Local vs remote MCP server: stdio or Streamable HTTP?
A local MCP server runs on your computer and talks over stdio; a remote one runs elsewhere and is reached by URL over Streamable HTTP. How to choose.

A local MCP server runs on your own computer: the AI app launches it as a subprocess and exchanges messages with it over stdio (standard input and output), and it runs with your user account's permissions. A remote MCP server is hosted on the internet rather than your machine and is reached at a URL over Streamable HTTP, usually after an OAuth sign-in or with an API key; it typically serves many clients and doesn't execute code on your machine.
The transport rules come from the MCP specification's Transports page (revision 2025-11-25), MCP's Architecture overview, and its guides to local and remote servers. Client details come from each client's own docs, and all were read on 2026-09-28. Sume's side is from its MCP overview and MCP tools and gates.
What is the difference between a local and a remote MCP server?
Where the server runs decides the rest: the transport, what goes in the client's config, and how it signs in. In a config file such as Cursor's mcp.json, a local entry names a command to run and a remote entry names a URL, as the example below the table shows.
| Question | Local MCP server | Remote MCP server |
|---|---|---|
| Where does it run? | On your computer, launched by the client as a subprocess | On a server, as an independent process that can handle many client connections |
| Which transport? | stdio | Streamable HTTP |
| How many clients does it serve? | Typically one | Typically many |
| What goes in the config? | A shell command, such as npx with args | A URL to the server's HTTP endpoint |
| How does it authenticate? | Set up by hand, for example an API key in env | OAuth, or a bearer token or API key in a header |
| Where is it available? | On each device where it is installed and configured | From any MCP client with an internet connection |
{
"mcpServers": {
"local-server": {
"command": "npx",
"args": ["-y", "mcp-server"]
},
"sume": {
"url": "https://mcp.sume.com/mcp"
}
}
}What is the difference between stdio and Streamable HTTP?
They are MCP's two standard transports. The messages are the same JSON-RPC on both; only the delivery changes. The spec asks clients to support stdio whenever possible.
- stdio: the client launches the server as a subprocess. The server reads JSON-RPC messages from its standard input and writes messages to its standard output, one per line, and it may write logs to standard error.
- Streamable HTTP: the server runs as an independent process that can handle multiple client connections at a single endpoint, such as
https://example.com/mcp. Every client message is a new HTTP POST, and the server answers each request with one JSON object or opens a Server-Sent Events stream. - HTTP+SSE, an older HTTP transport, is deprecated; MCP SSE vs Streamable HTTP explains the change.
Can a local MCP server use HTTP?
Yes. Cursor's docs list both HTTP transports as local or remote, and its remote-server example points at http://localhost:3000/mcp. The spec sets rules for that case: servers must validate the Origin header on every connection, a locally running server should bind only to localhost (127.0.0.1), and servers should require authentication. Without these protections, a remote website could reach a local MCP server through DNS rebinding.
Is a local or a remote MCP server safer?
It depends on what the server can reach. Both MCP's guide and Hugging Face's smolagents docs say to use servers from trusted sources only, and the risks differ:
- Local: a stdio server executes code on your machine, which smolagents calls its intended function. MCP's guide notes that the filesystem server runs with your user account permissions, so it can perform any file operation you can.
- Remote: it doesn't execute code on your machine, but it acts on the accounts and data you grant it. MCP's guide says to review the permissions requested during authentication.
Which one should I use?
- Local, when the work is on your machine. Claude Code's docs call stdio servers ideal for tools that need direct system access or custom scripts.
- Remote, when the work is a hosted service. MCP's guide calls remote servers ideal for web-based AI applications and for services that require server-side processing or authentication.
- Check what your client supports. Android Studio's MCP integration doesn't support stdio servers, and Claude's help center says local servers set up in Claude Desktop aren't available in claude.ai.
- Check where your client connects from. Claude's custom connectors reach a remote server from Anthropic's cloud, so a server on a private network, behind a VPN, or blocked by a firewall won't connect.
Is Sume's MCP server local or remote?
Remote only. Sume's hosted MCP is a remote HTTP server at https://mcp.sume.com/mcp for clients that speak streamable HTTP (what that URL is). You sign in with OAuth or send a Sume API key as Authorization: Bearer or x-api-key, per MCP OAuth and API keys. Sume's docs say hosted MCP cannot read files from your laptop, so a local file path means nothing to it, and Sume's generation requests take media as public HTTPS URLs (Media inputs).
Sume's basics page says hosted MCP still works but is not part of the primary path today.
Sources
- MCP specification 2025-11-25: Transports (read 2026-09-28)
- Model Context Protocol: Architecture overview (read 2026-09-28)
- Model Context Protocol: Connect to local MCP servers (read 2026-09-28)
- Model Context Protocol: Connect to remote MCP servers (read 2026-09-28)
- Cursor Docs: Model Context Protocol (MCP) (read 2026-09-28)
- Claude Code Docs: Connect Claude Code to tools via MCP (read 2026-09-28)
- Claude Help Center: Get started with custom connectors using remote MCP (read 2026-09-28)
- Hugging Face smolagents: Tools (read 2026-09-28)
- Android Developers: Add an MCP server (read 2026-09-28)
- MCP overview
- MCP quickstart
- MCP OAuth and API keys
- MCP tools and gates
- Media inputs
- Sume basics
Related posts
More in Developers
- Long polling vs short polling: what's the difference?
Short polling asks on a timer and gets an instant answer; long polling holds each request open until there's news or a timeout, then asks again.
- MCP error codes: what -32601, -32602, and -32001 mean
MCP error codes are JSON-RPC codes. What -32700 to -32603 mean, why -32001 is a client-side timeout, and how a failed tool call differs from both.
- MCP JSON config: what's in mcp.json and why clients differ
An MCP JSON config lists servers by name: a command for local ones, a URL and headers for remote ones. Why the key names differ between clients.
- MCP server API key vs OAuth: which one to use
Use OAuth when a person signs in from Claude, Cursor, or another client; use an API key header for scripts, CI, and headless runs with no browser.
Written by Sume