MCP TypeScript SDK 2.3.1 adds the optional expectedResource setting to requireBearerAuth in @modelcontextprotocol/server-legacy. When it is set, the verifier must report a matching AuthInfo.resource; another value or no value produces HTTP 401 invalid_token. GitHub's top-level v2.3.1 release entry is timestamped 2026-10-05T11:54:56Z, while the package-specific GitHub release entry is timestamped 2026-10-05T11:49:40Z.
The MCP TypeScript SDK release timestamps
The repository's GitHub Releases page contains separate entries for the repository release and the individual package tag:
- GitHub's top-level
v2.3.1release was published by Felix Weinberger at2026-10-05T11:54:56Zand points to commitfcef852. - GitHub's package-specific
@modelcontextprotocol/server-legacy@2.3.1release was published by GitHub Actions at2026-10-05T11:49:40Z, also at commitfcef852. - npm's registry metadata records
2026-10-05T11:50:22.350Zin the package'stime["2.3.1"]field.
The 11:54 UTC value in the draft came from the top-level GitHub release. The 11:49:40Z value came from the package-specific GitHub release row, not from npm. The npm publication timestamp that can be sourced from npm's registry is 11:50:22.350Z. These timestamps describe different release records, so they should not be presented as one event.
The MCP TypeScript SDK expectedResource check
requireBearerAuth receives an expectedResource URL alongside the token verifier. The verifier returns an AuthInfo object and reports the token's resource, normally derived from the OAuth aud claim. The middleware then compares that value with expectedResource as strings.
The comparison ignores a URI fragment and one trailing slash. A token reported for another host, scheme, port, path, query, or no resource fails the check. The middleware returns HTTP 401 invalid_token with its WWW-Authenticate challenge before it checks required scopes or expiry. If expectedResource is omitted, the middleware does not compare AuthInfo.resource.
The authorization guide shows the setting in the middleware configuration:
const auth = requireBearerAuth({
verifier,
requiredScopes: ['mcp'],
resourceMetadataUrl,
expectedResource: mcpServerUrl,
});The same guide tells verifiers to report the matching entry from aud, which may be one value, a list, or absent. A verifier that reports no matching resource leaves the request on the 401 path when the setting is enabled.
The MCP TypeScript SDK package timeline
Pull request #2929 added the optional expectedResource setting to requireBearerAuth and verifyBearerToken in @modelcontextprotocol/server. The top-level GitHub v2.3.0 release entry was published at 2026-10-02T17:55:03Z.
Pull request #2952 merged on 2026-10-05 with commit 5a18673 and added the same audience check to the frozen @modelcontextprotocol/server-legacy middleware. The option is off unless a caller supplies it, so existing callers that omit it keep the previous comparison behavior.
Sources
- MCP TypeScript SDK releases (read 2026-10-06)
- MCP TypeScript SDK v2.3.1 release (read 2026-10-06)
- MCP TypeScript SDK server-legacy 2.3.1 release (read 2026-10-06)
- npm registry metadata for @modelcontextprotocol/server-legacy (read 2026-10-06)
- PR #2952: add expectedResource to server-legacy (read 2026-10-06)
- MCP TypeScript SDK authorization guide (read 2026-10-06)
- PR #2929: add expectedResource to the server bearer-token check (read 2026-10-06)
Last verified: 2026-10-06.