Zum Inhalt springen

Model Context Protocol Release Notes

39 Einträge aus 2 Quellen. Zuletzt aktualisiert:

Folge Model Context Protocol, um die Release Notes in deinen Feed zu holen.

Model Context Protocol-Produkte (2)

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Typescript SDK von Model Context Protocol

@modelcontextprotocol/core 2.2.0: expectedIssuer und Issuer-Prüfung

In @modelcontextprotocol/core 2.2.0 ist das Erstellen von ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider oder CrossAppAccessProvider ohne expectedIssuer veraltet, fetchToken() wirft bei abweichendem Authorization Server einen AuthorizationServerMismatchError, und die Schemas akzeptieren einen optionalen issuer-Stempel.

Minor Changes

  • #2887 edd12e2 Thanks @maxisbey! - Constructing ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked @deprecated. Behaviour is otherwise unchanged. Pass the issuer of the authorization server the credentials were registered with.

    fetchToken() throws AuthorizationServerMismatchError, before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. The AuthorizationServerMismatchError message no longer assumes the authorization-code callback; its fields are unchanged.

    OAuthTokensSchema and OAuthClientInformationSchema accept the optional issuer stamp, so a provider that reads storage back through them keeps it. auth() overwrites it on every save.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Typescript SDK von Model Context Protocol

@modelcontextprotocol/codemod 2.2.0: v1-to-v2 erhält Header und Direktiven

Der v1-to-v2-Codemod in @modelcontextprotocol/codemod 2.2.0 setzt umgeschriebene Imports an die Stelle des ersten v1-Imports, sodass Lizenz-Header und Direktiven wie 'use client' erhalten bleiben, wobei in einigen Fällen noch bekannte Lücken bestehen.

Patch Changes

  • #2582 f091897 Thanks @axits-lab! - The v1-to-v2 codemod now writes rewritten imports where the first v1 import stood, not at the top of the file, so a license header, // @ts-nocheck, /// <reference> or a 'use client' / 'use server' / 'use strict' directive above it stays in place. Known gap: when a later step of the codemod replaces or removes the import (for example a file whose only SDK import is ErrorCode or StreamableHTTPError), the new import can still land above or inside the header, and a /** */ header can be removed. Files already migrated with codemod 2.1.0 or earlier are not repaired; check the top of those files.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Typescript SDK von Model Context Protocol

@modelcontextprotocol/client 2.2.0: expectedIssuer für Auth-Provider empfohlen

In @modelcontextprotocol/client 2.2.0 ist das Erstellen von ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider oder CrossAppAccessProvider ohne expectedIssuer veraltet, fetchToken() wirft bei abweichendem Authorization Server einen AuthorizationServerMismatchError, und die Schemas akzeptieren einen optionalen issuer-Stempel.

Minor Changes

  • #2887 edd12e2 Thanks @maxisbey! - Constructing ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked @deprecated. Behaviour is otherwise unchanged. Pass the issuer of the authorization server the credentials were registered with.

    fetchToken() throws AuthorizationServerMismatchError, before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. The AuthorizationServerMismatchError message no longer assumes the authorization-code callback; its fields are unchanged.

    OAuthTokensSchema and OAuthClientInformationSchema accept the optional issuer stamp, so a provider that reads storage back through them keeps it. auth() overwrites it on every save.

Patch Changes …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Typescript SDK von Model Context Protocol

TypeScript SDK Version 1.30.1: Body- und Batch-Limits, Auth-Fix

Version 1.30.1 des TypeScript SDK liest HTTP-Request-Bodys mit Größenlimit, begrenzt die Länge von JSON-RPC-Batches und behebt in der Authentifizierung den Verlust des Resource-URI ohne abschließenden Schrägstrich.

