| Package | Version |
|---|---|
@modelcontextprotocol/client
| 2.2.0 |
@modelcontextprotocol/server
| 2.2.0 |
@modelcontextprotocol/core
| 2.2.0 |
@modelcontextprotocol/server-legacy
| 2.2.0 |
@modelcontextprotocol/codemod
| 2.2.0 |
@modelcontextprotocol/node, express, hono, fastify
| unchanged |
Upgrade notes
- Pass
expectedIssuerto the machine-to-machine OAuth providers. ConstructingClientCredentialsProvider,PrivateKeyJwtProvider,StaticPrivateKeyJwtProviderorCrossAppAccessProviderwithout it is deprecated and logs a warning. Set it to theissuerof the authorization server the credentials were registered with. (#2887) fetchToken()checks which authorization server the client information belongs to. It throwsAuthorizationServerMismatchErrorbefore sending anything when the provider's client information is bound to a different authorization server. (#2887)- List calls return the whole list.
listTools(),listPrompts(),listResources()andlistResourceTemplates()called without a cursor now follownextCursoruntil the server stops sending one.listMaxPagesstill caps the walk. (#2886)
Fixes
- CommonJS TypeScript projects type-check again: the
josetypes used by the DPoP API are inlined into the declaration files (regression in 2.1.0). (#2883) Client.listen()no longer lets a rejection escape as a process-level unhandled rejection, and no longer hangs when a send never settles. (#2642)_metais preserved oninput_requiredresults. (#2862)- Hostnames ending in
.localhostcount as loopback for OAuth token endpoints, so host-based multi-tenant local setups work. (#2597) OAuthTokensSchemaandOAuthClientInformationSchemaaccept the optionalissuerfield, so a provider that reads its storage back through them keeps it. (#2887)createMcpHandlerno longer overflows the stack when the factory returns the same server instance for more than one request. Returning a fresh instance per request is still required. (#2778)createMcpHandlerends asubscriptions/listenstream right after the acknowledgement when it honored none of the requested notification types. (#2651)- Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection. (#2885)
- The
v1-to-v2codemod keeps a file's leading comment block and directives above the rewritten imports. (#2582) - Corrected citations in the JSDoc for OAuth token endpoints and for the
registerClientdeprecation notice. (#2768, #2729)
Thanks
@maxisbey, @web-abin, @SyedTashfin, @arimu1, @axits-lab, @vjymisal0 and @sushantkumar23.
Per-package changelogs
client · server · core · server-legacy · codemod