Issues
Volume
Response Time
Time to first maintainer response
Stale Issues
Issues with no activity
Issues by Label
| Label | Count |
|---|---|
| enhancement | 23 |
| bug | 17 |
| documentation | 9 |
| auth | 4 |
| security | 4 |
| SEP | 2 |
| SEP-requested | 1 |
| draft | 1 |
| governance | 1 |
| proposal | 1 |
| schema | 1 |
| sdk/2026-07-feedback | 1 |
Issues Awaiting Maintainer Response
Sorted by longest wait time first
| Issue | Title | Labels | Comments | Waiting |
|---|---|---|---|---|
| #229 | Pagination for tool/call | enhancement | 5 | 524d |
| #569 | Unspecified error handling for tool calls with output schema | enhancement | 2 | 466d |
| #910 | Specification should be more prescriptive about client/host/LLM behavior | enhancement | 0 | 425d |
| #1281 | Versioning challenges with spec negotiation – client/server compatibility & rollout concerns | enhancement | 5 | 396d |
| #1341 | Obligatory MCP state transitions | (unlabeled) | 2 | 384d |
| #1416 | Bug(Schema): Linting issues found using the @sourcemeta/jsonschema cli | bug | 0 | 364d |
| #2452 | Tasks SEP-1686: In-progress results | bug | 1 | 161d |
| #2470 | Proposal: Capability-Aware Tool Presentation for Heterogeneous Model Sizes | (unlabeled) | 4 | 159d |
| #2600 | Schema generation pipeline may produce overly permissive schemas without safeguards | bug | 1 | 136d |
| #2721 | Clarify behavior when `initialize.params.protocolVersion` conflicts with `MCP-Protocol-Version` | bug | 0 | 111d |
| #2734 | No visibility of errors from tool call responses | bug | 8 | 108d |
| #2920 | MRTR url-mode: standardize the "still waiting" response (state-only InputRequiredResult) + retry/cancel guidance | (unlabeled) | 0 | 78d |
| #2919 | MRTR: `inputRequests` is a closed enum of three methods — add an extensible / reverse-DNS-namespaced member type | (unlabeled) | 0 | 78d |
| #2939 | SEP-2549: clarify whether cacheScope is required or defaults to public | bug | 0 | 75d |
| #3003 | [Spec Gap] Tool Execution Errors lack a schema-governed signal for LLM forwarding — structuredContent should be defined for error path | bug | 10 | 61d |
| #3114 | generate:schema:json produces empty schemas when using wildcard type on Windows | bug | 0 | 41d |
| #3207 | MCP-2026-008: CacheableResult cacheScope:public enables cross-user cache poisoning | (unlabeled) | 0 | 26d |
| #3213 | MCP-2026-015: server/discover instructions field enables prompt injection (amplified by cacheScope:public) | (unlabeled) | 5 | 25d |
| #3223 | redirect URIs using localhost | bug | 0 | 22d |
| #3224 | A list of Implementation Requirements for OAuth Client ID Metadata Document | bug | 0 | 21d |
| #3226 | Clarify whether notifications/resources/list_changed should be sent if the list of resource templates changes | bug | 0 | 21d |
| #3232 | [Proposal] Add visibility / 'hidden': true attribute for confidential prompts and server instructions | (unlabeled) | 1 | 20d |
| #3238 | `inputSchema` and `requestedSchema` hard-code JSON Schema keywords into dialect-agnostic slots | bug | 0 | 18d |
| #3237 | Tasks extension (SEP-2663): no interoperable surface for partial output of a running task | (unlabeled) | 0 | 18d |
| #3337 | [IG #2626 / Channel-Policy Per-Send Audit] Proposal for the Enterprise IG Audit/Compliance Scope | (unlabeled) | 0 | 0d |
Stats — volume, response time, staleness, labels
Volume
Response Time
Time to first maintainer response
Stale Issues
Issues with no activity
Issues by Label
| Label | Count |
|---|---|
| bug | 154 |
| ready for work | 131 |
| P2 | 114 |
| enhancement | 107 |
| v2 | 95 |
| P3 | 88 |
| fix proposed | 76 |
| needs decision | 71 |
| potentially close | 47 |
| v1 | 46 |
| auth | 45 |
| P1 | 18 |
| question | 14 |
| spec-2026-07-28 | 14 |
| documentation | 13 |
| needs confirmation | 12 |
| needs design | 10 |
| good first issue | 9 |
| help wanted | 7 |
| needs repro | 7 |
| needs maintainer | 5 |
| breaking change | 4 |
| pending SEP approval | 4 |
| improves spec compliance | 3 |
| v2-fixes | 1 |
Untriaged (46)
No type label — bot pending or needs manual triage.