What's Changed

New Contributors

Full Changelog: https://github.com/modelcontextprotocol/typescript-sdk/compare/1.30.0...1.30.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Typescript SDK von Model Context Protocol

@modelcontextprotocol/server 2.1.0: OAuth-Scope-Challenges per scopeChallenge

@modelcontextprotocol/server 2.1.0 fügt für Tools, Ressourcen, Resource Templates und Prompts anfragezeitliche OAuth-Scope-Challenges über einen scopeChallenge-Callback hinzu, die bei unzureichendem Scope vor der Verarbeitung eine HTTP-403-Antwort mit insufficient_scope liefern.

Minor Changes

  • #1624 6032170 Thanks @SamMorrowDrums! - Add request-time OAuth scope challenges for tools, resources, resource templates, and prompts. Each primitive's scopeChallenge callback receives the parsed request and verified authentication info, then either continues or returns the exact scope set for an insufficient_scope response. requireScopes provides a small helper for static all-of checks.

    createMcpHandler and Streamable HTTP transports return HTTP 403 with an insufficient_scope challenge before handler execution or SSE setup. The preflight is active whenever a registered primitive carries a scopeChallenge callback — there is no handler- or transport-level configuration. The challenge's WWW-Authenticate header is built by the same formatter as the bearer-auth 401/403 answers, and its resource_metadata parameter is derived from the verified AuthInfo: requireBearerAuth / verifyBearerToken now stamp their configured resourceMetadataUrl onto the AuthInfo they return (new optional AuthInfo.resourceMetadataUrl field), with a fallback to the well-known location for an HTTP(S) RFC 8707 resource identifier; the parameter is omitted when neither is available. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Typescript SDK von Model Context Protocol

@modelcontextprotocol/node 2.1.0: OAuth-Scope-Challenges per scopeChallenge

@modelcontextprotocol/node 2.1.0 fügt für Tools, Ressourcen, Resource Templates und Prompts anfragezeitliche OAuth-Scope-Challenges über einen scopeChallenge-Callback hinzu, die bei unzureichendem Scope vor der Verarbeitung eine HTTP-403-Antwort mit insufficient_scope liefern.

Minor Changes

  • #1624 6032170 Thanks @SamMorrowDrums! - Add request-time OAuth scope challenges for tools, resources, resource templates, and prompts. Each primitive's scopeChallenge callback receives the parsed request and verified authentication info, then either continues or returns the exact scope set for an insufficient_scope response. requireScopes provides a small helper for static all-of checks.

    createMcpHandler and Streamable HTTP transports return HTTP 403 with an insufficient_scope challenge before handler execution or SSE setup. The preflight is active whenever a registered primitive carries a scopeChallenge callback — there is no handler- or transport-level configuration. The challenge's WWW-Authenticate header is built by the same formatter as the bearer-auth 401/403 answers, and its resource_metadata parameter is derived from the verified AuthInfo: requireBearerAuth / verifyBearerToken now stamp their configured resourceMetadataUrl onto the AuthInfo they return (new optional AuthInfo.resourceMetadataUrl field), with a fallback to the well-known location for an HTTP(S) RFC 8707 resource identifier; the parameter is omitted when neither is available. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Typescript SDK von Model Context Protocol

@modelcontextprotocol/hono 2.0.1: Body-Größenlimit und Batch-Begrenzung

@modelcontextprotocol/hono 2.0.1 liest Streamable-HTTP-Request-Bodys nur noch mit einem Standardlimit von 4 MiB (konfigurierbar über maxRequestBodySize), antwortet bei Überschreitung mit 413 Payload Too Large und begrenzt JSON-RPC-Batches auf 100 Nachrichten.

Patch Changes

  • #2698 7b781ed Thanks @maxisbey! - Read Streamable HTTP request bodies with a size limit. Every SDK-owned body read — WebStandardStreamableHTTPServerTransport (and the Node transport built on it), createMcpHandler, toNodeHandler, and createMcpHonoApp's JSON pre-parse — now stops at 4 MiB by default (the limit the legacy SSE transport already uses; the Express adapter and stdio bound their reads too) and answers 413 Payload Too Large before anything is parsed. toWebRequest (when it reads the Node stream itself) now rejects once the body exceeds the limit with an error whose name is 'RequestBodyTooLargeError' and status is 413, and toNodeHandler answers that with 413; hand-wired callers of toWebRequest should handle the rejection or pass a pre-parsed body, and isLegacyRequest reports such a request as non-legacy so the modern handler answers it. JSON-RPC batch arrays are limited to 100 messages; a longer batch is answered 400 / -32600 and none of it is dispatched.

