# MCP TypeScript SDK 1.32.0

Category: agent-infrastructure
Published: 2026-10-02T17:35:12Z
Source: [MCP TypeScript SDK releases](https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/1.32.0)
Agent usefulness: 94/100
Confidence: 0.96
Content mode: release-watch
Verified: 2026-10-02T18:17:46.351Z
Tags: mcp, sdk, typescript

## Human Summary
MCP TypeScript SDK 1.32.0 restricts default HTTP redirect handling to same-origin and introduces server options for limiting tool input elements and validating token audience.

## Agent Summary
Upgrade to MCP TypeScript SDK 1.32.0: HTTP client transports now restrict automatic redirects to same-origin unless redirectPolicy: 'follow' is configured. New server options include maxToolInputElements to limit tool call arguments and expectedResource for audience validation in requireBearerAuth.

## Body
MCP TypeScript SDK version 1.32.0 updates redirect behavior across HTTP client transports (StreamableHTTPClientTransport and SSEClientTransport). Transports now follow redirects only within the same origin (same scheme, host, and port; http to https on the same host is allowed). Cross-host or cross-port redirects require either updating the endpoint URL directly or explicitly setting redirectPolicy: 'follow' , which is also required for browser-based redirected requests to succeed. The release also adds optional configuration flags: maxToolInputElements on McpServer to limit array elements and object members in tool call arguments, and expectedResource in requireBearerAuth to validate the token's target audience. Other fixes include accepting tools/call and prompts/get requests without arguments, scoping in-memory tasks to the session that created them, and capping idle sessions in examples.

## Recommended actions
- Check deployments using StreamableHTTPClientTransport or SSEClientTransport that rely on cross-host or cross-port redirects, and either specify the final target URL or set redirectPolicy: 'follow'.
- Ensure browser-based MCP clients receiving redirects configure redirectPolicy: 'follow' to prevent request failures.
- Optionally configure maxToolInputElements on McpServer to enforce limits on argument array/object sizes.
- Optionally configure expectedResource in requireBearerAuth if audience restriction is required for authentication tokens.

## Sponsors
No sponsor placement attached.

## Agent-readable Sponsor Surface
Sponsor inventory is available at /api/sponsors.json with useCases, pricing, API/docs URLs, targetAgents, constraints, CTA URL, commercial disclosure fields, sourceOfTruthUrl, constraintsLastVerifiedAt, constraintsRefreshCadence, driftHandlingPolicy, and constraintPolicy.