untriaged (46) — Bot has not labeled yet, or needs manual type assignment.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #1459 | pcarleton | _onclose() incomplete cleanup: _timeoutInfo not cleared and stale .finally() can delete new connection's abort controller | 1 | 1 | 210d | |
| #1565 | joy7758 | RC1 Review Request: AAR-MCP-2.0 Verifiable Interaction Layer (Conformance Gate included) | 1 | — | 192d | |
| #1956 | sejano77 | SEP-1303: Input validation errors should return Tool Execution Errors, not Protocol Errors | 3 | 1 | 130d | |
| #1959 | apicurius | Bug: `_handleSseStream` retains reader lock on stream close, leaking ~50MB per reconnection | 2 | 1 | 130d | |
| #2018 | blackwell-systems | handleAutomaticTaskPolling ignores AbortSignal; cancelled requests poll indefinitely | 1 | 1 | 120d | |
| #2042 | morozow | Security: Transitive dependencies with known vulnerabilities in @modelcontextprotocol/sdk@1.29.0 | 1 | 1 | 114d | |
| #2054 | khill1269 | `registerPrompt()` silently drops `icons` from PromptDefinition config | 1 | 1 | 112d | |
| #2078 | mcpsafe-gh | Security scan results for typescript-sdk — MCPSafe AIVSS 53/100 (Grade F) | 2 | — | 112d | |
| #2083 | swadel | Type inconsistency: StreamableHTTPServerTransport.onclose widens Transport interface contract under exactOptionalPropertyTypes | 2 | 1 | 111d | |
| #2093 | thkim-us | v2 alpha: @modelcontextprotocol/server has @cfworker/json-schema as optional peer but imports it unconditionally | 2 | 1 | 110d | |
| #2151 | fallintoplace | closeSSEStream() breaks request-scoped SSE resumability for terminal responses | 1 | 1 | 100d | |
| #2237 | dvaerum | [PLEASE DELETE] sorry | 1 | — | 92d | |
| #2257 | idobrovolski | KIMI mcp integration fix | 1 | 1 | 88d | |
| #2480 | SnowSky1 | Streamable HTTP server accepts invalid media types by Accept-header substring | — | — | 51d | |
| #2489 | morluto | [v2] Origin and Host validators accept userinfo before allowlisted hostnames | 1 | — | 50d | |
| #2491 | zelinewang | [v2] Declaration source maps (.d.cts.map/.d.mts.map) reference unshipped src/ with empty sourcesContent — dangling for consumers | 1 | — | 50d | |
| #2515 | tobiasBora | [v2] Multiple connect per server | — | — | 46d | |
| #2542 | EvanGribar | [v2] MRTR wipe-cache example reads unvalidated elicitation content and defaults malformed scope to all | — | — | 40d | |
| #2545 | tobiasBora | [v2] Server: print warning if `sendResourceUpdated` is used but `subscribe` is not set | 1 | — | 39d | |
| #2591 | solirpa | OAuth: isLoopbackHost rejects *.localhost subdomains, breaking host-based local dev (InsecureTokenEndpointError) | 4 | — | 33d | |
| #2615 | teamleaderleo | [v2] Legacy Streamable HTTP reconnects continue after the client request times out | — | — | 27d | |
| #2619 | claude | [v2] versionNegotiation: 2xx server/discover response with an empty or unparseable body fails connect() instead of falling back to legacy initialize | — | — | 26d | |
| #2643 | claude | [v2] StreamableHTTPClientTransport: auth awaits in _send are un-abortable — requestSignal cannot cancel token()/onUnauthorized/metadata-discovery parks | — | — | 22d | |
| #2641 | claude | [v2] Client.listen() rejections escape as process-level unhandledRejection while the send is in flight; a parked send hangs listen() past its ack timeout | — | — | 22d | |
| #2646 | claude | [v2] Legacy-era cancel of a resumed request: notifications/cancelled inherits the request's resumptionToken, so the transport swallows the cancellation and opens a rogue resumed GET | 1 | — | 22d | |
| #2682 | Erli-ms | [v2] StreamableHTTPClientTransport standby GET/SSE stream reconnects forever when the server gracefully idle-closes it ( maxRetries never trips) | — | — | 15d | |
| #2689 | ev253 | Streamable HTTP server accepts unsafe integer in x-mcp-header field when mirrored header is absent | — | — | 13d | |
| #2695 | sainikhiljuluri | `maxTotalTimeout` is never enforced unless a progress notification arrives | 8 | — | 12d | |
| #2693 | sainikhiljuluri | Resource templates ignore `enabled`: disable() leaves them listed, readable and completable | 1 | — | 12d | |
