Agent skill

MCP Dart Streamable HTTP

by leehack in leehack/mcp_dart

A skill your agent uses when serving an MCP server over HTTP with mcpdart or connecting to a remote one: StreamableMcpServer setup, Host and Origin allowlists (DNS rebinding protection), CORS for…

MITAuto-check passedBackend & APIs

Install MCP Dart Streamable HTTP

skills CLI
$ npx skills add leehack/mcp_dart --skill mcp-dart-streamable-http -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install leehack/mcp_dart mcp-dart-streamable-http --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/leehack/mcp_dart.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mcp-dart-streamable-http .claude/skills/mcp-dart-streamable-http && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mcp-dart-streamable-http
GitHub stars
116
Token cost
~2k tokens
SKILL.md length
435 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when serving an MCP server over HTTP with mcpdart or connecting to a remote one: StreamableMcpServer setup, Host and Origin allowlists (DNS rebinding protection), CORS for…

  • Serving an MCP server over HTTP with mcpdart
  • SKILL.md covers Guidelines, Examples and More
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Connecting to a remote one: StreamableMcpServer setup

What it does

MCP Dart Streamable HTTP is an agent skill from leehack/mcp_dart. Use when serving an MCP server over HTTP with mcpdart or connecting to a remote one: StreamableMcpServer setup, Host and Origin allowlists (DNS rebinding protection), CORS for browser clients, bearer-token or OAuth protection with protected-resource metadata, and StreamableHttpClientTransport headers, auth providers and OAuth authorization-code discovery.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering MCP servers, Cross-platform mobile apps and OAuth and OpenID Connect. It works with Model Context Protocol and Dart. The repository describes itself as: Dart implementation of MCP SDK. The licence is MIT.

When your agent uses it

  • Serving an MCP server over HTTP with mcpdart
  • Connecting to a remote one: StreamableMcpServer setup
  • Host and Origin allowlists (DNS rebinding protection)
  • CORS for browser clients

Example prompts

  • “/mcp-dart-streamable-http”

What it can do on your machine

Read from SKILL.md and the folder at commit 69ffef3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are dart).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

MCP Dart Streamable HTTP loads about 2k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 435 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from leehack/mcp_dart at commit 69ffef3, republished under its MIT licence (© leehack). 435 words, ~2,034 tokens.

Download SKILL.mdSave it as .claude/skills/mcp-dart-streamable-http/SKILL.md (or your agent's skills folder).
name
mcp-dart-streamable-http
description
Use when serving an MCP server over HTTP with mcp_dart or connecting to a remote one: StreamableMcpServer setup, Host and Origin allowlists (DNS rebinding protection), CORS for browser clients, bearer-token or OAuth protection with protected-resource metadata, and StreamableHttpClientTransport headers, auth providers and OAuth authorization-code discovery.

Streamable HTTP servers and clients with mcp_dart

Streamable HTTP is the MCP transport for remote servers, browsers, Flutter Web and mobile apps. StreamableMcpServer serves one endpoint (default /mcp), routes MCP 2026-07-28 requests statelessly and manages sessions for initialization-era (MCP 2025-11-25 and earlier) clients. StreamableHttpClientTransport is the matching client transport. Server APIs need dart:io; the client transport also runs on the web.

