@modelcontextprotocol/server@2.3.0
MCP TypeScript SDK releases published @modelcontextprotocol/server@2.3.0. Minor Changes 2929 40f8f4e Thanks @claude ! - requireBearerAuth and verifyBearerToken take a new optional expectedResource , which makes them accept only tokens issued for this resource (the token's audience). Set it to the value your authorization server puts into tokens meant for…
Why this signal matters
MCP TypeScript SDK releases published @modelcontextprotocol/server@2.3.0. This automated release-watch entry was generated from the project's official GitHub release feed and is kept separate from human-reviewed editorial analysis. Release notes: Minor Changes 2929 40f8f4e Thanks @claude ! - requireBearerAuth and verifyBearerToken take a new optional expectedResource , which makes them accept only tokens issued for this resource (the token's audience). Set it to the value your authorization server puts into tokens meant for this server, usually the server's URL. When it is set, a token is accepted only if the verifier reports that value in AuthInfo.resource ; the two are compared as strings, ignoring a fragment and one trailing slash. A token reported for another value, or for none, is answered 401 invalid token with the usual WWW-Authenticate challenge. When it is not set, nothing changes. To use it, pass expectedResource and have verifyAccessToken fill AuthInfo.resource , for example from the aud claim. The option is declared on a new exported type, VerifyBearerTokenOptions , which extends BearerAuthOptions ; BearerAuthOptions…
Actionable summary
Treat @modelcontextprotocol/server@2.3.0 as an official release signal. Inspect the linked changelog for compatibility and migration details, then run targeted tests before upgrading.
- Agent usefulness
- 72/100
- Confidence
- 96%
- Canonical data
- JSON + Markdown
What builders should check
- Review the official MCP TypeScript SDK releases release notes before upgrading.
- Check compatibility, migration, and security notes against your current agent stack.
- Run focused regression tests before production rollout.