Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To create a remote MCP server, choose a remote transport, define a small set of tools, deploy an HTTP endpoint, and connect an MCP client to that endpoint. Cloudflare’s current guidance uses Streamable HTTP for remote servers and presents Cloudflare Workers as one implementation route—not the only way to host MCP. The steps below follow that platform-specific workflow and explain where authentication and testing fit.
What makes an MCP server remote?
MCP servers expose tools and other capabilities to compatible clients. A local server commonly communicates over stdio, with the client starting a local process. A remote server is reached over a network; Cloudflare’s current transport guidance points new remote implementations to Streamable HTTP. Its documentation marks the older remote Server-Sent Events (SSE) transport as deprecated for this use.
That distinction affects how you deploy and connect, but it does not decide where the server must run. Cloudflare Workers are one documented hosting option. Other platforms may also host MCP servers; the workflow here describes Cloudflare’s choices rather than a universal set of commands or SDK requirements.
Transport and SDK details can change. Confirm the current MCP transport guidance and the instructions for the SDK and deployment platform you choose before implementing or migrating a server.
#1 Best Overall
Plan the tools, state, and access before building
Design tools around tasks
Start with the user’s intended tasks, then expose only the operations needed to complete them. Avoid turning an entire upstream API into a tool catalogue. Give each tool a clear purpose and document its parameters carefully so clients can choose and call it appropriately. After changing tool behavior or descriptions, evaluate that behavior with representative requests.
Decide whether the server needs state
Cloudflare’s build guide distinguishes a stateless handler, legacy compatibility routes, and stateful approaches. For a new stateless server, it recommends the createMcpHandler() route. That recommendation is specific to the documented Cloudflare workflow.
Do not switch to a stateless route without checking what your server relies on. If it depends on sessions, RPC behavior, pushed requests, streams, or replay, review Cloudflare’s stateful and compatibility guidance first. The available guidance identifies those distinctions but does not establish that one route suits every server.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteDecide who can use it
A server that exposes only public, non-sensitive capabilities may be configured without authentication in the documented example. If it accesses user accounts or acts on a user’s behalf, plan authentication and authorization before exposing it. Cloudflare documents Cloudflare Access and third-party OAuth options; authorization should limit users to the actions and data they have approved.
Build and deploy the Cloudflare example
The workflow below follows Cloudflare’s documented path at a high level. Consult the current Cloudflare Developers Documentation guide, “Build a Remote MCP server,” for its exact project setup, SDK version, configuration, and deployment commands. Those implementation details are platform- and version-specific, and no generic command recipe should be inferred from this outline.
Rank #2
- Choose Streamable HTTP. Use the current remote transport rather than starting a new implementation on the deprecated remote SSE transport.
- Create a stateless server if that matches your requirements. In Cloudflare’s example, use its
createMcpHandler()route for a new stateless server. If your server requires sessions or other stateful behavior, use the guide’s relevant stateful or compatibility approach instead. - Define a focused set of tools. Implement the operations needed for the intended user tasks. Make tool names and parameter descriptions specific, and enforce narrow permissions in the operations that access protected resources.
- Run the server locally. Follow the guide’s project-specific instructions, start the local server, and note its MCP endpoint. Do not assume a local URL or port; those depend on the project configuration.
- Test locally with MCP Inspector. Connect Inspector to the local endpoint and verify that it connects and discovers the tools you intended to expose.
- Deploy with Wrangler or the guide’s repository-based flow. Use the deployment workflow documented for your project. Store credentials using the platform’s secret-management facilities; the Cloudflare example uses Wrangler secrets rather than embedding credentials in source code.
- Test the deployed endpoint. Point MCP Inspector or another compatible client at the deployed URL. Confirm that it connects and discovers the intended tools before relying on it from an application.
Cloudflare’s guide also covers an unauthenticated example and OAuth-based authorization. An open endpoint is not appropriate merely because it is easier to test: decide access controls based on the data and actions the tools expose.
Secure and maintain the server
Use scoped authorization
For user-account access, authenticate the user and authorize only the permitted operations. Cloudflare’s access-control documentation describes Cloudflare Access and third-party OAuth options. The precise configuration depends on the identity provider and deployment; the documented options should not be read as a guarantee that an endpoint is secure by default.
Keep client secrets out of source code. Use the hosting platform’s secret-management mechanism, such as Wrangler secrets in the Cloudflare example, and avoid exposing credentials through tool parameters or responses.
