McpValidationFilter
Validates Model Context Protocol (MCP) requests:
| This feature has Evolving interface stability. It’s subject to change without notice, even in a minor or maintenance release. |
-
Validates the
Originheader against a list of allowed origins. -
Validates the
Acceptheader content types. -
Validates the JSON-RPC format of the payload.
-
Validates the MCP client message format, excluding the
toolsschemas. -
Rewrites the MCP protocol version in the
initializerequest to the supported version. PingGateway supports versions2025-06-18and2025-11-25(new in 2026.6). -
Adds an McpContext for further processing.
-
Optionally records metrics for MCP requests.
|
If your MCP server uses server-sent events (SSE), make sure you enable streaming in PingGateway. |
Usage
{
"name": string,
"type": "McpValidationFilter",
"config": {
"acceptedOrigins": [ configuration expression<pattern>, … ],
"metricsEnabled": configuration expression<boolean>,
"maxMetricParamValues": configuration expression<number>,
"preferredServerVersion": configuration expression<string>
}
}
}
Properties
"acceptedOrigins": array of configuration expression<pattern>, required-
Pattern or array of patterns matching the accepted origins for MCP requests.
The filter uses this for cross-origin request sharing (CORS) validation of the
Originheader.In PingGateway 2026.3 and 2026.6, the pattern isn’t anchored. Use an anchored pattern in your settings, such as
"acceptedOrigins": "^https://example.com$". Don’t use a pattern likeexample.comalone, because that matches any origin containingexample.com, includinghttp://malicious-example.com. "metricsEnabled": configuration expression<boolean>, optional-
Whether to record metrics for MCP requests.
Default:
true "maxMetricParamValues": configuration expression<number>, optional-
The maximum number of distinct tool, prompt, and resource names tracked in MCP metrics per method. Beyond this value, PingGateway groups the metrics into an "other" category.
This feature requires PingGateway 2026.9 or later. Default: 1000
"preferredServerVersion": configuration expression<string>, optional-
The preferred protocol version of the protected MCP server.
This feature requires PingGateway 2026.6 or later. Default: the latest supported version, currently
2025-11-25