Project releases
Ruflo 3.55 adds an authentication gate for network-facing MCP
Non-loopback MCP HTTP binds now require authentication by default; token-protected tools and the minimal public health route remain separate.
GitHub activity: · Published:
The remote authentication boundary
Authentication separates accepted and rejected requests—not permissions for individual tools.
Explanatory diagram · not live telemetryRemote client
Network-facing HTTP request
Bearer-token gate
Credential required off loopback
Authenticated → tools
Token grants every tool
No token → refused
Protected /rpc, /mcp and /info
Public /health
Minimal response; separate route
What changed
Ruflo 3.55 refuses to start an MCP HTTP server off loopback unless authentication is configured or the operator explicitly opts out. With a token, /rpc, /mcp and /info require it; a minimal /health endpoint stays public. Existing Docker or LAN launch configurations may need adjustment when upgrading.
The release also adds operator-credential checks to remote hive-mind operations and strengthens policy receipts against a missing or truncated local anchor. These are separate safeguards, not a full security audit. A valid HTTP token grants every MCP tool; loopback without a token still accepts local callers. An attacker able to rewrite both ledger copies still requires an external witness to be detected reliably.
Get started
For existing Node >=20 Ruflo installations, review launch configuration rather than starting a new network service from this article. npm view should report 3.55.0.
Documentation-verified only. We did not install this release, execute these commands or reproduce the maintainers’ tests.
npm view ruflo@3.55.0 version
The release is the authority for the local HTTP contract: protected /rpc, /mcp, /info and public /health. No hosted endpoint or new skills integration was verified.
Use it today
Audit existing HTTP launch configuration before upgrading. The release documents RUFLO_MCP_HTTP_TOKEN or --auth-token-file; manage the token securely and verify unauthenticated tool requests are refused. Do not treat the opt-out as normal setup.
Experimental commentary — acceptance test
Acceptance: a request without credentials is refused, a valid credential reaches the intended service, and /health stays minimal. This does not establish per-tool authorization, DNS-rebinding protection or a complete security assessment.
Limits and verification
- Loopback HTTP is not automatically authenticated. The release recommends a token whenever HTTP transport is used.
- No Host allow-list / DNS-rebinding protection is claimed. Remote hive-mind controls differ from local CLI/stdio.
- A token grants all tools. No token values or public server setup appear here.