github modelcontextprotocol/typescript-sdk @modelcontextprotocol/server-legacy@2.3.1

latest releases: v2.3.1, @modelcontextprotocol/core@2.3.1
3 hours ago

Patch Changes

  • #2952 5a18673 Thanks @claude! - requireBearerAuth in @modelcontextprotocol/server-legacy takes the optional expectedResource that @modelcontextprotocol/server 2.3.0 and @modelcontextprotocol/sdk 1.32.0 added: the resource the token must be issued for (its audience), usually the server's URL. When it is set, a token is accepted only if the verifier reports that value in AuthInfo.resource; the two are compared as strings, ignoring a fragment and one trailing slash. A token reported for another value, or for none, is answered 401 invalid_token with the usual WWW-Authenticate challenge. When it is not set, nothing changes. The package stays frozen otherwise; this option is added so that its requireBearerAuth matches the 1.x middleware it is a copy of.

  • Updated dependencies []:

    • @modelcontextprotocol/core@2.3.1

Don't miss a new typescript-sdk release

NewReleases is sending notifications on new releases.