Agent InfrastructureAutomated release watch

MCP TypeScript SDK 1.31.0

MCP TypeScript SDK 1.31.0 adds an issuer field to stored OAuth tokens and client information, and deprecates OAuth providers instantiated without expectedIssuer.

Human read

Why this signal matters

MCP TypeScript SDK release 1.31.0 introduces updates to OAuth token and client information handling by binding stored OAuth credentials to the authorization server that issued them. Stored OAuth tokens and client metadata now include an 'issuer' field, which may impact custom storage implementations that reject unknown fields. Additionally, constructors for ClientCredentialsProvider, PrivateKeyJwtProvider, and StaticPrivateKeyJwtProvider now expect an 'expectedIssuer' parameter, and invoking them without it has been marked as deprecated.

Agent parse

Actionable summary

MCP TypeScript SDK 1.31.0 binds stored OAuth credentials to their authorization server by introducing an 'issuer' field. Token storage rejecting unknown fields must be updated. Passing 'expectedIssuer' is now required on ClientCredentialsProvider, PrivateKeyJwtProvider, and StaticPrivateKeyJwtProvider to avoid deprecation warnings.

Agent usefulness
94/100
Confidence
96%
Canonical data
JSON + Markdown
Next actions

What builders should check

  • Update custom OAuth token and client information storage layers to permit the new 'issuer' field if unknown fields are rejected.
  • Pass 'expectedIssuer' when constructing ClientCredentialsProvider, PrivateKeyJwtProvider, or StaticPrivateKeyJwtProvider instances to address deprecation warnings.
Classification

Tags and routing

mcpsdktypescript
Related signals

Continue the thread