Skip to main content
FrontMCP applies security headers to every HTTP response, including Content Security Policy (CSP), Strict-Transport-Security (HSTS), X-Frame-Options, and X-Content-Type-Options. X-Content-Type-Options: nosniff and X-Frame-Options: DENY are on by default, and X-Powered-By is never sent. Configure the rest with frontmcp.config server settings, with @FrontMcp({ http: { securityHeaders } }), or with FRONTMCP_* environment variables. The Express host and the fetch handler used on Cloudflare Workers, Vercel Edge and Deno share one resolver, so both send the same headers.

Quick Start

Add security headers to frontmcp.config.ts:
frontmcp dev passes this config to the server as environment variables. The cloudflare, vercel, lambda and distributed builds write them into the generated serverless-setup.js, and only where the platform has not already set that variable, so a real environment variable always wins. The node target has no setup file: set the FRONTMCP_* variables where the server runs, or configure http.securityHeaders on @FrontMcp (see below).

CSP Configuration

Value-less CSP directives like upgrade-insecure-requests and block-all-mixed-content are supported — set the value to an empty string ('').

Example Directives

Security Headers

X-Content-Type-Options: nosniff and X-Frame-Options: DENY are applied by default even without explicit configuration. Set contentTypeOptions or frameOptions to false to omit the header (the environment variable equivalent is off).

Decorator Option

The same settings can live on @FrontMcp. This is the only route that works on every target without a build step:
Precedence, highest first: http.securityHeaders, then the FRONTMCP_* variables, then the defaults. csp.enabled: false in the decorator overrides FRONTMCP_CSP_ENABLED.

Environment Variables

The settings map to these variables (see the note above for which commands set them for you): FRONTMCP_HSTS, FRONTMCP_CONTENT_TYPE_OPTIONS and FRONTMCP_FRAME_OPTIONS accept off, false or none to omit the header. A malformed FRONTMCP_HEADERS_CUSTOM is ignored. You can set or override these at runtime without rebuilding:

Programmatic Access

For built-in HTTP transport targets, FrontMCP applies the configured security headers during HTTP response handling. For custom transport adapters, header application is your adapter’s responsibility — wire equivalent logic into the response pipeline yourself. The internal helper utilities are not part of the public @frontmcp/sdk API; if you need them re-exported, open a feature request rather than importing from repository-internal source paths.

Report-Only Mode

Use reportOnly: true to test CSP rules without blocking content:
This sets the Content-Security-Policy-Report-Only header instead of Content-Security-Policy, allowing you to monitor violations before enforcing the policy.

Configuration File

Full configuration reference

Production Build

Build and deploy for production