    The limit is configurable with a new maxRequestBodySize option (bytes, default DEFAULT_MAX_REQUEST_BODY_SIZE = 4 MiB, exported from @modelcontextprotocol/server) on …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Python SDK von Model Context Protocol

MCP Python SDK 2.2.0: Redirects nur im selben Origin, Sitzungslimits

Das Python SDK 2.2.0 folgt HTTP-Redirects nur noch innerhalb desselben Origins des Endpunkts, schließt untätige Streamable-HTTP-Sitzungen (Legacy-Spec bis 2025-11-25) nach 30 Minuten und begrenzt Server auf höchstens 10 000 gleichzeitige Sitzungen.

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

A few defaults changed in this release. If you run a server or client on 2.x, skim these first:

Behaviour changes

HTTP client redirects are only followed within the endpoint's origin (#3397)

  • Client("https://..."), streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host).
  • A redirect anywhere else is not followed: the call fails with MCPError and the session stays usable (an SSE connect fails with httpx2.HTTPStatusError). If that other URL is the server you meant, use it as the endpoint URL.
  • The follow_redirects setting on an httpx2.AsyncClient you pass in is no longer used for MCP requests, so you don't need it for the trailing-slash redirect any more.
  • The OAuth providers apply the same rule to their own requests.

Idle Streamable HTTP sessions now expire (legacy <=2025-11-25 spec( (#3395)

  • A stateful session with nothing in flight for 30 minutes is closed. The client's next request gets a 404 and it has to initialize again.
  • Clients that keep the GET stream open (the SDK's Client does) are not affected. Neither are stateless servers or 2026-07-28 connections.
  • A server also holds at most 10 000 sessions at once; beyond that, new sessions get a 503. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Python SDK von Model Context Protocol

MCP Python SDK 1.30.0: Redirect-Einschränkung und issuer-Prüfung bei OAuth

Das Wartungsrelease Python SDK 1.30.0 folgt Redirects nur noch innerhalb desselben Origins, schließt untätige Streamable-HTTP-Sitzungen nach 30 Minuten, begrenzt Server auf 10 000 Sitzungen und lässt den OAuth-Client den issuer des Autorisierungsservers prüfen.

Maintenance release of the 1.x line. 2.x is the current line; 1.x docs are at https://py.sdk.modelcontextprotocol.io/v1/.

A few defaults changed in this release. If you run a server or client on 1.x, skim these first:

Behaviour changes

HTTP client redirects are only followed within the endpoint's origin (#3448)

  • streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host).
  • A redirect anywhere else now fails the request with httpx.HTTPStatusError. If that other URL is the server you meant, use it as the endpoint URL.
  • The follow_redirects setting on an httpx.AsyncClient you pass in is no longer used for MCP requests, so you don't need it for the trailing-slash redirect any more.
  • OAuthClientProvider applies the same rule to its own requests.

Idle Streamable HTTP sessions now expire (#3426)

  • A stateful session with nothing in flight for 30 minutes is closed. The client's next request gets a 404 and it has to initialize again.
  • Clients that keep the GET stream open (the SDK's client does) are not affected.
  • A server also holds at most 10 000 sessions at once; beyond that, new sessions get a 503.
  • To turn either off: FastMCP(..., session_idle_timeout=None, max_sessions=None).

The OAuth client checks the authorization server's issuer (#3431) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Python SDK von Model Context Protocol

MCP Python SDK 2.0.1: Warnung mit Verweis auf Migrationsleitfaden

Das Python SDK 2.0.1 bringt als einmaligen Backport eine Warnung, die Importe von mcp.server.fastmcp auf den Migrationsleitfaden verweist.

One off backport of the FastMCP import warning for 2.0.x, this is due to a lot of people running into this error and making issues on other repos about it. Ideally either pin mcp<2 or upgrade to 2.

