Local vs remote MCP server: stdio or Streamable HTTP?

A local MCP server runs on your computer and talks over stdio; a remote one runs elsewhere and is reached by URL over Streamable HTTP. How to choose.

5 min readSume
All posts

A local MCP server runs on your own computer: the AI app launches it as a subprocess and exchanges messages with it over stdio (standard input and output), and it runs with your user account's permissions. A remote MCP server is hosted on the internet rather than your machine and is reached at a URL over Streamable HTTP, usually after an OAuth sign-in or with an API key; it typically serves many clients and doesn't execute code on your machine.

The transport rules come from the MCP specification's Transports page (revision 2025-11-25), MCP's Architecture overview, and its guides to local and remote servers. Client details come from each client's own docs, and all were read on 2026-09-28. Sume's side is from its MCP overview and MCP tools and gates.

What is the difference between a local and a remote MCP server?

Where the server runs decides the rest: the transport, what goes in the client's config, and how it signs in. In a config file such as Cursor's mcp.json, a local entry names a command to run and a remote entry names a URL, as the example below the table shows.

From the MCP Transports spec (2025-11-25), MCP's Architecture overview and remote servers guide, and Cursor's MCP docs, read 2026-09-28.
QuestionLocal MCP serverRemote MCP server
Where does it run?On your computer, launched by the client as a subprocessOn a server, as an independent process that can handle many client connections
Which transport?stdioStreamable HTTP
How many clients does it serve?Typically oneTypically many
What goes in the config?A shell command, such as npx with argsA URL to the server's HTTP endpoint
How does it authenticate?Set up by hand, for example an API key in envOAuth, or a bearer token or API key in a header
Where is it available?On each device where it is installed and configuredFrom any MCP client with an internet connection
{
  "mcpServers": {
    "local-server": {
      "command": "npx",
      "args": ["-y", "mcp-server"]
    },
    "sume": {
      "url": "https://mcp.sume.com/mcp"
    }
  }
}

What is the difference between stdio and Streamable HTTP?

They are MCP's two standard transports. The messages are the same JSON-RPC on both; only the delivery changes. The spec asks clients to support stdio whenever possible.

  • stdio: the client launches the server as a subprocess. The server reads JSON-RPC messages from its standard input and writes messages to its standard output, one per line, and it may write logs to standard error.
  • Streamable HTTP: the server runs as an independent process that can handle multiple client connections at a single endpoint, such as https://example.com/mcp. Every client message is a new HTTP POST, and the server answers each request with one JSON object or opens a Server-Sent Events stream.
  • HTTP+SSE, an older HTTP transport, is deprecated; MCP SSE vs Streamable HTTP explains the change.

Can a local MCP server use HTTP?

Yes. Cursor's docs list both HTTP transports as local or remote, and its remote-server example points at http://localhost:3000/mcp. The spec sets rules for that case: servers must validate the Origin header on every connection, a locally running server should bind only to localhost (127.0.0.1), and servers should require authentication. Without these protections, a remote website could reach a local MCP server through DNS rebinding.

Is a local or a remote MCP server safer?

It depends on what the server can reach. Both MCP's guide and Hugging Face's smolagents docs say to use servers from trusted sources only, and the risks differ:

  • Local: a stdio server executes code on your machine, which smolagents calls its intended function. MCP's guide notes that the filesystem server runs with your user account permissions, so it can perform any file operation you can.
  • Remote: it doesn't execute code on your machine, but it acts on the accounts and data you grant it. MCP's guide says to review the permissions requested during authentication.

Which one should I use?

  • Local, when the work is on your machine. Claude Code's docs call stdio servers ideal for tools that need direct system access or custom scripts.
  • Remote, when the work is a hosted service. MCP's guide calls remote servers ideal for web-based AI applications and for services that require server-side processing or authentication.
  • Check what your client supports. Android Studio's MCP integration doesn't support stdio servers, and Claude's help center says local servers set up in Claude Desktop aren't available in claude.ai.
  • Check where your client connects from. Claude's custom connectors reach a remote server from Anthropic's cloud, so a server on a private network, behind a VPN, or blocked by a firewall won't connect.

Is Sume's MCP server local or remote?

Remote only. Sume's hosted MCP is a remote HTTP server at https://mcp.sume.com/mcp for clients that speak streamable HTTP (what that URL is). You sign in with OAuth or send a Sume API key as Authorization: Bearer or x-api-key, per MCP OAuth and API keys. Sume's docs say hosted MCP cannot read files from your laptop, so a local file path means nothing to it, and Sume's generation requests take media as public HTTPS URLs (Media inputs).

Sume's basics page says hosted MCP still works but is not part of the primary path today.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume