feat(mcp): serve the stateless 2026-07-28 MCP protocol, and bump dependencies - #23
Merged
Merged
Conversation
Move to MCP SDK v2 (@modelcontextprotocol/server) and agents 0.24, whose createMcpHandler serves 2026-07-28 clients natively and still answers 2025 clients (initialize handshake) through its stateless fallback, on the same /mcp endpoint. Cursor and MCP Inspector still speak only 2025. Session analytics now also count a modern client's server/discover, read from the Mcp-Method header, since modern clients never send initialize. The v2 packages share the project's zod, so the dual-zod @ts-expect-error in servicesProvider is gone.
zod 4.6, hono 4.13, jose 6.2.12, awilix 13.0.5, graphql 16.14.2, vite 8.3,
wrangler 4.144, @cloudflare/vite-plugin 1.62, oxlint 1.86, tailwindcss 4.3.3.
oxlint 1.86 flags irregular whitespace: the two comments that escaped a
glob's "*/" with a zero-width space now write it as {*}, like the rest of
analytics.ts.
No code changes needed. graphql is only used by this server, so there is no second copy to clash with. Checked live on both protocol eras: queries, the schema fetch and query correction behave as on graphql 16.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The MCP server now speaks the stateless 2026-07-28 MCP spec (no
initializehandshake, noMcp-Session-Id), and 2025 clients keep working on the same/mcpURL. This PR also bumps every dependency that can be bumped.How it works
@modelcontextprotocol/server) andagents0.24. ItscreateMcpHandlerserves 2026-07-28 clients natively and answers 2025 clients through its stateless fallback (legacy: "stateless", the default). That fallback is how the server already worked, so 2025 clients see no change.servicesProvideralready builds a fresh server per request, so the factory just returns it.responseMode: "json"replacesenableJsonResponse.initialize, so a session now also counts onserver/discover, which the SDK client sends when it connects. It's read from theMcp-Methodheader, so the body is never touched. The Plausible path is unchanged. A modern client that skips discovery goes uncounted;tools/listis no substitute because clients re-send it every time their cached list expires.@ts-expect-errorinservicesProvideris gone.agents/mcp/serverdoesn't pull in SDK v1, and the bundle drops from 4.13 MB to 2.9 MB.CLAUDE.mdhas a new "MCP protocol versions" section.Dependency bumps
@cloudflare/vite-plugin1.62, oxlint 1.86, tailwindcss 4.3.3.@types/node26. None needed code changes.*/with a zero-width space now write it as{*}.@modelcontextprotocol/server,clientandcorestay pinned at exactly 2.0.0 (2.2.0 is out), because that's whatagents0.24.0, its latest release, declares as its peer.Tested
bun type-check,bun test(184 pass, 5 new),bun lint,bun build.legacy, pinned2026-07-28andautomodes. Every mode connects, lists the 14 tools, returns auth-scoped data fromtenant-overview, runsquery-catalogueand the schema fetch, and keeps write tools hidden by default.Not tested yet
Notes
compatibility_dateinwrangler.jsonc(2025-08-03) is unchanged. It affects Workers runtime behaviour, so it's a separate decision.childsintoidinstead ofchildren, and the retry then fails. graphql 16 behaves the same.