Skip to main content

Module transport

Module transport 

Source
Expand description

WebSocket accept + authorization handshake.

Upgrades an accepted TCP stream to a WebSocket, gating on the x-claude-code-ide-authorization header. A mismatched token is rejected during the handshake with HTTP 401 — the connection never reaches the MCP loop. Loopback bind + this token are the security boundary (design §4).

Functions§

accept
Accept a WebSocket connection on stream, requiring the x-claude-code-ide-authorization header to match expected_token (constant-time). Rejects with HTTP 401 otherwise — the returned future resolves to an error and the connection is dropped.