What's Changed

Full Changelog: https://github.com/modelcontextprotocol/python-sdk/compare/v2.0.0...v2.0.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Python SDK von Model Context Protocol

MCP Python SDK 2.1.1: Hinweis auf Migrationsleitfaden bei fastmcp-Importen

Das Python SDK 2.1.1 verweist bei Importen von mcp.server.fastmcp nun auf den Migrationsleitfaden.

What's Changed

Full Changelog: https://github.com/modelcontextprotocol/python-sdk/compare/v2.1.0...v2.1.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Python SDK von Model Context Protocol

MCP Python SDK 2.1.0: StdioServerParameters direkt, Bilder und Audio in Prompts

Das Python SDK 2.1.0 lässt Client direkt StdioServerParameters akzeptieren, erlaubt Image und Audio in Prompt-Nachrichten, dehnt das 4-MiB-Limit für Request-Bodys auf SSE-Transport und OAuth-Endpunkte aus und zeigt Clients bei unerwarteten Handler-Exceptions nur noch eine generische Fehlermeldung.

Highlights

  • Client accepts StdioServerParameters directly: Client(StdioServerParameters(command="uv", args=["run", "server.py"])) (#3321).
  • Prompt messages accept Image and Audio, prompt functions may return bare content blocks, and Message / UserMessage / AssistantMessage are exported from mcp.server.mcpserver (#3320).
  • The 4 MiB request body limit now also covers the SSE transport and the OAuth endpoints; SseServerTransport and MCPServer.sse_app() take max_request_body_size, and the SSE message endpoint answers 405 to non-POST requests (#3336).

Behaviour changes to be aware of

  • Handler exceptions (#3314): an unexpected exception from a tool, resource or prompt handler is logged once at ERROR with its traceback, and the client now sees only Error executing tool <name> (or the resource/prompt equivalent) rather than the exception text. Raise ToolError / ResourceError when the message is meant for the model; those still reach the client and are logged at INFO without a traceback.
  • Content-block return annotations (#3320): a tool annotated to return TextContent, EmbeddedResource, Image, Audio, or lists/unions of them no longer advertises outputSchema or returns structuredContent; its content is unchanged. Pass structured_output=True to keep the previous shape.

Fixes …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Python SDK von Model Context Protocol

MCP Python SDK 1.29.1: Request-Body-Limit für SSE und OAuth

Das Python SDK 1.29.1 vervollständigt das FastMCP-Settings-Modell beim Import, wendet das Request-Body-Limit auf SSE- und OAuth-Endpunkte an und liefert für rekursive Tool-Rückgabetypen ein Output-Schema mit Objekt als Wurzel.

What's Changed

Full Changelog: https://github.com/modelcontextprotocol/python-sdk/compare/v1.29.0...v1.29.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Python SDK von Model Context Protocol

MCP Python SDK 2.0.0: Stabiles v2-Release mit Spezifikation 2026-07-28

Das Python SDK 2.0.0 ist das stabile v2-Release mit Unterstützung der MCP-Spezifikation 2026-07-28 und aller früheren Revisionen, überarbeiteter Dokumentation und Migrationsleitfaden, während 1.x in den Wartungsmodus mit nur noch Sicherheitsfixes wechselt und pip install mcp nun 2.x installiert.

MCP Python SDK v2 Stable Release

This is v2.0.0, the stable v2 release of the MCP Python SDK. It supports the 2026-07-28 revision of the Model Context Protocol and serves every earlier revision from the same server. pip install mcp now installs 2.x.

pip install "mcp[cli]"
# or
uv add "mcp[cli]"

Documentation Rewrite

The documentation has the full tutorial and API reference. Coming from v1? What's new in v2 is the tour of what changed and why, and the migration guide lists every breaking change with before-and-after code.

V1 Maintenance mode

v1.x is in maintenance mode and will only receive security fixes from now on The 1.x line lives on the v1.x branch, continues to receive critical bug fixes and security patches, and is documented at https://py.sdk.modelcontextprotocol.io/v1/. If your project is not ready to migrate, keep a <2 upper bound on your requirement (for example mcp>=1.28,<2).

