github modelcontextprotocol/typescript-sdk v2.2.0
2.2.0

3 hours ago
Package Version
@modelcontextprotocol/client 2.2.0
@modelcontextprotocol/server 2.2.0
@modelcontextprotocol/core 2.2.0
@modelcontextprotocol/server-legacy 2.2.0
@modelcontextprotocol/codemod 2.2.0
@modelcontextprotocol/node, express, hono, fastify unchanged

Upgrade notes

  • Pass expectedIssuer to the machine-to-machine OAuth providers. Constructing ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider or CrossAppAccessProvider without it is deprecated and logs a warning. Set it to the issuer of the authorization server the credentials were registered with. (#2887)
  • fetchToken() checks which authorization server the client information belongs to. It throws AuthorizationServerMismatchError before sending anything when the provider's client information is bound to a different authorization server. (#2887)
  • List calls return the whole list. listTools(), listPrompts(), listResources() and listResourceTemplates() called without a cursor now follow nextCursor until the server stops sending one. listMaxPages still caps the walk. (#2886)

Fixes

  • CommonJS TypeScript projects type-check again: the jose types used by the DPoP API are inlined into the declaration files (regression in 2.1.0). (#2883)
  • Client.listen() no longer lets a rejection escape as a process-level unhandled rejection, and no longer hangs when a send never settles. (#2642)
  • _meta is preserved on input_required results. (#2862)
  • Hostnames ending in .localhost count as loopback for OAuth token endpoints, so host-based multi-tenant local setups work. (#2597)
  • OAuthTokensSchema and OAuthClientInformationSchema accept the optional issuer field, so a provider that reads its storage back through them keeps it. (#2887)
  • createMcpHandler no longer overflows the stack when the factory returns the same server instance for more than one request. Returning a fresh instance per request is still required. (#2778)
  • createMcpHandler ends a subscriptions/listen stream right after the acknowledgement when it honored none of the requested notification types. (#2651)
  • Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection. (#2885)
  • The v1-to-v2 codemod keeps a file's leading comment block and directives above the rewritten imports. (#2582)
  • Corrected citations in the JSDoc for OAuth token endpoints and for the registerClient deprecation notice. (#2768, #2729)

Thanks

@maxisbey, @web-abin, @SyedTashfin, @arimu1, @axits-lab, @vjymisal0 and @sushantkumar23.

Per-package changelogs

client · server · core · server-legacy · codemod

Don't miss a new typescript-sdk release

NewReleases is sending notifications on new releases.