validation, and JSON bodies over maxRequestBodySize (4 MiB by default) are answered 413 before being parsed.

Parameters ​

options? ​

CreateMcpHonoAppOptions = {}

Configuration options

Returns ​

Hono

A configured Hono application