@modelcontextprotocol 2.3.0: Server Lifecycle, Redirects, and New Security Options
The 2.3.0 release of @modelcontextprotocol/client, server, and related packages mandates one server per request, changes HTTP redirect handling, and adds security and validation options. Developers must update their architecture and configuration to stay compatible and secure.
What changed?
The 2.3.0 update to the @modelcontextprotocol suite brings several notable changes: - Server-side: Server.connect() now rejects if the instance is already connected. A single McpServer and its transport must now be created per incoming request; shared global server instances are no longer supported. - HTTP client transport: Redirects are followed only when targeting the same origin. For cross-origin redirects, you must explicitly set redirectPolicy: 'follow'. In browsers, such redirects fail unless that option is set. - New server-side options: maxToolInputElements limits array/object argument size in tool calls, and expectedResource enforces bearer authentication tokens to be issued for the specific server. - Validation: prompts/get with no arguments is validated as an empty object ({}), and .optional() or .default(...) in prompt argsSchemas do not see undefined values. - The client now requires eventsource-parser version 3.0.8 or later. - Origin header validation enhancements now allow ://* entries (e.g., moz-extension://*) to better support browser extension clients. - Tasks extension's tasks/get and tasks/cancel are now available for 2026-07-28 connections.
Why does it matter to an everyday developer?
If your code assumes a shared server instance across HTTP requests, it will now break or behave incorrectly. The new model requires a lightweight per-request instantiation, which improves isolation and reliability but changes established patterns. Redirect handling is now safer by default but stricter: deployments relying on redirects across domains or ports must add explicit configuration, especially in browsers, or requests will fail. Security improvements let you bound token validity and limit tool call complexity, helping secure your backend. The new origin validation options help web extensions interact more flexibly with your server.
