Skip to content

chore(deps): MCP SDK 2.3.1 and workers-oauth-provider 1.2.2 - #259

Merged
mattzcarey merged 2 commits into
cloudflare:mainfrom
mattzcarey:chore/upgrade-mcp-sdk-2.3
Oct 7, 2026
Merged

mattzcarey merged 2 commits into
cloudflare:mainfrom
mattzcarey:chore/upgrade-mcp-sdk-2.3

Conversation

@mattzcarey

@mattzcarey mattzcarey commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Brings the MCP SDK up to date as the base for the scope-challenge work that replaces #255 and #256.

Package From To
@modelcontextprotocol/server 2.0.0 2.3.1
@modelcontextprotocol/client (dev) 2.0.0 2.3.1
@cloudflare/workers-oauth-provider 1.2.1 1.2.2
  • Removes our subscriptions/listen workaround. Since 2.2.0, createMcpHandler ends a listen stream itself when it honours none of the requested types. It sends the acknowledgement, then resultType: "complete", then closes. Our server declares no list-changed or subscribe capability, so that applies to every filter. The end-to-end test now covers all five filter shapes (tools, prompts and resources list changes, resource subscriptions, and an empty filter). On SDK 2.0.0 without the workaround, all five hang.
  • 2.3.0 requires a fresh server for every request. We already build one per request.
  • 2.1.0 caps request bodies at 4 MiB and requires MCP-Protocol-Version on 2026-07-28 requests. Neither affects current traffic.
  • 2.1.0 also adds per-tool scopeChallenge. The follow-up doesn't use it, because it has to decide before the tool runs, and we only know a scope is missing once Cloudflare returns a 403.
  • workers-oauth-provider 1.2.2 only changes signing algorithms for enterprise-managed authorization (EMA) issuers, which we don't use.

@mattzcarey
mattzcarey merged commit a2bea55 into cloudflare:main Oct 7, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant