Open sourceOpen-source releaseMLOps, Tooling & Infrastructure1 source · Oct 5, 2026

modelcontextprotocol/typescript-sdk v2.3.1: 2.3.1

requireBearerAuth in @modelcontextprotocol/server-legacy takes the optional expectedResource that @modelcontextprotocol/server 2.3.0 added: it accepts only tokens issued for this server (the token's audience).

Key points

  • | @modelcontextprotocol/node, express, hono, fastify | unchanged |
  • Off unless you set it. (#2952)
  • The npm pages of @modelcontextprotocol/server and @modelcontextprotocol/client now open with one note that links the documentation, the migration guide and the issue form. (#2955)

Sources (1)

  • [1]modelcontextprotocol/typescript-sdk v2.3.1: 2.3.1
    GitHub: modelcontextprotocol/typescript-sdk · Oct 5, 11:54 AM
    - `requireBearerAuth` in `@modelcontextprotocol/server-legacy` takes the optional `expectedResource` that `@modelcontextprotocol/server` 2.3.0 added: it accepts only tokens issued for this server (the token's audience).
    | `@modelcontextprotocol/node`, `express`, `hono`, `fastify` | unchanged |

Extractive summary: sentences quoted from the sources.

Before this

  1. Oct 2, 2026[AINews] Pi 1.0, Pi Durable, and AIE NYC
  2. Sep 30, 2026axolotl-ai-cloud/axolotl v0.20.0
  3. Sep 30, 2026[AINews] OpenAI DevDay 2026: Dots, 6.1 Sol, Ultrafast, Decisions API, Agents API, Spaces, Marketplace, and 1.2 Billion ChatGPT WAU
  4. Sep 29, 2026Comfy-Org/ComfyUI v0.38.0

Related