Minor Changes
-
#2887
edd12e2Thanks @maxisbey! - ConstructingClientCredentialsProvider,PrivateKeyJwtProvider,StaticPrivateKeyJwtProviderorCrossAppAccessProviderwithoutexpectedIssueris deprecated: the constructor logs oneconsole.warnand that call signature is marked@deprecated. Behaviour is otherwise unchanged. Pass theissuerof the authorization server the credentials were registered with.fetchToken()throwsAuthorizationServerMismatchError, before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. TheAuthorizationServerMismatchErrormessage no longer assumes the authorization-code callback; its fields are unchanged.OAuthTokensSchemaandOAuthClientInformationSchemaaccept the optionalissuerstamp, so a provider that reads storage back through them keeps it.auth()overwrites it on every save.
Patch Changes
-
#2885
9dd722fThanks @claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen asunhandledrejectionon Cloudflare Workers) in addition to the returned rejection. -
#2883
c0f7aecThanks @claude! - Fix a type-check failure for CommonJS TypeScript projects introduced in 2.1.0:dist/index.d.ctsimported types fromjose, which is ESM-only, sotscwithmodule: node16/node18andskipLibCheck: falsefailed with TS1479. The twojosetypes used by the DPoP API (CryptoKey,JWK) are now inlined into the declaration files. No runtime change. -
#2768
efebf5bThanks @web-abin! - Correct the JSDoc for insecure OAuth token endpoints. The TLS requirement comes from the MCP authorization specification's OAuth 2.1 communication-security rules, not SEP-2207, which covers OIDC-flavored refresh-token guidance. Documentation only; no runtime behavior change. -
#2729
a4ae2f9Thanks @claude! - Correct theregisterClient@deprecatednotice: Dynamic Client Registration was deprecated by spec PR #2858 (Client ID Metadata Documents), not SEP-2577 (which deprecates roots, sampling, and logging). The notice now also names the earliest possible removal date under the feature lifecycle policy (2027-07-28) and clarifies that theclient_id_metadata_document_supportedgating lives in the built-inauth()flow —registerClientcalled directly always sends the registration request. Documentation only; no runtime behavior change. -
#2862
e780e13Thanks @SyedTashfin! - Preserve_metaoninput_requiredresults. The 2026-07-28 decode seam rebuilt the payload frominputRequestsandrequestStateonly, so result-level metadata a server sent on aninput_requiredresult (includingio.modelcontextprotocol/serverInfo) was dropped before anallowInputRequired: truecaller could see it.Result._metais a result-level field, soinput_requiredcarries it exactly like any other result. -
#2886
ef39308Thanks @claude! -listTools(),listPrompts(),listResources()andlistResourceTemplates()called without a cursor now follownextCursoruntil the server stops sending one, instead of stopping silently with a short list when a cursor repeats; a page that has the same items and the samenextCursoras the page before it ends the walk and is not added twice, andlistMaxPagesstill caps the walk. -
#2642
cfa09dbThanks @claude! - FixClient.listen()rejections escaping as process-level unhandled rejections. The internalopeningpromise could reject (ack timeout, transport close, server cancel, caller abort) whilelisten()was still serially awaitingtransport.send(...), so no rejection handler was attached yet — the rejection surfaced as anunhandledRejectionthat caller-side handling cannot prevent, and a send that never settles (e.g. a stdio write parked on'drain') leftlisten()suspended forever even though the ack timer had already fired.listen()now suspends on theopeningstate machine directly and routes send failures into it, so every termination path rejects the returned promise and nothing escapes. -
#2597
7f7a94cThanks @arimu1! - Treat hostnames ending in.localhostas loopback for the SEP-2207 token-endpoint https guard (RFC 6761 §6.3), so host-based multi-tenant local OAuth works. The SDK does not resolve the name itself:*.localhostreaches the local machine only if the system resolver follows RFC 6761. -
Updated dependencies [
edd12e2]:- @modelcontextprotocol/core@2.2.0