Guidelines

  • serverFactory runs once per stateless MCP 2026-07-28 request and once per legacy session. Return createMcpServer(services) from it (see the mcp-dart-server project structure) and build application state (databases, caches, clients) once, outside the factory.
  • If you change protocol, pass the same McpProtocol to StreamableMcpServer(protocol: ...) and to the factory's McpServerOptions(protocol: ...).
  • Leave enableDnsRebindingProtection at its default (true), even on localhost. Set allowedHosts to the exact public hostnames and allowedOrigins to the exact browser origins (https://app.example.com), never wildcards. allowedOrigins also drives credentialed CORS.
  • Bind to 127.0.0.1 for local development. StreamableMcpServer listens on plain HTTP: terminate TLS at a reverse proxy or load balancer for remote deployments, and set OAuthProtectedResourceOptions.metadataUri to the public URL when the proxy rewrites scheme, host or port.
  • Authenticate with authenticationHandler: (request) => ... returning StreamableMcpAuthenticationResult.allow(), .unauthorized() or .insufficientScope(scope: ...). Verify the token's signature or introspect it, and check issuer, audience/resource, expiry and scopes. Never trust claims from an unverified token. Host/Origin checks run before authentication. Pass a closure: package:mcp_dart/mcp_dart.dart defaults to web-safe exports, so the analyzer types request as dynamic (it is an HttpRequest at runtime on dart:io), and a tear-off typed Function(HttpRequest) fails analysis.
  • Configure oauthProtectedResource so failures return 401 with a WWW-Authenticate: Bearer resource_metadata="..." challenge and the metadata is served at /.well-known/oauth-protected-resource/<path>. Without it, a failed check is a generic 403. The boolean authenticator hook remains for simple allow/deny checks.
  • Keep the strict defaults (strictProtocolVersionHeaderValidation, rejectBatchJsonRpcPayloads) unless a specific legacy peer requires otherwise. Stop the server with await server.stop().
  • Client: pass static headers through StreamableHttpClientTransportOptions(requestInit: {'headers': {...}}) and tokens through an OAuthClientProvider whose tokens() returns OAuthTokens(accessToken: ...). Load tokens from secure storage; never hard-code, log or persist them in plaintext files.
  • For interactive OAuth, implement OAuthAuthorizationCodeProvider. The transport discovers protected-resource and authorization-server metadata, builds a PKCE S256 URL and calls redirectToAuthorizationUrl. When the redirect arrives, call transport.finishAuthRedirect(code, state: ..., issuer: ...) with the callback's state (and iss when present), then reconnect. Cross-origin authorization servers must be approved with a narrow oauthUriValidator.
  • Legacy HTTP+SSE (SseClientTransport, SseServerManager) is deprecated. Use Streamable HTTP for new integrations.
Show full SKILL.md (45 more words)Show less

Examples

A protected Streamable HTTP server behind a TLS-terminating proxy:

dart
import 'dart:io';

import 'package:mcp_dart/mcp_dart.dart';

void registerTools(McpServer server) {
  server.registerTool(
    'echo',
    description: 'Echo a message.',
    inputSchema: JsonSchema.object(
      properties: {'message': JsonSchema.string()},
      required: ['message'],
    ),
    annotations: const ToolAnnotations(readOnlyHint: true),
    callback: (args, extra) async => CallToolResult(
      content: [TextContent(text: args['message'] as String)],
    ),
  );
}

/// Application-defined: verify the JWT signature or introspect the token and
/// check issuer, audience/resource and expiry. Return its scopes, or null.
Future<Set<String>?> verifyBearerToken(String token) async => null;

Future<StreamableMcpAuthenticationResult> authenticate(
  HttpRequest request,
) async {
  final header = request.headers.value(HttpHeaders.authorizationHeader);
  if (header == null || !header.startsWith('Bearer ')) {
    return const StreamableMcpAuthenticationResult.unauthorized();
  }
  final scopes = await verifyBearerToken(header.substring(7));
  if (scopes == null) {
    return const StreamableMcpAuthenticationResult.unauthorized(
      errorDescription: 'Invalid or expired token',
    );
  }
  if (!scopes.contains('tools:read')) {
    return const StreamableMcpAuthenticationResult.insufficientScope(
      scope: 'tools:read',
    );
  }
  return const StreamableMcpAuthenticationResult.allow();
}

