{"schemaVersion":"2026-07-21.signal.v2","id":"live-c6644d84177421243aa3","title":"@modelcontextprotocol/core@2.2.0","slug":"mcp-typescript-sdk-40modelcontextprotocol-2fcore-402-2-0-modelcontextprotocol-core-2-2-243aa3","url":"https://www.niubiagent.com/signals/mcp-typescript-sdk-40modelcontextprotocol-2fcore-402-2-0-modelcontextprotocol-core-2-2-243aa3","jsonUrl":"https://www.niubiagent.com/api/posts/mcp-typescript-sdk-40modelcontextprotocol-2fcore-402-2-0-modelcontextprotocol-core-2-2-243aa3.json","markdownUrl":"https://www.niubiagent.com/content/mcp-typescript-sdk-40modelcontextprotocol-2fcore-402-2-0-modelcontextprotocol-core-2-2-243aa3","summaryHuman":"MCP TypeScript SDK releases published @modelcontextprotocol/core@2.2.0. Minor Changes 2887 edd12e2 Thanks @maxisbey ! - Constructing ClientCredentialsProvider , PrivateKeyJwtProvider , StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked…","summaryAgent":"Treat @modelcontextprotocol/core@2.2.0 as an official release signal. Inspect the linked changelog for compatibility and migration details, then run targeted tests before upgrading.","category":"agent-infrastructure","tags":["mcp","sdk","typescript"],"sourceName":"MCP TypeScript SDK releases","sourceUrl":"https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/%40modelcontextprotocol%2Fcore%402.2.0","publishedAt":"2026-09-28T19:07:52Z","curatedAt":"2026-09-29T00:17:33.511Z","confidence":0.96,"agentUsefulness":89,"sponsorIds":[],"language":"en","contentMode":"release-watch","verifiedAt":"2026-09-29T00:17:33.511Z","changeType":"breaking","actionItems":["Review the official MCP TypeScript SDK releases release notes before upgrading.","Check compatibility, migration, and security notes against your current agent stack.","Run focused regression tests before production rollout."],"body":"MCP TypeScript SDK releases published @modelcontextprotocol/core@2.2.0. This automated release-watch entry was generated from the project's official GitHub release feed and is kept separate from human-reviewed editorial analysis. Release notes: Minor Changes 2887 edd12e2 Thanks @maxisbey ! - Constructing ClientCredentialsProvider , PrivateKeyJwtProvider , StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked @deprecated . Behaviour is otherwise unchanged. Pass the issuer of the authorization server the credentials were registered with. fetchToken() throws AuthorizationServerMismatchError , before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. The AuthorizationServerMismatchError message no longer assumes the authorization-code callback; its fields are unchanged. OAuthTokensSchema and OAuthClientInformationSchema accept the optional issuer stamp, so a provider that reads storage back through them keeps it. auth() overwrites it on…","sponsors":[]}