| #2700 | trickyfalcon | Client follows server 3xx into internal/loopback services: redirect SSRF / protocol confusion (bare fetch, no host validation) — same class as python-sdk #3358 | — | — | 10d | |
| #2701 | johnhenry | Deno: TS2307 on all .js subpath imports — './*' exports map types to '*.js.d.ts' | 2 | — | 10d | |
| #2704 | qiyueqiu | Stateless StreamableHTTPServerTransport: per-request requirement is invisible through the Node wrapper (500 with empty body) | 1 | — | 9d | |
| #2705 | qiyueqiu | registerTool with zod raw shape: refine/superRefine/transform are silently dropped from validation | 1 | — | 9d | |
| #2715 | roy-tong | Semantics question: how should tool-call telemetry count cancelled or retried `tools/call` requests? | 1 | — | 8d | |
| #2718 | lukeyeager | [v2] Incompatibility with refresh_tokens from Azure when client_id=resource_id | — | — | 7d | |
| #2719 | dmcnelis | Docs: registerClient's @deprecated notice cites SEP-2577; DCR deprecation is PR #2858 (SEP-2577 is Roots/Sampling/Logging) | — | — | 7d | |
| #2721 | papayet | outputSchema always emitted as JSON Schema draft-07, breaking clients that only accept 2020-12 | 1 | — | 6d | |
| #2722 | Seinra | [v2] Era-negotiation probe drops spec-conformant server/discover responses (top-level resultType/_meta) and misclassifies modern servers as legacy | 3 | — | 6d | |
| #2723 | YatsukBogdan1 | remove() is a no-op after a handle is renamed, and the entry stays callable | — | — | 6d | |
| #2728 | MahathirMohammadShuvo | UriTemplate.match() does not percent-decode extracted values | 4 | — | 6d | |
| #2730 | amirtafreshi | StreamableHTTP server transport returns bare 400 for a notification when the request has Connection: close | 1 | — | 6d | |
| #2733 | cliffhall | [v2] OAuth discovery validates any /.well-known/openid-configuration document as OIDC, rejecting conforming RFC 8414 metadata | — | — | 5d | |
| #2735 | chelojimenez | Client.listTools() silently drops pages when a server repeats a cursor | 2 | — | 4d | |
| #2737 | yusifaliyevpro | Upgrade `zod` dependency to `4.5.x` | 2 | — | 4d | |
| #2739 | jacekradko | StreamableHTTPClientTransport leaves POST requests pending when their SSE response ends or errors | 2 | — | 3d | |
| #2742 | skeerthish | experimental.tasks.getTaskResult() throws TypeError: Cannot read properties of undefined (reading '_zod') when the optional result schema is omitted | 1 | — | 1d |
Bugs (154)
Queue — pick the top fix-ready and work it. Priority then age.
in-progress (7) — Assigned — someone is on it.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #754 | boogie-amplitude | ProxyOAuthServerProvider fails with Zod validation error when using Ory Hydra as OAuth provider | bug P2 | 4 | 1 | 419d |
| #1149 | spacewander | output schema has unnecessary restriction type=object | bug P2 | 7 | 1 | 285d |
| #1186 | Miaoxingren | Zombie Task Collision in StreamableHTTPServerTransport | bug P2 | 3 | 1 | 278d |
| #1429 | aldipower | Do not return and expose internal errors to the client as this is a security risk | bug P2 | 3 | 1 | 216d |
| #1658 | arthurchan35 | StreamableHTTPServerTransport has no public API to reconstruct a session-aware transport from persisted session data | bug P2 | 4 | — | 175d |
| #911 | dsp-ant | Implement consistent structuredContent handling per specification clarification | bug P3 | — | — | 365d |
| #2604 | conorbronsdon | CODEOWNERS auth paths do not resolve on main, so the auth team is never auto-requested | bug P3 | 1 | — | 30d |
fix-proposed (73) — Bot posted a suggested fix — review the diff. P0/P1 first.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #209 | praboud-ant | /token endpoint should validate redirect_uri matches | bug P1 | 3 | 1 | 531d |
| #235 | jspahrsummers | Revoke tokens if authorization code presented a second time | bug P1 | 3 | 1 | 522d |
| #971 | NorthIsUp | CommonJS export paths broken - missing index.js file in dist/cjs | bug P1 | 8 | 1 | 341d |
| #1562 | gogakoreli | schemaToJson() produces $ref in tool inputSchema, causing LLM failures | bug P1 | 5 | 1 | 193d |
