Development·EASYHUB JOURNAL
MCP TypeScript and Python SDK 2.3.0 tighten redirects and token audience checks while adding controls for large SSE tool results

What changed
The Model Context Protocol TypeScript and Python SDKs both shipped 2.3.0 on October 2. The TypeScript SDK now follows redirects only within the same origin by default, adds maxToolInputElements and OAuth expectedResource audience validation, and changes stateless Streamable HTTP guidance to create a server/transport per request; project tests report major latency and memory reductions for 50–100 MB single-event SSE tool results. The Python SDK adds max_sse_event_size, optional disabling of subscriptions/listen, a one-time HeaderMismatch retry, stricter x-mcp-header registration validation and improved OAuth timeout handling. These are SDK behavior and security-boundary changes, not a new MCP protocol-version announcement.
- Original title
- 2.3.0
- Source
- GitHub · github.com
- Topic
- Development
- Source month
- 2026-10
This is a concise EasyHub summary of the linked source, not the full report or original reporting. Availability and preview conditions are described in the summary and original.
Summary page published · Editorial information