# mcp-handler: what changed from 1 to 2 - Product: mcp-handler (https://whatsnew.fyi/product/mcp-handler) - Vendor: Vercel - Range: changelog entries numbered after v1.1.0 up to and including v2.1.1, stable releases only - Entries below: 4 releases (newest first) - Resolved: 1 is v1.1.0 and 2 is v2.1.1, the newest stable release of each major we track - Carrying security changes: 0 · CVEs mentioned: 0 · Mentioning breaking changes: 0 · Removing or deprecating something: 3 - Page: https://whatsnew.fyi/product/mcp-handler/compare/1...2 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. ## What changed (17 changes, grouped by kind) ### Changed #### v2.1.1 (2026-08-13) - Forward maxSubscriptions to the MCP SDK handler so applications can bound or disable subscription streams #### v2.1.0 (2026-07-30) - Replace createMcpHandler(initialize, serverOptions, config) with createMcpHandler(initialize, options) using a single options object combining ServerOptions with serverInfo, verboseLogs, and onEvent, exported as McpHandlerOptions #### v2.0.1 (2026-07-29) - Mount the MCP handler directly at a framework route instead of using legacy transport endpoint routing - CLI now generates app/api/mcp/route.ts for the MCP handler #### v2.0.0 (2026-07-29) - Upgrade to MCP SDK v2 and the 2026-07-28 MCP specification - Handler now serves the stateless 2026-07-28 protocol with per-request _meta envelope and server/discover natively - SDK's stateless legacy fallback answers 2025-era Streamable HTTP clients from the same handler - The /sse and /message endpoints answer 410 Gone - Tool/prompt/resource registration follows SDK v2 with registerTool using z.object(...) Standard Schemas - extra.authInfo is now ctx.http?.authInfo - withMcpAuth now builds 401/403 challenges with the SDK's consolidated OAuthError/bearerAuthChallengeResponse ### Removed #### v2.1.0 (2026-07-30) - Remove deprecated 1.x compatibility shims: basePath, streamableHttpEndpoint, sseEndpoint, sseMessageEndpoint, disableSse, redisUrl, maxDuration, and sessionIdGenerator #### v2.0.0 (2026-07-29) - Legacy HTTP+SSE transport (protocol 2024-11-05) has been removed - Variadic server.tool(...) is gone ### Deprecated #### v2.0.1 (2026-07-29) - Legacy route, SSE, Redis, and session config keys remain accepted as ignored 2.x compatibility shims #### v2.0.0 (2026-07-29) - redis dependency and redisUrl, maxDuration, and sessionIdGenerator config options are deprecated no-ops - Dynamic Client Registration is deprecated by the spec in favor of Client ID Metadata Documents ## Release notes ### v2.1.1 - Date: 2026-08-13 - Version: v2.1.1 - Original notes: https://github.com/vercel/mcp-handler/releases/tag/v2.1.1 - Permalink: https://whatsnew.fyi/product/mcp-handler/releases/v2.1.1 - **changed** — Forward maxSubscriptions to the MCP SDK handler so applications can bound or disable subscription streams ###### Patch Changes - e38a932: Forward `maxSubscriptions` to the MCP SDK handler so applications can bound or disable subscription streams. ### v2.1.0 - Date: 2026-07-30 - Version: v2.1.0 - Original notes: https://github.com/vercel/mcp-handler/releases/tag/v2.1.0 - Permalink: https://whatsnew.fyi/product/mcp-handler/releases/v2.1.0 - **changed** — Replace createMcpHandler(initialize, serverOptions, config) with createMcpHandler(initialize, options) using a single options object combining ServerOptions with serverInfo, verboseLogs, and onEvent, exported as McpHandlerOptions - **removed** — Remove deprecated 1.x compatibility shims: basePath, streamableHttpEndpoint, sseEndpoint, sseMessageEndpoint, disableSse, redisUrl, maxDuration, and sessionIdGenerator ###### Minor Changes - 8398dbd: `createMcpHandler(initialize, serverOptions, config)` is