# @modelcontextprotocol/server@2.3.0

Category: agent-infrastructure
Published: 2026-10-02T17:43:27Z
Source: [MCP TypeScript SDK releases](https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/%40modelcontextprotocol/server%402.3.0)
Agent usefulness: 77/100
Confidence: 0.96
Content mode: release-watch
Verified: 2026-10-02T20:17:49.698Z
Tags: mcp, sdk, typescript

## Human Summary
MCP TypeScript SDK releases published @modelcontextprotocol/server@2.3.0. Minor Changes - 2929 (https://github.com/modelcontextprotocol/typescript-sdk/pull/2929) 40f8f4e (https://github.com/modelcontextprotocol/typescript-sdk/commit/40f8f4e229d963cd7fd2890bda2aeebe7005299a) Thanks @claude (https://github.com/apps/claude)! - requireBearerAuth and…

## Agent Summary
Treat @modelcontextprotocol/server@2.3.0 as an official release signal. Inspect the linked changelog for compatibility and migration details, then run targeted tests before upgrading.

## Body
MCP TypeScript SDK releases published @modelcontextprotocol/server@2.3.0. This automated release-watch entry was generated from the project's official GitHub release feed and is kept separate from human-reviewed editorial analysis. Release notes: Minor Changes - 2929 (https://github.com/modelcontextprotocol/typescript-sdk/pull/2929) 40f8f4e (https://github.com/modelcontextprotocol/typescript-sdk/commit/40f8f4e229d963cd7fd2890bda2aeebe7005299a) Thanks @claude (https://github.com/apps/claude)! - requireBearerAuth and verifyBearerToken take a new optional expectedResource , which makes them accept only tokens issued for this resource (the token's audience). Set it to the value your authorization server puts into tokens meant for this server, usually the server's URL. When it is set, a token is accepted only if the verifier reports that value in AuthInfo.resource ; the two are compared as strings, ignoring a fragment and one trailing slash. A token reported for another value, or for none, is answered 401 invalid token with the usual WWW-Authenticate challenge. When it is not set, nothing changes. To use it, pass expectedResource and…

## Recommended actions
- Review the official MCP TypeScript SDK releases release notes before upgrading.
- Check compatibility, migration, and security notes against your current agent stack.
- Run focused regression tests before production rollout.

## Sponsors
No sponsor placement attached.

## Agent-readable Sponsor Surface
Sponsor inventory is available at /api/sponsors.json with useCases, pricing, API/docs URLs, targetAgents, constraints, CTA URL, commercial disclosure fields, sourceOfTruthUrl, constraintsLastVerifiedAt, constraintsRefreshCadence, driftHandlingPolicy, and constraintPolicy.