# @modelcontextprotocol/core@2.2.0

Category: agent-infrastructure
Published: 2026-09-28T19:07:52Z
Source: [MCP TypeScript SDK releases](https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/%40modelcontextprotocol%2Fcore%402.2.0)
Agent usefulness: 89/100
Confidence: 0.96
Content mode: release-watch
Verified: 2026-09-29T00:17:33.511Z
Tags: mcp, sdk, typescript

## Human Summary
MCP TypeScript SDK releases published @modelcontextprotocol/core@2.2.0. Minor Changes 2887 edd12e2 Thanks @maxisbey ! - Constructing ClientCredentialsProvider , PrivateKeyJwtProvider , StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked…

## Agent Summary
Treat @modelcontextprotocol/core@2.2.0 as an official release signal. Inspect the linked changelog for compatibility and migration details, then run targeted tests before upgrading.

## Body
MCP TypeScript SDK releases published @modelcontextprotocol/core@2.2.0. This automated release-watch entry was generated from the project's official GitHub release feed and is kept separate from human-reviewed editorial analysis. Release notes: Minor Changes 2887 edd12e2 Thanks @maxisbey ! - Constructing ClientCredentialsProvider , PrivateKeyJwtProvider , StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked @deprecated . Behaviour is otherwise unchanged. Pass the issuer of the authorization server the credentials were registered with. fetchToken() throws AuthorizationServerMismatchError , before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with. The AuthorizationServerMismatchError message no longer assumes the authorization-code callback; its fields are unchanged. OAuthTokensSchema and OAuthClientInformationSchema accept the optional issuer stamp, so a provider that reads storage back through them keeps it. auth() overwrites it on…

## Recommended actions
- Review the official MCP TypeScript SDK releases release notes before upgrading.
- Check compatibility, migration, and security notes against your current agent stack.
- Run focused regression tests before production rollout.

## Sponsors
No sponsor placement attached.

## Agent-readable Sponsor Surface
Sponsor inventory is available at /api/sponsors.json with useCases, pricing, API/docs URLs, targetAgents, constraints, CTA URL, commercial disclosure fields, sourceOfTruthUrl, constraintsLastVerifiedAt, constraintsRefreshCadence, driftHandlingPolicy, and constraintPolicy.