| #2002 | ElliotDrel | Bug: StdioServerTransport doesn't handle stdin close/end — causes zombie process accumulation | bug P1 | 8 | 1 | 124d |
| #2084 | rsalus | [SEP-1613 regression] tools/list still emits draft-07 in 1.29.0 — `target` option missing from mcp.js `toJsonSchemaCompat` calls | bug P1 | 5 | 1 | 111d |
| #2273 | itosa-kazu | Root package export points to missing dist index files | bug P1 | 3 | 1 | 84d |
| #147 | au-re | Additional parameters are not passed through to tools | bug P2 | 3 | 1 | 568d |
| #149 | disintegrator | Unordered and partial query parameter matching | bug P2 | 5 | 1 | 566d |
| #321 | nichtsam | SSEServerTransport doesn't seem to close properly | bug P2 | 9 | 1 | 507d |
| #392 | mhart | Promise/async handling causes unhandled rejections | bug P2 | 4 | 1 | 496d |
| #471 | tobegit3hub | MCP SDK Can not handle the MCP Servers with subpath | bug P2 | 9 | 1 | 480d |
| #470 | tobegit3hub | MCP SDK Path Handling Bug for Subpath Servers | bug P2 | 5 | 1 | 480d |
| #563 | joshcanhelp | Invalid JSON RPC requests do not respond with an error | bug P2 | 2 | 1 | 460d |
| #581 | ZachGerman | Enforcing Content-Type header on client requests | bug P2 | 1 | 1 | 456d |
| #650 | zackify | Dynamic Resources 404 when using nested paths | bug P2 | 2 | 1 | 441d |
| #677 | dudo | ResourceTemplate fails when user selects <Empty> for optional parameter | bug P2 | 4 | 1 | 438d |
| #759 | johnfriz | OAuth token exchange fails with URL-encoded responses - assumes JSON format only | bug P2 | 4 | 1 | 418d |
| #771 | alexhermida | Memory leak in StreamableHTTP and SSE | bug P2 | 6 | 1 | 413d |
| #776 | elvisjhonataoliveira | [BUG] Multi-Node Deployment with Persistent Storage Mode not working | bug P2 | 5 | 1 | 412d |
| #780 | shellRaining | onerror and other listener not remove after client close (stdio) | bug P2 | 4 | 1 | 411d |
| #811 | mahmoudmoravej | Cannot destructure property 'requestInfo' of 'undefined' as it is undefined. | bug P2 | 4 | 1 | 404d |
| #817 | nikhilmat | Package attaches process signal handlers | bug P2 | 2 | 1 | 400d |
| #842 | cameroncooke | Bulk tool registration causes EventEmitter memory leak warnings | bug P2 | 4 | 1 | 393d |
| #868 | shellRaining | When executing client.close(), onerror will be executed twice (Streamable HTTP) | bug P2 | 8 | 1 | 386d |
| #876 | Kelier | sse timeout set dont work & always close after 5mins | bug P2 | 5 | 1 | 384d |
| #893 | inverted-capital | McpServer re-registers capabilities after connect, blocking dynamic registration even when capabilities were supplied at construction | bug P2 | 3 | 1 | 377d |
| #941 | jeremyshi-ant | OAuth: scope parameter missing from token exchange requests | bug P2 | 1 | 1 | 353d |
| #943 | y0geshdev | The bug in InMemoryEventStore break SSE stream resumability | bug P2 | 4 | 1 | 351d |
| #1001 | younaman | Bug Report-3: Missing Progress Monotonicity Validation Leading to Resource Exhaustion | bug P2 | 2 | 1 | 334d |
| #1004 | CahidArda | storeEvent in EventStore Receives Hardcoded `streamId` | bug P2 | 2 | 1 | 333d |
| #1079 | 4bd4ll4h | # MCP SDK ResourceTemplate URI Validation Issue: RFC 6570 Template Matching Behavior | bug P2 | 8 | 1 | 302d |
| #1167 | bmingles | Support `roots/list` request from server to client | bug P2 | 6 | 1 | 280d |
| #1234 | pcarleton | OAuth: Resource metadata URL lost after redirect, causing token exchange to fail | bug P2 | 2 | 1 | 271d |
| #1308 | joshjg | Tool output validation fails when outputSchema is a Zod schema other than ZodObject | bug P2 | 8 | 1 | 259d |
| #1385 | punkpeye | Task-augmented tool call errors are wrapped incorrectly, masking actual error messages | bug P2 | 4 | 1 | 230d |
| #1417 | severi | MCP servers deployed on AWS Lambda Function URLs stopped working after upgrading from v1.24.2 to v1.25.0+ | bug P2 | 5 | 1 | 223d |
| #1471 | mattzcarey | registerToolTask handlers receive wrong arguments when inputSchema is omitted | bug P2 | 3 | 1 | 210d |
| #1476 | Bacra | Client received "no session ID or not initialization request" when server restart | bug P2 | 2 | 1 | 210d |