Future<void> main() async {
  final server = StreamableMcpServer(
    serverFactory: (sessionId) {
      final mcpServer = McpServer(
        const Implementation(name: 'echo-server', version: '1.0.0'),
      );
      registerTools(mcpServer);
      return mcpServer;
    },
    host: '0.0.0.0',
    port: 3000,
    path: '/mcp',
    allowedHosts: {'mcp.example.com'},
    allowedOrigins: {'https://app.example.com'},
    authenticationHandler: (request) => authenticate(request),
    oauthProtectedResource: OAuthProtectedResourceOptions(
      metadata: OAuthProtectedResourceMetadata(
        resource: Uri.parse('https://mcp.example.com/mcp'),
        authorizationServers: [Uri.parse('https://auth.example.com')],
        scopesSupported: const ['tools:read'],
      ),
      metadataUri: Uri.parse(
        'https://mcp.example.com/.well-known/oauth-protected-resource/mcp',
      ),
      scope: 'tools:read',
    ),
  );

  await server.start();
  stderr.writeln('Listening on :3000/mcp');
  await ProcessSignal.sigint.watch().first;
  await server.stop();
}

A client that sends a pre-issued bearer token and a custom header:

dart
import 'package:mcp_dart/mcp_dart.dart';

class StaticTokenProvider implements OAuthClientProvider {
  StaticTokenProvider(this._loadToken);

  final Future<String> Function() _loadToken;

  @override
  Future<OAuthTokens?> tokens() async =>
      OAuthTokens(accessToken: await _loadToken());

  @override
  Future<void> redirectToAuthorization() async {
    throw UnauthorizedError('The MCP server rejected the stored token.');
  }
}

Future<void> listRemoteTools(Future<String> Function() loadToken) async {
  final client = McpClient(
    const Implementation(name: 'remote-client', version: '1.0.0'),
  );
  try {
    await client.connect(
      StreamableHttpClientTransport(
        Uri.parse('https://mcp.example.com/mcp'),
        opts: StreamableHttpClientTransportOptions(
          authProvider: StaticTokenProvider(loadToken),
          requestInit: const {
            'headers': {'X-Client-Name': 'remote-client'},
          },
        ),
      ),
    );
    final tools = await client.listTools();
    print(tools.tools.map((tool) => tool.name).join(', '));
  } on UnauthorizedError catch (error) {
    print('Sign-in required: $error');
  } finally {
    await client.close();
  }
}

More

© leehack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/mcp-dart-streamable-http of leehack/mcp_dart.

Open the folder on GitHubat commit 69ffef3

Compare with similar skills

MCP Dart Streamable HTTP next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

MCP Dart Streamable HTTP compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
MCP Dart Streamable HTTP this skillleehack/mcp_dart116—~2kAutomated safety check: PassMIT
Retrieving Developer Knowledgegoogle/skills21k—~2kAutomated safety check: PassApache-2.0
Flutter MCP E2E HarnessArenukvern/mcp_flutter385—~2.2kAutomated safety check: PassMIT
Flutter MCP Toolkit DebugArenukvern/mcp_flutter385—~4.7kAutomated safety check: PassMIT
Review Security ReportPrefectHQ/fastmcp28k—~1.2kAutomated safety check: PassApache-2.0
Xquik MCPXquik-dev/x-twitter-scraper209—~997Automated safety check: PassMIT

Similar skills

  • Official

    Searches, retrieves, and synthesizes official Google developer documentation across Google Cloud, AI/Gemini, Android, Chrome, Web, Flutter, Go, Firebase, and other Google developer platforms.

    21k GitHub stars~2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Flutter MCP E2E Harness

    Arenukvern/mcp_flutter

    A skill your agent uses when writing or running repeatable E2E scenarios for Flutter apps as checked-in Dart with the fluttermcpharness package (packages/harness) — build/launch the app, attach to…

    385 GitHub stars~2.2k tokensUpdated 4 days ago
    MobileAuto-check passed
  • Flutter MCP Toolkit Debug

    Arenukvern/mcp_flutter

    Diagnose problems in a running Flutter app — read logs, evaluate Dart expressions, interpret error envelopes.

    385 GitHub stars~4.7k tokensUpdated 4 days ago
    MobileAuto-check passed
  • Review Security Report

    PrefectHQ/fastmcp

    Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them.

    28k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Xquik MCP

    Xquik-dev/x-twitter-scraper

    Connect, verify, and troubleshoot Xquik's remote MCP server.

