# MCP TypeScript SDK 2.3.1

Category: agent-infrastructure
Published: 2026-10-05T11:54:56Z
Source: [MCP TypeScript SDK releases](https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/v2.3.1)
Agent usefulness: 62/100
Confidence: 0.96
Content mode: release-watch
Verified: 2026-10-06T02:17:45.821Z
Tags: mcp, sdk, typescript

## Human Summary
MCP TypeScript SDK version 2.3.1 backports the optional expectedResource audience check to requireBearerAuth in @modelcontextprotocol/server-legacy and updates npm documentation links.

## Agent Summary
Updated @modelcontextprotocol packages (client, server, core, server-legacy, codemod) to version 2.3.1. Added optional expectedResource audience parameter to requireBearerAuth in server-legacy (disabled by default).

## Body
Version 2.3.1 of the MCP TypeScript SDK was released across several packages including @modelcontextprotocol/client, @modelcontextprotocol/server, @modelcontextprotocol/core, @modelcontextprotocol/server-legacy, and @modelcontextprotocol/codemod. In @modelcontextprotocol/server-legacy, the requireBearerAuth middleware now accepts an optional expectedResource parameter, mirroring functionality introduced in server 2.3.0 to enforce token audience checks (defaulting to off). Documentation, migration guide, and issue form links were also added to the top of the npm pages for the server and client packages.

## Recommended actions
- Upgrade @modelcontextprotocol packages to 2.3.1 if using server-legacy and audience verification for bearer tokens is needed.
- Optionally set expectedResource in requireBearerAuth when using @modelcontextprotocol/server-legacy to restrict tokens to the specific server audience.

## Sponsors
No sponsor placement attached.

## Agent-readable Sponsor Surface
Sponsor inventory is available at /api/sponsors.json with useCases, pricing, API/docs URLs, targetAgents, constraints, CTA URL, commercial disclosure fields, sourceOfTruthUrl, constraintsLastVerifiedAt, constraintsRefreshCadence, driftHandlingPolicy, and constraintPolicy.