Skip to content
Docs menu

For companies

HTTPS reverse proxy

Publish the team server over HTTPS with nginx or Caddy. Tokens must never travel over plain HTTP outside the server itself.

The server listens on plain HTTP on 127.0.0.1:3738. Put a reverse proxy in front of it that terminates TLS. The client bridge refuses plain HTTP for anything except loopback addresses, and it does not follow redirects, so configure clients with the final HTTPS URL, including the trailing slash: https://memory.example.com/mcp/.

What the proxy must do

  • Forward the original Host header. For browser requests the server compares the Origin header with Host and rejects cross-origin calls with 403. If the proxy rewrites Host to 127.0.0.1:3738, the web interface stops working.
  • Pass the Authorization header through unchanged. Both nginx and Caddy do this by default.
  • Allow long requests. One memory operation may take up to TAM_TEAM_OPERATION_TIMEOUT (120 s by default). Set the proxy’s read timeout above that.
  • Allow request bodies up to 1 MB. The server rejects larger bodies with 413.
  • Serve everything (/, /mcp/, /healthz) from the same host name.

Caddy

Caddy obtains and renews certificates automatically and keeps the Host header.

memory.example.com {
	encode gzip
	request_body {
		max_size 2MB
	}
	reverse_proxy 127.0.0.1:3738 {
		transport http {
			read_timeout 180s
		}
	}
}

nginx

With certificates from your usual source (for example certbot):

server {
    listen 443 ssl;
    server_name memory.example.com;

    ssl_certificate     /etc/letsencrypt/live/memory.example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/memory.example.com/privkey.pem;

    client_max_body_size 2m;

    location / {
        proxy_pass http://127.0.0.1:3738;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_read_timeout 180s;
        proxy_send_timeout 180s;
        proxy_buffering off;
    }
}

server {
    listen 80;
    server_name memory.example.com;
    return 301 https://$host$request_uri;
}

The HTTP-to-HTTPS redirect is for browsers only. MCP clients must be configured with the https:// URL directly, because the bridge will not follow the redirect.

Check from outside

curl -s https://memory.example.com/healthz
curl -s -o /dev/null -w "%{http_code}\n" https://memory.example.com/mcp/   # 401 without a token is correct

A 401 with WWW-Authenticate: Bearer on /mcp/ means the proxy works and authentication is enforced.

Access restrictions

Tokens are the only authentication. If the server should be reachable only from the office network or a VPN, restrict it at the proxy or firewall as well (for example nginx allow / deny, or Caddy’s remote_ip matcher).

Found a mistake? Open an issue on GitHub.

Search