Skip to content

< all problems20 · Level 06, MCP

Never Reply to an MCP Notification

medium · debug · MCP

A JSON-RPC request has an id and expects exactly one response. A notification has no id at all and expects silence. notifications/initialized, sent by every MCP client after the handshake, is one.

serve(messages) below replies to everything. The client gets a response with "id": null, cannot match it to any request, and may desynchronise so every later response looks like it belongs to the wrong request.

Fix serve(messages) so it:

  1. Returns one response per request, in order.
  2. Returns nothing at all for a notification, including an unknown one. "Method not found" is still a reply.
  3. Still answers unknown requests with -32601.

The catch: id: 0 is a valid id, and if request.get("id"): treats it as absent.