| #1582 | asoorm | Scope overwrite in 403 upscoping prevents progressive authorization for servers with per-operation scopes | bug P2 | 1 | 1 | 189d |
| #1635 | ac-aashugupta | StreamableHTTPClientTransport should handle 404 and 406 gracefully for GET SSE stream | bug P2 | 3 | 1 | 180d |
| #1641 | semistrict | StreamableHTTPClientTransport cannot be restarted after close() — breaks OAuth re-authentication | bug P2 | 2 | 1 | 178d |
| #1708 | mbochneak | StreamableHTTPClientTransport doesn't handle 404 per spec (no session clear + re-init) | bug P2 | 8 | 1 | 167d |
| #1760 | DhyeyaDesai | Race condition in auth() causes refresh token invalidation when rotating tokens are used | bug P2 | 3 | 1 | 160d |
| #1819 | yu1uuu | Resources: Disable listChanged capability in V1x | bug P2 | 3 | 1 | 155d |
| #1844 | felixweinberger | Elicit primitive schemas reject extra JSON Schema keys (pattern, format, etc.) | bug P2 | 2 | 1 | 152d |
| #1869 | dgon-jd | prompts/get rejects omitted `arguments` when all argsSchema fields are optional; tools fix (#1404) not in 1.x | bug P2 | 3 | 1 | 145d |
| #1872 | carrotRakko | SSE client: duplicate Authorization header when using eventSourceInit.fetch + requestInit.headers | bug P2 | 2 | 1 | 145d |
| #1944 | bokelley | StreamableHTTPServerTransport rejects JSON-only Accept with 406 even when enableJsonResponse: true | bug P2 | 3 | 1 | 133d |
| #1960 | andypalmi | RegisteredTool.update() crashes with ZodObject inputSchema (passthrough schemas) | bug P2 | 2 | 1 | 129d |
| #1968 | huven | OAuth resource indicator from protected resource metadata is normalized with a trailing slash | bug P2 | 3 | 1 | 127d |
| #1994 | Phil-Browne | Stateless StreamableHTTPServerTransport: non-initialize requests return 500 with empty body when transport is reused (regression vs 1.24.3) | bug P2 | 2 | 1 | 124d |
| #2011 | Euaell | zod listed in both dependencies and peerDependencies causes duplicate installs and TS type-incompatibility | bug P2 | 1 | 1 | 122d |
| #2012 | blackwell-systems | tools/call with null arguments returns -32603 (InternalError) instead of being accepted | bug P2 | 1 | 1 | 122d |
| #2023 | JoannaaKL | StdioClientTransport.close() does not kill the process tree, leaving orphan processes | bug P2 | 2 | 1 | 118d |
| #2037 | pkailas | DEFAULT_INHERITED_ENV_VARS | bug P2 | 2 | 1 | 115d |
| #2076 | ContextVM-org | `resetTimeoutOnProgress` on low-level `request()` only works when `onprogress` is explicitly provided | bug P2 | 3 | 1 | 112d |
| #2108 | cclabadmin | Streamable HTTP server accepts mismatched `MCP-Protocol-Version` header and body `protocolVersion` on `initialize` | bug P2 | 5 | 1 | 108d |
| #2126 | DmitroKihtenko | OAuth AS metadata discovery crashes on 200 OK + non-JSON response instead of falling back to OIDC | bug P2 | 2 | 1 | 104d |
| #2145 | produtoramaxvision | tools/list returns empty inputSchema for ZodEffects-wrapped schemas (Zod .superRefine / .refine / .transform / .pipe) | bug P2 | 5 | 1 | 102d |
| #2155 | randyramig | Claude.AI hangs with 408 timeout when MCP tool response JSON contains U+2028 (LINE SEPARATOR) or U+2029 (PARAGRAPH SEPARATOR) | bug P2 | 3 | 1 | 100d |
| #2165 | sakthiveltofficial | AbortSignal cancellation throws `SdkErrorCode.RequestTimeout` instead of a distinct abort error | bug P2 | 4 | 1 | 96d |
| #2166 | sakthiveltofficial | `UriTemplate.match()` returns `null` for multi-variable path expressions like `{userId,format}` | bug P2 | 3 | 1 | 96d |
| #2232 | luizgribeiro | sendToolListChanged drops notifications on stateless Streamable HTTP transports (missing relatedRequestId) | bug P2 | 7 | 1 | 92d |
| #2247 | SSanju | Invalid Request frames silently dropped with no error response — client hangs waiting for id that never resolves | bug P2 | 6 | 1 | 91d |
| #2284 | felixweinberger | Spec-method requests with invalid params answer -32603 instead of -32602 | bug P2 | 6 | 1 | 81d |
| #2433 | scottmsilver | streamable HTTP server: no duplicate-in-flight request-id guard — concurrent POSTs with the same JSON-RPC id cross-wire responses | bug P2 | 3 | 1 | 60d |
