MCP’s TypeScript monorepo shipped v2.2.0 on 2026-09-28: client/server/core/server-legacy/codemod aligned at 2.2.0. M2M OAuth providers should pass expectedIssuer; fetchToken() throws AuthorizationServerMismatchError on issuer mismatch. Cursor-less listTools/listPrompts/listResources/listResourceTemplates now follow nextCursor (capped by listMaxPages). Fixes the 2.1.0 CJS jose types regression and Client.listen() unhandled rejection / send hang.

Key Takeaways

  • ✓Shipped v2.2.0 — client/server/core/server-legacy/codemod aligned; node/express/hono/fastify unchanged
  • ✓M2M OAuth: pass expectedIssuer; fetchToken throws AuthorizationServerMismatchError on mismatch
  • ✓list* without cursor auto-follows nextCursor (listMaxPages cap)
  • ✓Fixes CJS jose types regression and Client.listen() rejection/hang
  • ✓Install: npm i @modelcontextprotocol/[email protected]
🧭

Finished reading? Explore benchmark rankings & pricing

Real-world SWE-bench scores & $20/mo vs API cost break-even calculator

🔬

In-Depth Technical Analysis

Core Background & Industry Pain Points

IDE/agent hosts rely on the official MCP TypeScript SDK for tool discovery and OAuth. Pain points: multi-tenant local OAuth without issuer binding; manual cursor loops for paged list*; CJS+jose/DPoP type regressions after 2.1.0; Client.listen() hangs when a send never settles.

Architecture Highlights & Internals

v2.2.0 aligns client/server/core/server-legacy/codemod at 2.2.0. Pass expectedIssuer into M2M OAuth providers; fetchToken() throws AuthorizationServerMismatchError on mismatch (#2887). Cursor-less listTools/listPrompts/listResources/listResourceTemplates follow nextCursor up to listMaxPages (#2886). Jose types are inlined for CJS; Client.listen() no longer leaks rejections or hangs; .localhost counts as loopback; createMcpHandler same-instance reuse no longer stack-overflows.

Authoritative Benchmarks & Measured Scores

No public throughput/latency table. Validate issuer checks, full list walks, CJS tsc, and listen stability on your host.

Developer Hands-on Guide

npm i @modelcontextprotocol/[email protected] @modelcontextprotocol/[email protected]. Set expectedIssuer on M2M providers; rely on auto-paging with a sane listMaxPages. See modelcontextprotocol.io and the 2.2.0 release.