npm @modelcontextprotocol/sdk 1.32.0

4 hours ago

Upgrade notes

  • Redirects: the HTTP client transports now follow a redirect only when it stays on the same origin (same scheme, host and port; http to https on the same host is allowed). A deployment whose endpoint redirects to another host or port either configures the final URL or sets redirectPolicy: 'follow' on StreamableHTTPClientTransport or SSEClientTransport. In browsers, a redirected request fails unless that option is set.
  • New options, both off unless you set them: maxToolInputElements on McpServer limits the number of array elements and object members in a tool call's arguments. expectedResource on requireBearerAuth accepts only tokens issued for this server (the token's audience).

What's Changed

  • [v1.x] fix(client): follow redirects only within the endpoint's origin by @claude[bot] in #2902
  • docs: point SECURITY.md at GitHub Security Advisories (v1.x) by @claude[bot] in #2910
  • [v1.x] examples: close idle sessions and cap the session map by @maxisbey in #2914
  • [v1.x] fix(tasks): keep tasks of the in-memory task store within the session that created them by @claude[bot] in #2925
  • [v1.x] feat(server): add maxToolInputElements option to limit the number of elements in tool-call arguments by @claude[bot] in #2927
  • [v1.x] fix(server): accept tools/call and prompts/get requests that omit arguments by @raashish1601 in #2045
  • [v1.x] feat(auth): add expectedResource to requireBearerAuth by @claude[bot] in #2930
  • [v1.x] test(e2e): cover tools/call and prompts/get without arguments by @claude[bot] in #2931
  • chore: bump version to 1.32.0 by @claude[bot] in #2935

New Contributors

Full Changelog: 1.31.0...1.32.0

Don't miss a new sdk release

NewReleases is sending notifications on new releases.