now `createMcpHandler(initialize, options)` — a single options object combining the SDK's `ServerOptions` with `serverInfo`, `verboseLogs`, and `onEvent` (exported as `McpHandlerOptions`). The deprecated 1.x compatibility shims (`basePath`, `streamableHttpEndpoint`, `sseEndpoint`, `sseMessageEndpoint`, `disableSse`, `redisUrl`, `maxDuration`, `sessionIdGenerator`) are removed. ### v2.0.1 - Date: 2026-07-29 - Version: v2.0.1 - Original notes: https://github.com/vercel/mcp-handler/releases/tag/v2.0.1 - Permalink: https://whatsnew.fyi/product/mcp-handler/releases/v2.0.1 - **changed** — Mount the MCP handler directly at a framework route instead of using legacy transport endpoint routing - **changed** — CLI now generates app/api/mcp/route.ts for the MCP handler - **deprecated** — Legacy route, SSE, Redis, and session config keys remain accepted as ignored 2.x compatibility shims ###### Patch Changes - e6e6378: Mount the MCP handler directly at a framework route and remove legacy transport endpoint routing. The CLI now generates `app/api/mcp/route.ts`; deprecated route, SSE, Redis, and session config keys remain accepted as ignored 2.x compatibility shims. ### v2.0.0 - Date: 2026-07-29 - Version: v2.0.0 - Original notes: https://github.com/vercel/mcp-handler/releases/tag/v2.0.0 - Permalink: https://whatsnew.fyi/product/mcp-handler/releases/v2.0.0 - **changed** — Upgrade to MCP SDK v2 and the 2026-07-28 MCP specification - **changed** — Handler now serves the stateless 2026-07-28 protocol with per-request _meta envelope and server/discover natively - **changed** — SDK's stateless legacy fallback answers 2025-era Streamable HTTP clients from the same handler - **removed** — Legacy HTTP+SSE transport (protocol 2024-11-05) has been removed - **changed** — The /sse and /message endpoints answer 410 Gone - **deprecated** — redis dependency and redisUrl, maxDuration, and sessionIdGenerator config options are deprecated no-ops - **changed** — Tool/prompt/resource registration follows SDK v2 with registerTool using z.object(...) Standard Schemas - **removed** — Variadic server.tool(...) is gone - **changed** — extra.authInfo is now ctx.http?.authInfo - **changed** — withMcpAuth now builds 401/403 challenges with the SDK's consolidated OAuthError/bearerAuthChallengeResponse - **deprecated** — Dynamic Client Registration is deprecated by the spec in favor of Client ID Metadata Documents ###### Major Changes - 33c06b6: Upgrade to MCP SDK v2 and the 2026-07-28 MCP specification (CIMD era). - The handler now serves the stateless 2026-07-28 protocol (per-request `_meta` envelope, `server/discover`) natively, with the SDK's stateless legacy fallback answering 2025-era Streamable HTTP clients from the same handler. - **Breaking**: requires `@modelcontextprotocol/server` ^2.0.0 (replaces the `@modelcontextprotocol/sdk` peer dependency), `zod` ^4.2.0 for schemas, and Node.js 20+. - **Breaking**: the legacy HTTP+SSE transport (protocol 2024-11-05) has been removed. `/sse` and `/message` endpoints answer `410 Gone`; the `redis` dependency and `redisUrl`, `maxDuration`, and `sessionIdGenerator` config options are deprecated no-ops. - **Breaking**: tool/prompt/resource registration follows SDK v2 (`registerTool` with `z.object(...)` Standard Schemas; variadic `server.tool(...)` is gone; `extra.authInfo` is now `ctx.http?.authInfo`). - `withMcpAuth` now builds its 401/403 challenges with the SDK's consolidated `OAuthError`/`bearerAuthChallengeResponse`, keeping RFC 9728 `resource_metadata` discovery in place for CIMD-era authorization flows. Dynamic Client Registration is deprecated by the spec in favor of Client ID Metadata Documents — see README.