| #2464 | jtemps | zod v4: toJSONSchema options are hardcoded — z.date() breaks tools/list; output schemas advertise required/closed shapes the raw structuredContent can't satisfy | bug P2 | 1 | 1 | 55d |
| #2531 | jqnatividad | Widen `@hono/node-server` range: `^1.19.9` cannot resolve past GHSA-frvp-7c67-39w9 (no patched 1.x) | bug P2 | 2 | — | 42d |
| #929 | LandonSchropp | Client#listPrompts results in MCP error -32601: Method not found | bug P3 | 5 | 1 | 357d |
| #949 | Lutz2015 | Client error for command SSE stream disconnected: TypeError: terminated | bug P3 | 4 | 1 | 348d |
| #1914 | shaun0927 | authExtensions docs say custom claims override reserved JWT claims, but implementation keeps reserved claims authoritative | bug P3 | 4 | 1 | 138d |
| #2112 | sceran | docs(README): `@modelcontextprotocol/fastify` missing from middleware listing | bug P3 | 4 | 1 | 108d |
ready-for-work (43) — Triaged and reproducible — pick one up. P0/P1 first.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #174 | punkpeye | stderr is not available until after start is called | bug P1 | 3 | 1 | 543d |
| #251 | gmaison | Bug: npm spawn processes incorrectly use root directory instead of project directory | bug P1 | 1 | 1 | 518d |
| #553 | sram1337 | tool/call results in 'Method not found' with StreamableHTTPServerTransport in stateful session after successful initialize (SDK v1.12.0) | bug P1 | 4 | 1 | 463d |
| #778 | junjiexv | invoke asyn method in mcp tool through StreamableHttpTransport cause early return from tool call | bug P1 | 5 | 1 | 412d |
| #852 | christopherorea | Missing session reuse in browser: client.connect ignores mcp-session-id | bug P1 | 9 | 1 | 391d |
| #1028 | juanlluva | ListTools request handler fails to generate inputSchema (jsonSchema) | bug P1 | 7 | 1 | 321d |
| #2650 | sushantkumar23 | [v2] subscriptions/listen holds a stream open even when it has honoured nothing | bug P1 | 1 | — | 21d |
| #436 | jigarchhadwa | SSE client is not adding headers from requestInit? in _commonHeaders method | bug P2 | 9 | 2 | 489d |
| #484 | ajgray-stripe | SDK makes HTTPS fetches through an HTTP proxy | bug P2 | 3 | 1 | 477d |
| #509 | rickchow88 | Bug Report: Tool Handlers Not Invoked with StdioServerTransport on macOS | bug P2 | 3 | 1 | 472d |
| #573 | carlpeaslee | Dynamically listed Resources created by ResourceTemplates display the ResourceTemplates rather than their own | bug P2 | 2 | 1 | 459d |
| #579 | pavelfeldman | StdioClientTransport does not follow the spec on close | bug P2 | — | — | 458d |
| #951 | thomasst | Prefer token endpoint auth method obtained during OAuth client registration | bug P2 | 3 | 1 | 348d |
| #999 | younaman | Bug Report-1: Missing Cancellation Logging Implementation | bug P2 | 2 | — | 334d |
| #1049 | masx200 | [MCP-SDK] stdio client crashes with "MCP error -32000: Connection closed" when spawned server exits unexpectedly | bug P2 | 2 | 1 | 308d |
| #1112 | YashwantRamAB | Can not create proxy OAuth flow with google OAuth | bug P2 | 5 | 1 | 292d |
| #1211 | whynixx | SSE stream disconnected: TypeError: terminated | bug P2 | 6 | 1 | 274d |
| #1415 | mozmo15 | getParseErrorMessage prioritizes error.message which bypasses custom Zod errors | bug P2 | 4 | 1 | 223d |
| #1858 | maximemoreillon | ERR_PACKAGE_PATH_NOT_EXPORTED with @modelcontextprotocol/express | bug P2 | 4 | 2 | 148d |
| #1954 | daksh-goyal | adaptOAuthProvider returns expired tokens without checking expiry, breaking long-running StreamableHTTP connections | bug P2 | 2 | 1 | 131d |
| #2048 | morozow | High-severity CVEs via pnpm audit | bug P2 | 1 | 1 | 113d |
| #2098 | cloudingenium-automation | StreamableHTTPClientTransport: 2-retry SSE reconnect ceiling + silent-success after exhaustion | bug P2 | 2 | 1 | 109d |
| #2233 | marc-wilson | Published package omits `src/` but `dist/**/*.js.map` references it, breaking source-map consumers | bug P2 | 4 | 1 | 92d |
| #2499 | ayush00git | Bug: Resumption token dropped when a resumed SSE stream disconnects before any id-bearing event | bug P2 | 1 | — | 49d |
| #2548 | mpalmer80216 | Widen @hono/node-server range to ^1.19.9 || ^2 so GHSA-frvp-7c67-39w9 is reachable (npm suggests a breaking downgrade) | bug P2 | 3 | — | 39d |