    209 GitHub stars~997 tokensUpdated today
    Backend & APIsAuto-check passed
  • Unifapi

    unifapi-agent/agents

    A skill your agent uses when working with UnifAPI public-data APIs or the UnifAPI MCP server: connecting OAuth MCP clients, discovering operations, calling social/search/scrape/news APIs…

    586 GitHub stars~741 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from leehack/mcp_dart

  • MCP Dart Client

    leehack/mcp_dart

    A skill your agent uses when connecting a Dart or Flutter app to a Model Context Protocol (MCP) server with mcpdart: creating an McpClient, launching a local server over stdio or reaching a remote…

    116 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • MCP Dart Server

    leehack/mcp_dart

    A skill your agent uses when building or extending a Model Context Protocol (MCP) server in Dart with mcpdart: structuring the project, creating an McpServer, adding tools, resources, resource…

    116 GitHub stars~4.1k tokensUpdated 2 days ago
    Auto-check passed
  • MCP Developer

    leehack/mcp_dart

    A skill your agent uses when building, testing, debugging, or reviewing Model Context Protocol servers, clients, transports, tools, resources, prompts, and agent host configuration.

    116 GitHub stars~770 tokensUpdated 2 days ago
    Auto-check passed

Questions about MCP Dart Streamable HTTP

What does MCP Dart Streamable HTTP do?

A skill your agent uses when serving an MCP server over HTTP with mcpdart or connecting to a remote one: StreamableMcpServer setup, Host and Origin allowlists (DNS rebinding protection), CORS for…. MCP Dart Streamable HTTP is an agent skill from leehack/mcp_dart. Use when serving an MCP server over HTTP with mcpdart or connecting to a remote one: StreamableMcpServer setup, Host and Origin allowlists (DNS rebinding protection), CORS for browser clients, bearer-token or OAuth protection with protected-resource metadata, and StreamableHttpClientTransport headers, auth providers and OAuth authorization-code discovery.

When should I use MCP Dart Streamable HTTP?

MCP Dart Streamable HTTP fits situations like: serving an MCP server over HTTP with mcpdart; connecting to a remote one: StreamableMcpServer setup; host and Origin allowlists (DNS rebinding protection); CORS for browser clients.

How do I install MCP Dart Streamable HTTP in Claude Code?

Run `npx skills add leehack/mcp_dart --skill mcp-dart-streamable-http -a claude-code`. Or copy the skill folder (skills/mcp-dart-streamable-http in leehack/mcp_dart) into .claude/skills/mcp-dart-streamable-http in your project. Claude Code loads it when a task matches its description.

How do I install MCP Dart Streamable HTTP in Codex?

Run `npx skills add leehack/mcp_dart --skill mcp-dart-streamable-http -a codex`. Or copy the skill folder (skills/mcp-dart-streamable-http in leehack/mcp_dart) into .agents/skills/mcp-dart-streamable-http in your project. Codex loads it when a task matches its description.

Can I use MCP Dart Streamable HTTP in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add leehack/mcp_dart --skill mcp-dart-streamable-http -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-dart-streamable-http, .gemini/skills/mcp-dart-streamable-http, .github/skills/mcp-dart-streamable-http and .opencode/skills/mcp-dart-streamable-http in your project.

What does MCP Dart Streamable HTTP need to run?

SKILL.md names no scripts, command-line tools or credentials: MCP Dart Streamable HTTP is instructions for the agent only.

Does MCP Dart Streamable HTTP access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is MCP Dart Streamable HTTP safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does MCP Dart Streamable HTTP use?

MCP Dart Streamable HTTP is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does MCP Dart Streamable HTTP use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to MCP Dart Streamable HTTP?

Skills that share tags, products or a category with MCP Dart Streamable HTTP: Retrieving Developer Knowledge (google/skills, 21k stars), Flutter MCP E2E Harness (Arenukvern/mcp_flutter, 385 stars), Flutter MCP Toolkit Debug (Arenukvern/mcp_flutter, 385 stars) and Review Security Report (PrefectHQ/fastmcp, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains MCP Dart Streamable HTTP?

leehack (a GitHub user) maintains it in leehack/mcp_dart, which has 116 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 5, 2026.

Source: leehack/mcp_dart on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.