Release /
xiaohongshu-mcp v2.5.0
Require a bearer token before clients can call the HTTP API or MCP tools.
What changed in v2.5.0
`AUTH_TOKEN` or a nonempty `-token` enables optional authentication; the command-line value takes precedence. Health checks and CORS preflight remain public.
v2.5.0; authentication is disabled unless a token is configured.
New things you can do
Seeded by @iluxav with Codex, from the release's public sources. Each change links to its evidence.