github modelcontextprotocol/typescript-sdk v2.3.0
2.3.0

3 hours ago
Package Version
@modelcontextprotocol/client 2.3.0
@modelcontextprotocol/server 2.3.0
@modelcontextprotocol/core 2.3.0
@modelcontextprotocol/server-legacy 2.3.0
@modelcontextprotocol/codemod 2.3.0
@modelcontextprotocol/node 2.1.1
@modelcontextprotocol/express, hono 2.0.2
@modelcontextprotocol/fastify 2.0.1

Upgrade notes

  • One server per request. Server.connect() now rejects while the instance is already connected, and a stateless Streamable HTTP transport handles one request. Create the McpServer and the transport inside the request handler (or in the createMcpHandler factory) instead of sharing one instance across requests. Creating a server is cheap since #2889. (#2918)
  • Redirects stay on the same origin. The HTTP client transports now follow a redirect only when it stays on the same origin (same scheme, host and port; http to https on the same host is allowed). A deployment whose endpoint redirects to another host or port either configures the final URL or sets redirectPolicy: 'follow' on the transport. In browsers, a redirected request fails unless that option is set. (#2901)
  • New options, both off unless you set them. maxToolInputElements on McpServer limits the number of array elements and object members in a tool call's arguments. expectedResource on requireBearerAuth / verifyBearerToken accepts only tokens issued for this server (the token's audience); with Express, upgrade @modelcontextprotocol/express together with @modelcontextprotocol/server. (#2926, #2929)
  • prompts/get without arguments is validated as {}, as tools/call already is. A top-level .optional() or .default(...) on a prompt's argsSchema no longer sees undefined. (#2107)
  • The client requires eventsource-parser 3.0.8 or later. It cuts the time and memory needed to receive a large message sent as a single SSE event: in our test a 100 MB tool result went from about a minute and 1.7 GB of peak memory to under a second and about 0.5 GB. (#2846)

New

  • validateOriginHeader and the allowedOrigins option of the Express, Fastify and Hono app helpers accept <scheme>://* entries such as moz-extension://*, so a server can admit MCP clients that run as a browser extension. (#2907)
  • tasks/get and tasks/cancel of the Tasks extension can be served and called on a 2026-07-28 connection. (#2599)

Fixes

  • A large message received as a single SSE event over Streamable HTTP is fast again: a 50 MB tool result that took about 13 seconds arrives in under a second. (#2846)
  • prompts/get without arguments no longer fails when every argument of the prompt is optional. (#2107)
  • SSEClientTransport refreshes once after a 401 on connect instead of retrying without limit. (#2905, #2934)
  • registerTool no longer converts tool schemas up front, so a server built per request stops converting every tool on every request. (#2889)
  • hono is a regular dependency of @modelcontextprotocol/node, so installs with strict peer-dependency checking no longer fail. (#2897)
  • A server/discover probe answered with an unusable 2xx reply now says so instead of reading like a network failure. (#2903)
  • McpServer.registerPrompt() types the callback correctly when no argsSchema is given. (#2841)
  • The license field of the package manifests is Apache-2.0. (#2908)

Don't miss a new typescript-sdk release

NewReleases is sending notifications on new releases.