github modelcontextprotocol/typescript-sdk @modelcontextprotocol/node@2.0.0

Patch Changes

  • #2402 a400259 Thanks @felixweinberger! - First beta release of SDK v2 with support for the MCP 2026-07-28 specification
    revision. See the migration guides for upgrading from v1
    (docs/migration/upgrade-to-v2.md) and adopting the 2026-07-28 revision
    (docs/migration/support-2026-07-28.md).

  • #2405 f172626 Thanks @mattzcarey! - Ship CommonJS builds alongside ESM. Each package now emits both .mjs/.d.mts
    and .cjs/.d.cts (via tsdown format: ['esm', 'cjs']), and its exports map
    adds a require condition so require('@modelcontextprotocol/…') works from
    CommonJS consumers. Output extensions are normalized across all packages
    (@modelcontextprotocol/core moves from .js/.d.ts to .mjs/.d.mts); the
    public import paths are unchanged.

  • #2441 561c6d8 Thanks @felixweinberger! - POSTs whose Content-Type media type is not application/json are now
    rejected with 415 Unsupported Media Type; the header is parsed instead of
    substring-matched. Previously any value merely containing the substring
    passed the check (for example text/plain; a=application/json), case
    variants were wrongly rejected, and the 2026-07-28 entry did not inspect
    Content-Type at all — requests with a missing or non-JSON header that used
    to be served on that path now also answer 415. Values with parameters
    (application/json; charset=utf-8, including malformed parameter sections
    like application/json;) continue to work. SDK clients always send the
    correct header and are unaffected.

    The new isJsonContentType(header) helper is exported for transport and
    framework-adapter authors — custom entries composing the exported building
    blocks (classifyInboundRequest, PerRequestHTTPServerTransport) must apply
    it themselves. The hono adapter's JSON body pre-parse and the client's
    response dispatch now use the same parsed-media-type comparison.

  • #2445 78fabea Thanks @felixweinberger! - Document composing the host and origin validation guards in front of toNodeHandler for hand-wired node:http servers, matching the protected wiring the examples and serving guide now demonstrate.

  • Updated dependencies [a400259, 44797d7, 1b90c96, f172626, 561c6d8, ce2f65d, 1480241, 7c49b47, e0a0ab7, 7e69735, 3c7ddaf, 8e1d2e9, e8de519, f413763, 0ab5d14, 24be404, 470678d, f130e1a, 7635115, 61866d7, 3f07a32]:

    • @modelcontextprotocol/server@2.0.0

Don't miss a new typescript-sdk release

NewReleases is sending notifications on new releases.