| #2559 | felixweinberger | Streamable HTTP: JSON-response-mode stream mappings never complete their lifecycle | bug P2 | 4 | — | 36d |
| #2558 | felixweinberger | Streamable HTTP: close replayed request streams once no in-flight requests remain | bug P2 | 2 | — | 36d |
| #2560 | felixweinberger | InMemoryEventStore: standalone-stream resume broken by getStreamIdFromEventId split | bug P2 | 1 | — | 36d |
| #2562 | felixweinberger | Streamable HTTP: pre-existing hardening items from the #2547 review | bug P2 | 2 | — | 36d |
| #2568 | mdi-odoo | normalizeHeaders references the bare global `HeadersInit`, breaking Node-only consumers with skipLibCheck: false | bug P2 | 1 | — | 36d |
| #2575 | igorsaevets | codemod v1-to-v2 hoists rewritten imports above the file's license header | bug P2 | 2 | — | 35d |
| #2580 | sweetrb | `_onprogress` raises a protocol error for a race servers cannot avoid (progress notification arriving with the response) | bug P2 | 4 | — | 34d |
| #2605 | UberBlackCat | Memory leak: `AjvJsonSchemaValidator.getValidator()` recompiles schemas without `$id` on every call | bug P2 | 1 | — | 30d |
| #2607 | blakebauman | createMcpHandler: reused McpServer instance grows an unbounded onclose chain — memory leak, then uncatchable RangeError after ~20k requests | bug P2 | — | — | 30d |
| #2612 | sebthom | Client.callTool() throws -32602 after tools/list_changed replaces an in-flight call's output schema | bug P2 | 1 | — | 28d |
| #42 | jspahrsummers | Typechecking should fail on returning {} for all requests | bug P3 | 2 | 1 | 662d |
| #584 | localden | SDK assumes one authorization server to be used from PRM | bug P3 | — | — | 456d |
| #1400 | AI-Hub-Admin | MCP 1.25 Cursor Second Connection to StreamableHTTPServerTransport Initialization Request Failed | bug P3 | 3 | 1 | 228d |
| #2410 | christopher-h-johnson | [v2] feedback: Client sends legacy `initialize` to non-conforming "MCP" endpoint — no dual-era probe | bug P3 | 7 | 2 | 62d |
| #2536 | sebthom | stdio.ts/ReadBuffer retains consumed input and copies the next stdio chunk | bug P3 | 1 | — | 40d |
| #2553 | colinaaa | Web-standard SSE responses override the HTTP server keep-alive lifetime | bug P3 | 2 | — | 37d |
| #2614 | sebthom | Client.listTools() corrupts its cached tool metadata when an output schema fails to compile | bug P3 | 1 | — | 28d |
| #2622 | javydreamercsw | McpServer constructor capabilities.tools.listChanged is silently overridden by setToolRequestHandlers() | bug P3 | 1 | — | 25d |
needs-maintainer (11) — Reporter replied, or bot/triage flagged for maintainer judgment.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #539 | ghalibansari | Raw bytes support sending to mcp server in callTool method | bug P3 | 5 | — | 467d |
| #861 | utkarshpandey6 | StreamableHTTPClientTransport is not implementing Transport properly | bug P3 | 2 | 1 | 387d |
| #181 | theodormarcu | MCP should return empty instead of error if tools / prompts / resources are not defined | bug | 9 | 1 | 540d |
| #342 | cj2a7t | SSEClientTransport | bug | 6 | 1 | 504d |
| #419 | bbracha-evinced | Cannot load a basic STDIO MCP server (JS) in claude desktop | bug | 3 | 1 | 491d |
| #545 | pavinduLakshan | Resolving Authorization server metadata URL omits the base path of the Authorization server URL | bug | 13 | 1 | 464d |
| #737 | Mohhit1230 | Request time out issue repeatedly | bug | 7 | 1 | 424d |
| #912 | zhuyuanmin | 【BUG】Use Koa server create StreamableHTTPServerTransport, when call tool, server crash! | bug | 5 | 1 | 364d |
| #2146 | One-Up-Dev | A se | bug | — | — | 102d |
| #2510 | evdbogaard | Mid-session re-auth after refresh-token expiry dead-ends: send() gets "REDIRECT" and throws UnauthorizedError without ever exchanging the new code | bug | 2 | — | 47d |
| #2598 | czh2774 | v2: extension methods shadowed by legacy spec-method registry — custom tasks/get & tasks/cancel handlers unreachable (-32601 before handler lookup) | bug | 2 | — | 32d |
close-candidates (14) — Bot says already-fixed/not-a-bug, or repro request expired (>14d).