Highlights

One SDK, both protocol eras …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Python SDK von Model Context Protocol

MCP Python SDK 1.29.0: Request-Body-Limits und Fortschrittsmeldungen

Das Python SDK 1.29.0 leitet Context.report_progress() an den auslösenden Request-Stream, ergänzt Request-Body-Limits für Streamable HTTP, lehnt einen abschließenden Zeilenumbruch in Tool-Namen ab und verschiebt die 1.x-Dokumentation nach /v1/.

What's Changed

Full Changelog: https://github.com/modelcontextprotocol/python-sdk/compare/v1.28.1...v1.29.0

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Python SDK von Model Context Protocol

MCP Python SDK 2.0.0rc1: Erster Release Candidate mit Breaking Changes

Der erste Release Candidate 2.0.0rc1 des Python SDK bereinigt vor dem stabilen v2 die API mit Breaking Changes, etwa Client(cache=None) statt cache=False, entfernten Context.client_id, RFC7523OAuthClientProvider und JWTParameters sowie scope= statt scopes=.

First v2 release candidate. Pre-releases are opt-in only; pip install mcp still resolves to the stable 1.x line.

pip install mcp==2.0.0rc1
# or
uv add "mcp==2.0.0rc1"

The documentation has the full tutorial and API reference, and the migration guide covers coming from v1. Stable v2 is planned for 2026-07-28 alongside the spec release - keep pinning an exact version until then.

Highlights

API cleanup ahead of stable (breaking for beta users)

The last pre-release pass over the public surface; every item has a migration guide entry.

  • Client(cache=False) is now Client(cache=None): CacheConfig() is the default and None switches the response cache off (#3164).
  • Context.client_id is removed - read _meta via ctx.request_context.meta, or the authenticated client via get_access_token().client_id (#3167).
  • RFC7523OAuthClientProvider and JWTParameters are removed - use ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider, or IdentityAssertionOAuthProvider (#3169).
  • The client-credentials providers take scope=, not scopes= (#3166).
  • OAuthClientProvider(timeout=...) is removed; it never bounded anything (#3165).
  • message_handler receives ServerNotification | Exception only; the dead RequestResponder arm and the mcp.shared.session module are gone (#3168). …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Python SDK von Model Context Protocol

MCP Python SDK 2.0.0b2: httpx2 ersetzt httpx, subscriptions/listen

Die zweite v2-Beta 2.0.0b2 des Python SDK ersetzt httpx durch httpx2 (mit Betriebssystem-Trust-Store für TLS, umbenannten Loggern und geändertem Accept-Header bei SSE) und ergänzt clientseitig subscriptions/listen.

Second v2 beta. Pre-releases are opt-in only; pip install mcp still resolves to the stable 1.x line.

pip install mcp==2.0.0b2
# or
uv add "mcp==2.0.0b2"

The documentation has the full tutorial and API reference, and the migration guide covers coming from v1. Stable v2 is still targeted for 2026-07-28 alongside the spec release - keep pinning an exact version.

Highlights

httpx is replaced by httpx2 (#2972)

The SDK's HTTP stack now runs on httpx2 (>=2.5.0), the next-generation httpx fork with SSE support built in, replacing httpx + httpx-sse. Most code needs no changes; if you pass your own http_client into a transport, change the import to httpx2. Runtime behavior that changes:

  • TLS verification uses the operating system trust store (via truststore) instead of certifi's bundle. SSL_CERT_FILE / SSL_CERT_DIR are honored first.
  • Loggers are renamed: httpx -> httpx2, httpcore.* -> httpcore2.* - update logging filters that match on those names.
  • SSE GET streams send Accept: application/json, text/event-stream (previously exactly text/event-stream).

Client-side subscriptions/listen (#3047)

The client half of subscriptions/listen (SEP-2575), promised in the b1 notes: one context manager, async for consumption, typed events.

Originalquelle(öffnet in neuem Tab)Problem melden