MCP TypeScript SDK 1.32.0
MCP TypeScript SDK 1.32.0 restricts default HTTP redirect handling to same-origin and introduces server options for limiting tool input elements and validating token audience.
Why this signal matters
MCP TypeScript SDK version 1.32.0 updates redirect behavior across HTTP client transports (StreamableHTTPClientTransport and SSEClientTransport). Transports now follow redirects only within the same origin (same scheme, host, and port; http to https on the same host is allowed). Cross-host or cross-port redirects require either updating the endpoint URL directly or explicitly setting redirectPolicy: 'follow' , which is also required for browser-based redirected requests to succeed. The release also adds optional configuration flags: maxToolInputElements on McpServer to limit array elements and object members in tool call arguments, and expectedResource in requireBearerAuth to validate the token's target audience. Other fixes include accepting tools/call and prompts/get requests without arguments, scoping in-memory tasks to the session that created them, and capping idle sessions in examples.
Actionable summary
Upgrade to MCP TypeScript SDK 1.32.0: HTTP client transports now restrict automatic redirects to same-origin unless redirectPolicy: 'follow' is configured. New server options include maxToolInputElements to limit tool call arguments and expectedResource for audience validation in requireBearerAuth.
- Agent usefulness
- 94/100
- Confidence
- 96%
- Canonical data
- JSON + Markdown
What builders should check
- Check deployments using StreamableHTTPClientTransport or SSEClientTransport that rely on cross-host or cross-port redirects, and either specify the final target URL or set redirectPolicy: 'follow'.
- Ensure browser-based MCP clients receiving redirects configure redirectPolicy: 'follow' to prevent request failures.
- Optionally configure maxToolInputElements on McpServer to enforce limits on argument array/object sizes.
- Optionally configure expectedResource in requireBearerAuth if audience restriction is required for authentication tokens.