| Package | Version |
|---|---|
@modelcontextprotocol/client
| 2.3.0 |
@modelcontextprotocol/server
| 2.3.0 |
@modelcontextprotocol/core
| 2.3.0 |
@modelcontextprotocol/server-legacy
| 2.3.0 |
@modelcontextprotocol/codemod
| 2.3.0 |
@modelcontextprotocol/node
| 2.1.1 |
@modelcontextprotocol/express, hono
| 2.0.2 |
@modelcontextprotocol/fastify
| 2.0.1 |
Upgrade notes
- One server per request.
Server.connect()now rejects while the instance is already connected, and a stateless Streamable HTTP transport handles one request. Create theMcpServerand the transport inside the request handler (or in thecreateMcpHandlerfactory) instead of sharing one instance across requests. Creating a server is cheap since #2889. (#2918) - Redirects stay on the same origin. The HTTP client transports now follow a redirect only when it stays on the same origin (same scheme, host and port; http to https on the same host is allowed). A deployment whose endpoint redirects to another host or port either configures the final URL or sets
redirectPolicy: 'follow'on the transport. In browsers, a redirected request fails unless that option is set. (#2901) - New options, both off unless you set them.
maxToolInputElementsonMcpServerlimits the number of array elements and object members in a tool call's arguments.expectedResourceonrequireBearerAuth/verifyBearerTokenaccepts only tokens issued for this server (the token's audience); with Express, upgrade@modelcontextprotocol/expresstogether with@modelcontextprotocol/server. (#2926, #2929) prompts/getwithoutargumentsis validated as{}, astools/callalready is. A top-level.optional()or.default(...)on a prompt'sargsSchemano longer seesundefined. (#2107)- The client requires
eventsource-parser3.0.8 or later. It cuts the time and memory needed to receive a large message sent as a single SSE event: in our test a 100 MB tool result went from about a minute and 1.7 GB of peak memory to under a second and about 0.5 GB. (#2846)
New
validateOriginHeaderand theallowedOriginsoption of the Express, Fastify and Hono app helpers accept<scheme>://*entries such asmoz-extension://*, so a server can admit MCP clients that run as a browser extension. (#2907)tasks/getandtasks/cancelof the Tasks extension can be served and called on a 2026-07-28 connection. (#2599)
Fixes
- A large message received as a single SSE event over Streamable HTTP is fast again: a 50 MB tool result that took about 13 seconds arrives in under a second. (#2846)
prompts/getwithoutargumentsno longer fails when every argument of the prompt is optional. (#2107)SSEClientTransportrefreshes once after a 401 on connect instead of retrying without limit. (#2905, #2934)registerToolno longer converts tool schemas up front, so a server built per request stops converting every tool on every request. (#2889)honois a regular dependency of@modelcontextprotocol/node, so installs with strict peer-dependency checking no longer fail. (#2897)- A
server/discoverprobe answered with an unusable 2xx reply now says so instead of reading like a network failure. (#2903) McpServer.registerPrompt()types the callback correctly when noargsSchemais given. (#2841)- The
licensefield of the package manifests isApache-2.0. (#2908)