MCP - The tweet discusses an issue with MCP clients

The tweet discusses an issue with MCP clients needing a real HTTPS URL, and how the MCP daemon provides a public DNS alias record that points back to localhost, which can be a security concern.

Updated: 4/4/2026
4/ Why? Because some MCP clients need a real https URL. https://t.co/7lEKPYhBGk looks like a proper server but never leaves your machine, it's a public DNS alias record that points back to localhost (127.00.1) The daemon prints the exact OS-specific keychain trust command on Source: https://x.com/gubatron/status/2035699779179876534

Did this solve your problem?

0 developers found this helpful