Hi!
In a setup where we have VirtualMCPServer and MCPServerEntry's, response headers sent by the upstream server seem to be swallowed by the VirtualMCPServer.
Example tool that throws:
mcpRouter.all('/mcp', async (ctx, _) => {
const body = ctx.request.body;
const isToolCall =
typeof body === 'object' && body !== null && 'method' in body && body.method === 'tools/call';
if (isToolCall) {
ctx.status = 403;
ctx.set(
'WWW-Authenticate',
'Bearer error="insufficient_scope", error_description="mcp header experiment", scope="mcp.write"',
);
ctx.body = {
error: 'insufficient_scope',
error_description: 'mcp header experiment',
};
return;
}
// SNIP
});
When calling straight to the server responds as such:
HTTP/2 403
server: nginx
date: Wed, 16 Sep 2026 08:41:31 GMT
content-type: application/json; charset=utf-8
content-length: 74
vary: Accept-Encoding
www-authenticate: Bearer error="insufficient_scope", error_description="mcp header experiment", scope="mcp.write" <-- BINGO!
strict-transport-security: max-age=31622400; includeSubDomains
access-control-allow-credentials: true
access-control-allow-methods: OPTIONS
access-control-allow-headers: accept, content-type
access-control-expose-headers: x-request-id, content-disposition
But going through the VirtualMCPServer our header gets swallowed:
HTTP/2 403
server: nginx
date: Wed, 16 Sep 2026 08:42:24 GMT
content-type: application/json
content-length: 94
vary: Accept-Encoding
strict-transport-security: max-age=31622400; includeSubDomains
access-control-allow-credentials: true
access-control-allow-methods: OPTIONS
access-control-allow-headers: accept, content-type
access-control-expose-headers: x-request-id, content-disposition
I couldn't find any configuration options to allow for passthrough response headers, only passthrough request headers. Could this be something that could be added to the project? I'm also willing to contribute if this ranks low in your current priorities.
Thanks!
Hi!
In a setup where we have
VirtualMCPServerandMCPServerEntry's, response headers sent by the upstream server seem to be swallowed by the VirtualMCPServer.Example tool that throws:
When calling straight to the server responds as such:
But going through the VirtualMCPServer our header gets swallowed:
I couldn't find any configuration options to allow for passthrough response headers, only passthrough request headers. Could this be something that could be added to the project? I'm also willing to contribute if this ranks low in your current priorities.
Thanks!