MCP TypeScript SDK v2.3.0:Server实例改为每请求创建及重定向限制
2.3.0
推荐理由
v2.3.0 强制改变 Server 生命周期模式并收紧网络策略,所有基于 MCP TS SDK 的服务端代码必须重构以适配“每请求一实例”,否则将引发连接错误。请尽快检查部署架构并完成迁移。
| Package | Version |
|---|---|
| @modelcontextprotocol/client | 2.3.0 |
| @modelcontextprotocol/server | 2.3.0 |
| @modelcontextprotocol/core | 2.3.0 |
| @modelcontextprotocol/server-legacy | 2.3.0 |
| @modelcontextprotocol/codemod | 2.3.0 |
| @modelcontextprotocol/node | 2.1.1 |
| @modelcontextprotocol/express, hono | 2.0.2 |
| @modelcontextprotocol/fastify | 2.0.1 |
| 包 | 版本 |
|---|---|
| @modelcontextprotocol/client | 2.3.0 |
| @modelcontextprotocol/server | 2.3.0 |
| @modelcontextprotocol/core | 2.3.0 |
| @modelcontextprotocol/server-legacy | 2.3.0 |
| @modelcontextprotocol/codemod | 2.3.0 |
| @modelcontextprotocol/node | 2.1.1 |
| @modelcontextprotocol/express, hono | 2.0.2 |
| @modelcontextprotocol/fastify | 2.0.1 |
Upgrade notes
升级说明
- One server per request. Server.connect() now rejects while the instance is already connected, and a stateless Streamable HTTP transport handles one request. Create the McpServer and the transport inside the request handler (or in the createMcpHandler factory) instead of sharing one instance across requests. Creating a server is cheap since #2889. (#2918)
- Redirects stay on the same origin. The HTTP client transports now follow a redirect only when it stays on the same origin (same scheme, host and port; http to https on the same host is allowed). A deployment whose endpoint redirects to another host or port either configures the final URL or sets redirectPolicy: 'follow' on the transport. In browsers, a redirected request fails unless that option is set. (#2901)
- New options, both off unless you set them. maxToolInputElements on McpServer limits the number of array elements and object members in a tool call's arguments. expectedResource on requireBearerAuth / verifyBearerToken accepts only tokens issued for this server (the token's audience); with Express, upgrade @modelcontextprotocol/express together with @modelcontextprotocol/server. (#2926, #2929)
- prompts/get without arguments is validated as {}, as tools/call already is. A top-level .optional() or .default(...) on a prompt's argsSchema no longer sees undefined. (#2107)
- The client requires eventsource-parser 3.0.8 or later. It cuts the time and memory needed to receive a large message sent as a single SSE event: in our test a 100 MB tool result went from about a minute and 1.7 GB of peak memory to under a second and about 0.5 GB. (#2846)
- 每个请求对应一个服务器。Server.connect() 在实例已连接时会拒绝,且无状态的 Streamable HTTP 传输处理单个请求。请在请求处理程序(或在 createMcpHandler 工厂)中创建 McpServer 和传输层,而不是跨请求共享同一个实例。由于 #2889,创建服务器的开销很低。(#2918)
- 重定向保持在同一源上。HTTP 客户端传输现在仅在重定向保持在同一源上(相同的协议、主机和端口;允许同一主机上的 http 到 https 转换)时才遵循重定向。如果端点的重定向指向其他主机或端口,则部署应配置最终 URL,或在传输层设置 redirectPolicy: 'follow'。在浏览器中,除非设置了该选项,否则重定向请求将失败。(#2901)
- 新增选项,默认均为关闭状态,除非你显式设置。McpServer 上的 maxToolInputElements 限制工具调用参数中的数组元素数量和对象成员数量。requireBearerAuth / verifyBearerToken 中的 expectedResource 仅接受为此服务器颁发的令牌(令牌的受众);使用 Express 时,请同时升级 @modelcontextprotocol/express 和 @modelcontextprotocol/server。(#2926, #2929)
- 不带参数的 prompts/get 验证为 {},与 tools/call 一样。提示词参数架构(argsSchema)顶层的 .optional() 或 .default(...) 不再接收 undefined。(#2107)
- 客户端需要 eventsource-parser 3.0.8 或更高版本。它减少了接收作为单个 SSE 事件发送的大消息所需的时间和内存:在我们的测试中,100 MB 的工具结果从大约一分钟和 1.7 GB 的峰值内存减少到不到一秒和大约 0.5 GB。(#2846)
New
新增
- validateOriginHeader and the allowedOrigins option of the Express, Fastify and Hono app helpers accept <scheme>://* entries such as moz-extension://*, so a server can admit MCP clients that run as a browser extension. (#2907)
- tasks/get and tasks/cancel of the Tasks extension can be served and called on a 2026-07-28 connection. (#2599)
- validateOriginHeader 以及 Express、Fastify 和 Hono 应用辅助函数的 allowedOrigins 选项接受 <scheme>://* 条目(例如 moz-extension://*),因此服务器可以接纳作为浏览器扩展运行的 MCP 客户端。(#2907)
- Tasks 扩展的 tasks/get 和 tasks/cancel 可以在 2026-07-28 连接上提供服务和调用。(#2599)
Fixes
修复
- A large message received as a single SSE event over Streamable HTTP is fast again: a 50 MB tool result that took about 13 seconds arrives in under a second. (#2846)
- prompts/get without arguments no longer fails when every argument of the prompt is optional. (#2107)
- SSEClientTransport refreshes once after a 401 on connect instead of retrying without limit. (#2905, #2934)
- registerTool no longer converts tool schemas up front, so a server built per request stops converting every tool on every request. (#2889)
- hono is a regular dependency of @modelcontextprotocol/node, so installs with strict peer-dependency checking no longer fail. (#2897)
- A server/discover probe answered with an unusable 2xx reply now says so instead of reading like a network failure. (#2903)
- McpServer.registerPrompt() types the callback correctly when no argsSchema is given. (#2841)
- The license field of the package manifests is Apache-2.0. (#2908)
- 通过 Streamable HTTP 作为单个 SSE 事件接收的大消息再次变快:原本需要约 13 秒的 50 MB 工具结果,现在可在不到一秒内到达。(#2846)
- 当提示词的所有参数均为可选时,不带参数的 prompts/get 不再失败。(#2107)
- SSEClientTransport 在连接出现 401 错误后仅刷新一次,而非无限重试。(#2905, #2934)
- registerTool 不再预先转换工具模式(schemas),因此按请求构建的服务器不再在每个请求中转换所有工具。(#2889)
- hono 是 @modelcontextprotocol/node 的常规依赖项,因此使用严格对等依赖检查进行安装时不再失败。(#2897)
- 对于 server/discover 探测,若返回不可用的 2xx 响应,现在会明确提示该情况,而不是被误读为网络故障。(#2903)
- 当未提供 argsSchema 时,McpServer.registerPrompt() 能正确类型化回调函数。(#2841)
- 包清单中的 license 字段为 Apache-2.0。(#2908)
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力