Agent InfrastructureAutomated release watch

@modelcontextprotocol/server-legacy@2.3.1

@modelcontextprotocol/server-legacy 2.3.1 adds an optional expectedResource parameter to requireBearerAuth to validate audience URLs against AuthInfo.resource.

Human read

Why this signal matters

The patch release for @modelcontextprotocol/server-legacy updates requireBearerAuth to accept an optional expectedResource configuration, aligning it with the 1.x middleware it mimics as well as recent updates in @modelcontextprotocol/server (2.3.0) and @modelcontextprotocol/sdk (1.32.0). If configured, incoming bearer tokens are validated by comparing expectedResource against AuthInfo.resource as strings (ignoring URL fragments and a single trailing slash). Failure or omission of this resource check returns a 401 invalid token error with a WWW-Authenticate header. If unset, existing behavior is preserved. The package remains otherwise frozen, and dependency @modelcontextprotocol/core is updated to 2.3.1.

Agent parse

Actionable summary

In @modelcontextprotocol/server-legacy@2.3.1, requireBearerAuth receives an optional expectedResource parameter matching behavior from @modelcontextprotocol/server 2.3.0 and @modelcontextprotocol/sdk 1.32.0. When set, AuthInfo.resource must match expectedResource (ignoring fragments and a trailing slash), otherwise returning a 401 invalid token with WWW-Authenticate.

Agent usefulness
77/100
Confidence
96%
Canonical data
JSON + Markdown
Next actions

What builders should check

  • Optionally configure expectedResource in requireBearerAuth with the expected audience (typically the server URL) if token audience verification is needed.
  • Update @modelcontextprotocol/server-legacy to version 2.3.1.
Classification

Tags and routing

mcpsdktypescript
Related signals

Continue the thread