modelcontextprotocol / modelcontextprotocol/java-sdk

Disable standalone GET SSE Stream option for Streamable HTTP client transport

Open
#1,068 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement P3
Dominant language
Java
Stars
3.7k
Forks
1.1k
Avg merge
1d 15h
Merged PRs (30d)
9

Description

Expected Behavior

The HttpClientStreamableHttpTransport.Builder should provide an option to completely disable the GET SSE stream, allowing the client to operate in pure request-response mode:

var transport = HttpClientStreamableHttpTransport.builder("https://example.com")
    .openSseStream(false) // Disable all GET SSE connections
    .build();

When openSseStream(false) is set:

  • No GET request is sent during connect() (regardless of openConnectionOnStartup)
  • No GET request is sent after session initialization in sendMessage()
  • The client operates in pure POST request / response mode
  • Server-initiated notifications and requests outside of POST response streams are not received

This aligns with the MCP specification, which uses MAY (RFC 2119) for the client GET across all spec versions (2025-03-26 and latest 2025-11-25):

The client MAY issue an HTTP GET to the MCP endpoint. This can be used to open an SSE stream, allowing the server to communicate to the client, without the client first sending data via HTTP POST.

Current Behavior

After the first successful POST response (typically InitializeResult), the transport unconditionally opens a GET SSE stream. The relevant code in HttpClientStreamableHttpTransport.sendMessage():

if (transportSession.markInitialized(
        responseEvent.responseInfo().headers().firstValue("mcp-session-id").orElseGet(() -> null))) {
    // Once we have a session, we try to open an async stream for
    // the server to send notifications and requests out-of-band.
    reconnect(null).contextWrite(deliveredSink.contextView()).subscribe();
}

The reconnect(null) call is unconditional — there is no builder flag, callback, or any mechanism to prevent it.

The existing openConnectionOnStartup(false) (which defaults to false) only prevents the eager GET during connect(). It does NOT prevent the GET triggered after the first POST response. There is no combination of existing builder options that achieves "never open a GET SSE stream."

Context

The MCP specification explicitly marks the GET SSE stream as optional — unchanged across both spec versions:

  • 2025-03-26: "The client MAY issue an HTTP GET to the MCP endpoint."
  • 2025-11-25: "The client MAY issue an HTTP GET to the MCP endpoint."

Despite this, the Java SDK provides no way to opt out. The GET stream is unconditionally opened after session initialization, and its lifecycle is difficult to manage:

Alternatives considered:

  • openConnectionOnStartup(false) — does not prevent the post-initialization GET
  • Intercepting at the HttpClient level to return a synthetic 405 Method Not Allowed for GET requests — this tricks the SDK into thinking the server doesn't support SSE streams, and the SDK stops trying. It works, but it's a hack: you have to wrap the HTTP client, intercept by method, and fabricate a response. This should be a first-class builder option, not something consumers need to reverse-engineer from the SDK's 405-handling behavior.

Precedent: The Go SDK already solved this exact problem via go-sdk#729 (merged Jan 11, 2026), adding a DisableStandaloneSSE field to StreamableClientTransport. The Java SDK should provide equivalent functionality.

Proposed fix: Add a builder option (e.g. disableStandaloneSSE(boolean) or openSseStream(boolean)) and guard both GET trigger points with it.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at HttpClientStreamableHttpTransport.Builder and the sendMessage() entry point named in the issue, then trace the GET path from connect() and session initialization. Add a builder option that prevents both standalone GET SSE triggers, and verify that disabled mode sends only POST request/response traffic without opening a GET stream.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
api, networking
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
72/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.