koala73/worldmonitor · error · McpProxySsrfError

serverUrl host is not allowed

Error message

serverUrl host is not allowed

What it means

SSRF guard error in the MCP proxy: the requested serverUrl resolved to a private or otherwise blocked address. The concrete IP is intentionally omitted from the public message (returning it would let callers probe internal IPs); it is only logged server-side as part of an audit record.

Solutions

  1. Point serverUrl at a public, routable hostname
  2. Do not use loopback, link-local, or RFC1918 addresses — they are blocked by design
  3. Check the server logs for the blocked_address audit entry if you believe this is a false positive
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at api/mcp-proxy.ts:117 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of koala73/worldmonitor@e586b8b4b8 (2026-08-21). Data as JSON: /api/errors/8cfa264a5d740aca. Report an issue: GitHub.

Appendix: source

Thrown at api/mcp-proxy.ts:119

export function proxyUsageIdentityFor(req, identity) {
  if (!identity?.isPremium) {
    return buildUsageIdentity({
      sessionUserId: null,
      isUserApiKey: false,
      enterpriseApiKey: null,
      widgetKey: null,
      clerkOrgId: null,
      userApiKeyCustomerRef: null,
      tier: null,
      planKey: null,
    });
  }

  if (identity.kind === 'internal-mcp') {
    return {
      auth_kind: 'mcp_oauth',
      principal_id: identity.userId,
      customer_id: identity.userId,
      tier: 0,
      plan_key: null,
    };
  }

  const enterpriseApiKey = identity.kind === 'enterprise'
    ? req.headers.get('X-WorldMonitor-Key') ?? req.headers.get('X-Api-Key')
    : null;
  return buildUsageIdentity({
    sessionUserId: identity.userId,
    isUserApiKey: identity.kind === 'user-api-key',
    enterpriseApiKey,
    widgetKey: null,
    clerkOrgId: null,
    userApiKeyCustomerRef: null,
    tier: null,
    planKey: null,
  });

View on GitHub (pinned to e586b8b4b8)