Qeravio
Canonical AI event

Model Context Protocol Client 2.2.0 Deprecates Constructors Without Expected Issuer

The client library now throws an error when a provider's client information mismatches the authorization server.

28 Sept 20261 verified claims1 sources1 observations
What happened

The official source reports this update: @modelcontextprotocol/client@2.2.0. Minor Changes #2887 edd12e2 Thanks @maxisbey ! - Constructing ClientCredentialsProvider , PrivateKeyJwtProvider , StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated: the constructor logs one console.warn and that call signature is marked @deprecated . Behaviour is otherwise unchanged. Pass the issuer of the authorization server the credentials were registered with. fetchToken() throws AuthorizationServerMismatchError , before sending anything, when the provider's client information is bound to a different authorization server than the one it is called with.

Why it matters

This official update documents a development concerning @modelcontextprotocol/client@2.2.0. Its practical significance depends on the scope and evidence stated by the source.

What to watch next

Read the official source update and verify its stated scope, evidence and timing before acting on it.

Connected knowledge

Entities affected by this event

Continue this topic
Evidence trail

Sources behind the event