koala73/worldmonitor · error · McpProxySsrfError
serverUrl host is not allowed
Error message
serverUrl host is not allowed
What it means
SSRF guard error in the MCP proxy: the requested serverUrl resolved to a private or otherwise blocked address. The concrete IP is intentionally omitted from the public message (returning it would let callers probe internal IPs); it is only logged server-side as part of an audit record.
Solutions
- Point serverUrl at a public, routable hostname
- Do not use loopback, link-local, or RFC1918 addresses — they are blocked by design
- Check the server logs for the blocked_address audit entry if you believe this is a false positive
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at api/mcp-proxy.ts:117 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of koala73/worldmonitor@e586b8b4b8 (2026-08-21).
Data as JSON: /api/errors/8cfa264a5d740aca.
Report an issue: GitHub.
Appendix: source
Thrown at api/mcp-proxy.ts:119
export function proxyUsageIdentityFor(req, identity) {
if (!identity?.isPremium) {
return buildUsageIdentity({
sessionUserId: null,
isUserApiKey: false,
enterpriseApiKey: null,
widgetKey: null,
clerkOrgId: null,
userApiKeyCustomerRef: null,
tier: null,
planKey: null,
});
}
if (identity.kind === 'internal-mcp') {
return {
auth_kind: 'mcp_oauth',
principal_id: identity.userId,
customer_id: identity.userId,
tier: 0,
plan_key: null,
};
}
const enterpriseApiKey = identity.kind === 'enterprise'
? req.headers.get('X-WorldMonitor-Key') ?? req.headers.get('X-Api-Key')
: null;
return buildUsageIdentity({
sessionUserId: identity.userId,
isUserApiKey: identity.kind === 'user-api-key',
enterpriseApiKey,
widgetKey: null,
clerkOrgId: null,
userApiKeyCustomerRef: null,
tier: null,
planKey: null,
});View on GitHub (pinned to e586b8b4b8)