{"schemaVersion":"2026-07-21.signal.v2","id":"live-ef0b14582c868a67ed9d","title":"MCP TypeScript SDK 1.31.0","slug":"mcp-typescript-sdk-1-31-0-mcp-typescript-sdk-1-31-0-67ed9d","url":"https://www.niubiagent.com/signals/mcp-typescript-sdk-1-31-0-mcp-typescript-sdk-1-31-0-67ed9d","jsonUrl":"https://www.niubiagent.com/api/posts/mcp-typescript-sdk-1-31-0-mcp-typescript-sdk-1-31-0-67ed9d.json","markdownUrl":"https://www.niubiagent.com/content/mcp-typescript-sdk-1-31-0-mcp-typescript-sdk-1-31-0-67ed9d","summaryHuman":"MCP TypeScript SDK 1.31.0 adds an issuer field to stored OAuth tokens and client information, and deprecates OAuth providers instantiated without expectedIssuer.","summaryAgent":"MCP TypeScript SDK 1.31.0 binds stored OAuth credentials to their authorization server by introducing an 'issuer' field. Token storage rejecting unknown fields must be updated. Passing 'expectedIssuer' is now required on ClientCredentialsProvider, PrivateKeyJwtProvider, and StaticPrivateKeyJwtProvider to avoid deprecation warnings.","category":"agent-infrastructure","tags":["mcp","sdk","typescript"],"sourceName":"MCP TypeScript SDK releases","sourceUrl":"https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/1.31.0","publishedAt":"2026-09-28T18:52:02Z","curatedAt":"2026-09-29T00:17:28.219Z","confidence":0.96,"agentUsefulness":94,"sponsorIds":[],"language":"en","contentMode":"release-watch","verifiedAt":"2026-09-29T00:17:28.219Z","changeType":"release","actionItems":["Update custom OAuth token and client information storage layers to permit the new 'issuer' field if unknown fields are rejected.","Pass 'expectedIssuer' when constructing ClientCredentialsProvider, PrivateKeyJwtProvider, or StaticPrivateKeyJwtProvider instances to address deprecation warnings."],"body":"MCP TypeScript SDK release 1.31.0 introduces updates to OAuth token and client information handling by binding stored OAuth credentials to the authorization server that issued them. Stored OAuth tokens and client metadata now include an 'issuer' field, which may impact custom storage implementations that reject unknown fields. Additionally, constructors for ClientCredentialsProvider, PrivateKeyJwtProvider, and StaticPrivateKeyJwtProvider now expect an 'expectedIssuer' parameter, and invoking them without it has been marked as deprecated.","sponsors":[]}