{"version":"2.1.295","anchor":"mcp-serve-session-tunnel-and-tool-output-protocol","canonical_anchor":"claude-mcp-serve-gains-an-http-transport-port-and-ses","heading":"claude mcp serve gains an HTTP mode and --session-tunnel, limited to cloud-remote sessions","tier":"use","area":"MCP","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295\/e\/mcp-serve-session-tunnel-and-tool-output-protocol","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295","markdown":"### claude mcp serve gains an HTTP mode and --session-tunnel, limited to cloud-remote sessions\n\nIn cloud-remote sessions only, claude mcp serve can run over HTTP, dial a session tunnel, read tokens from a descriptor and return tool output objects\n\n**Unclear.** Whether `--session-tunnel` is meant for direct use or is hidden for hosts only is not stated.\n\n**What**\n\n`claude mcp serve` runs Claude Code as an MCP server, so another program can use its tools. New options appear only when `CLAUDE_CODE_REMOTE` is true and `CLAUDE_CODE_ENVIRONMENT_KIND` is empty; ordinary local installs never see them and stay on stdio with raw results.\n\n- `--transport <transport>` (stdio or http, default stdio), `--port <port>`, `--result-format <format>` (raw or rendered) and `--session-tunnel`.\n\n- With http the server starts listening on the network. `--port` without http fails with `Error: --port only applies to --transport http`, and http must come right after `claude mcp serve`.\n\n- `--session-tunnel` needs `--transport http` and `--port 28471`, and reads one line of JSON on standard input with `session_id`, `session_token` and `api_base_url`. It dials a tunnel that relays tool calls and exits when the token expires or policy refuses. A bad envelope exits with `EX_CONFIG`.\n\n- With `--session-tunnel`, Claude Code can also read one JSON line from a file descriptor (a numbered input channel) holding `oauth_token` and `agent_proxy_token`. A non-empty sign-in token is installed and `CLAUDE_CODE_OAUTH_TOKEN_FILE_DESCRIPTOR` is cleared.\n\n- A relay token can come from `CCR_AGENT_PROXY_TOKEN_FILE_DESCRIPTOR`, refused unless it is a descriptor number of 3 or more and the process has no IPC channel. In a tool container with no session id, the proxy uses that or `agent_proxy_token`, uses the session id `tool-container`, and is disabled with a logged message if neither is given.\n\n- Structured tool output objects are returned only when `CLAUDE_CODE_MCP_SERVE_TOOL_OUTPUT` is on, with allow and deny rules from `CLAUDE_CODE_MCP_SERVE_SETTINGS`. Otherwise requests are refused with a message that it is not on.\n\n- A call can become a request for a person's approval, using `anthropic\/permissionAsks`, `anthropic\/returnToolOutput` and `anthropic\/toolHostInterface`. New served tools include `RunMonitorCommand`, `StageFile` and `PlaceFiles`.\n\n- As a tool-server daemon, hooks from settings or plugins are dropped with a warning, and in http mode the file watcher does not start. An HTTP hook that cannot be asked on certain events gives a 'Refused, and a retry will be too' message.\n\n**Why**\n\nThis lets remote or hosted setups run Claude Code's tools on a machine through a tunnel. Most users will not see it, since it only appears in cloud-remote sessions.\n\n- Area: MCP\n- Names: `--session-tunnel`, `claude mcp serve`\n- Tier: Use it now\n- Useful: 5\/5\n- Signal: 5\/5\n- Scope: individual\n- Heads-up: no"}