Keep the tool surface small
Tool descriptions are part of the interface clients use to decide what to call. State what each tool does, explain its parameters, and avoid permissions broader than the task requires. Test behavior after changes to descriptions, operations, or authorization so a seemingly small edit does not unexpectedly broaden access or alter results.
Test connection and tool discovery
MCP Inspector is the documented testing choice in the Cloudflare workflow. Test both the local endpoint during development and the deployed endpoint after deployment; success in one environment does not prove the other is configured correctly.
Rank #3
- Confirm Inspector can connect to the endpoint.
- Check that the intended tools are listed, with clear names and parameter descriptions.
- Exercise representative tool calls and verify that results match the expected task.
- For protected capabilities, check that authorization is required and that access is limited to the intended user permissions.
- Repeat relevant checks after changing tool behavior, tool descriptions, transport, or access configuration.
Choose the implementation path that fits
| Decision | Cloudflare guidance | What to verify |
|---|---|---|
| Remote transport | Streamable HTTP; remote SSE is deprecated for new use | Current protocol and SDK support |
| Server state | createMcpHandler() for a new stateless server; separate stateful and compatibility approaches are described |
Whether you rely on sessions, RPC, pushed requests, streams, or replay |
| Authentication | An unauthenticated example is possible; Cloudflare Access and third-party OAuth are documented options | Whether tools touch user accounts, data, or actions that need authorization |
| Testing | MCP Inspector or a compatible client | Connection, tool discovery, representative calls, and permissions locally and remotely |
| Hosting workflow | Workers deployment with Wrangler or the documented repository-based flow | Current project setup, runtime configuration, secrets, and deployment steps in Cloudflare’s guide |
This is a comparison of choices in Cloudflare’s documented workflow, not a provider-wide feature or price comparison. The available material does not establish which hosting provider is cheapest or best for every workload.
Recommended Free Tools
Troubleshoot common failures
The client cannot connect
Check that you are using the deployed endpoint for a remote connection, that deployment completed, and that the client is configured for the transport the server supports. If the server was built around remote SSE, revisit the current transport guidance; Cloudflare marks that transport deprecated for this use.
The client connects but lists no tools
Inspect the server’s tool definitions and the route that handles MCP requests. Use Inspector to check discovery against the local endpoint, then compare it with the deployed endpoint. A local success and remote failure point to a difference in deployment or configuration, but the exact cause depends on the project.
A stateless route does not support expected behavior
Review whether the implementation depends on sessions, RPC, pushed requests, streams, or replay. Cloudflare’s guide distinguishes stateless, stateful, and legacy compatibility approaches; select the route that matches those requirements rather than assuming the stateless handler is interchangeable.
Protected operations are available without the intended authorization
Review the access-control configuration and the permissions enforced by each tool. For user-account access, use authentication and authorization, narrow the actions the user grants, and verify the behavior with authorized and unauthorized test cases. Do not treat the presence of an OAuth provider as proof that every tool is properly scoped.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #4
Credentials are missing after deployment
Check that required secrets were configured through the platform’s secret-management workflow and are available to the deployed server. Do not fix a missing secret by committing it to source code.
Or skip the browser setup
If the MCP server you need is specifically for website screenshots, ScreenshotNeo offers a remote screenshot API and an MCP server with take_screenshot, get_page_info, and capture_pdf tools. It is not a general-purpose replacement for the Cloudflare MCP server build above. For one website screenshot, a single GET request can return an image or PDF:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for parameters and setup. ScreenshotNeo accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status. Its MCP server lets compatible AI agents take screenshots. The free plan includes 1,000 shots a month with no card; paid plans start at $5 for 3,000 shots. Sign up for 1,000 free screenshots a month, with no card required.
Frequently Asked Questions
Is a remote MCP server the same thing as a local MCP server?
No. The connection mode differs: Cloudflare describes local connections using stdio and remote connections using Streamable HTTP.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteCan I expose a remote MCP server without OAuth?
Cloudflare documents a public no-auth example. Whether that is appropriate depends on the data and actions the server exposes; access to user accounts calls for authentication and authorization.
Is Streamable HTTP the only way to host an MCP server?
This article describes Cloudflare’s current remote guidance, which points to Streamable HTTP. It does not establish a provider-neutral rule for every hosting platform or implementation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

