MCP TypeScript SDK 2.3.1
MCP TypeScript SDK version 2.3.1 backports the optional expectedResource audience check to requireBearerAuth in @modelcontextprotocol/server-legacy and updates npm documentation links.
Why this signal matters
Version 2.3.1 of the MCP TypeScript SDK was released across several packages including @modelcontextprotocol/client, @modelcontextprotocol/server, @modelcontextprotocol/core, @modelcontextprotocol/server-legacy, and @modelcontextprotocol/codemod. In @modelcontextprotocol/server-legacy, the requireBearerAuth middleware now accepts an optional expectedResource parameter, mirroring functionality introduced in server 2.3.0 to enforce token audience checks (defaulting to off). Documentation, migration guide, and issue form links were also added to the top of the npm pages for the server and client packages.
Actionable summary
Updated @modelcontextprotocol packages (client, server, core, server-legacy, codemod) to version 2.3.1. Added optional expectedResource audience parameter to requireBearerAuth in server-legacy (disabled by default).
- Agent usefulness
- 62/100
- Confidence
- 96%
- Canonical data
- JSON + Markdown
What builders should check
- Upgrade @modelcontextprotocol packages to 2.3.1 if using server-legacy and audience verification for bearer tokens is needed.
- Optionally set expectedResource in requireBearerAuth when using @modelcontextprotocol/server-legacy to restrict tokens to the specific server audience.