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #320 | ynaoto | The MCP client using a tool launched with uvx does not terminate. | bug | 2 | 1 | 508d |
| #451 | pete-grunge-ai | Subclassing McpServer causes tool invocation issues | bug | 4 | 1 | 484d |
| #1317 | lokendra-ss | Auth Failure Retry Handler `_hasCompletedAuthFlow` | bug P3 | 1 | — | 257d |
| #1450 | waltmayf | OAuth Token Exchange Fails with Separate Authorization Servers | bug | 2 | 1 | 211d |
| #1585 | jonnycoder1 | server.tool() silently drops inputSchema when passed plain JSON Schema objects instead of Zod schemas | bug | 5 | 1 | 188d |
| #1639 | vz443 | Hono Package is not under @modelcontextprotocol | bug | 4 | 1 | 179d |
| #1852 | cdunda-perchwell | StreamableHTTPServerTransport destroys sessions on TCP keepalive timeout (regression in 1.25+) | bug | 2 | 1 | 150d |
| #1946 | caravin | OAuth discovery does not fall back to well-known URI when 401 carries a non-Bearer WWW-Authenticate (e.g. Negotiate) | bug | 3 | 2 | 132d |
| #2077 | scastria | client code can't execute inside browser due to import spawn | bug | 3 | 1 | 112d |
| #2143 | slowtick | @modelcontextprotocol/client 2.0.0-alpha.2 is missing peer dependency declaration for @cfworker/json-schema | bug | 3 | 1 | 103d |
| #2162 | SrjAlamy | invalid argument should throw protocol error, rather than tool execution error | bug | 2 | 1 | 97d |
| #2255 | pavlo-to | Step-up authorization (403 insufficient_scope) dead-ends with SdkHttpError when a refresh_token is present | bug | 4 | 1 | 88d |
| #2408 | carissalicatovich | OAuth token exchange crashes on gzip-compressed token response (JSON.parse on undecompressed bytes) | bug | 2 | 1 | 62d |
| #2525 | Starefossen | Bug/Feature Request: Node 26 fetch HTTP/2 SSE stream buffering hangs MCP connections | bug | — | — | 43d |
backlog (6) — Triaged bug, no status — plan into a sprint or label.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #2175 | lokendra-ss-18283 | Session Close Notification for Stateful Connections (MCP Clients) | bug P2 | 2 | — | 96d |
| #2657 | itsjamie | [v2] classifyNetworkError passes { cause } into SdkError's data slot, so the underlying network error never reaches Error.cause | bug P2 | 1 | — | 19d |
| #2661 | jstar0 | Streamable HTTP SSE tests assume multiple events share one fetch chunk | bug P3 | 1 | — | 19d |
| #2100 | daveCode-dot | Tool inputSchema generation emits $ref for reused Zod instances · breaks strict MCP clients (kimi) | bug | 3 | — | 109d |
| #2526 | Starefossen | Bug/Feature Request: Node 26 fetch HTTP/2 SSE stream buffering hangs MCP connections | bug | — | — | 43d |
| #2677 | lgrolee | tools/list emits draft-07 $schema for Zod v4 schemas: toJsonSchemaCompat is called without a target, and mapMiniTarget defaults to 'draft-7' | bug | 4 | — | 16d |
Enhancements (97)
Decisions — say yes/no, then design or implement.
in-progress (13) — Assigned — someone is on it.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #1294 | domdomegg | Server SDK support for signaling token expiry (401) from tool handlers | enhancement P1 | 3 | — | 263d |
| #558 | kentcdodds | Support the resources/subscribe method | enhancement P2 | 6 | — | 462d |
| #2189 | felixweinberger | Implement SEP-2663: Tasks Extension | enhancement P2 | 2 | — | 96d |
| #2623 | quotentiroler | oauthMetadataResponse requires a full AS metadata document to read one field from it | enhancement P2 | — | — | 25d |
| #74 | lino-levan | Publish on the JSR | enhancement P3 | 1 | — | 643d |
| #963 | ochafik | Simplify attribution of elicitation to a tool call | enhancement P3 | 2 | — | 343d |
| #1090 | felixweinberger | Implement SEP-990: Enterprise Managed Authorization (Extension) | enhancement P3 | 4 | — | 298d |
| #1264 | felixweinberger | OpenTelemetry integration out of the box | enhancement P3 | 1 | — | 267d |
| #1271 | felixweinberger | Better contribution guidelines for external contributors | enhancement P3 | 1 | — | 267d |
| #1260 | felixweinberger | Refactor Protocol.ts to eliminate client/server conditionals | enhancement P3 | — | — | 267d |
| #1262 | felixweinberger | Inject your own logger | enhancement P3 | — | — | 267d |
| #1430 | NSeydoux | Support providing client scopes to StaticPrivateKeyJwtProvider (also applicable to PrivateKeyJwtProvider) | enhancement P3 | 1 | — | 216d |
| #1734 | felixweinberger | Evaluate OIDC nonce support | enhancement P3 | — | — | 162d |
decide (65) — needs decision — say yes (→ ready/design/backlog) or no (→ close). P1 first.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #283 | psclkhoury | Support JSON schema in addition to zod | enhancement P1 | 11 | — | 512d |
| #1063 | felixweinberger | Implement SEP-1724: Extensions | enhancement P1 | 1 | — | 306d |
| #1250 | felixweinberger | Remove or clarify ProxyOAuthProvider | enhancement P1 | — | — | 267d |
| #143 | jspahrsummers | Better CORS defaults for SSE transport | enhancement P2 | 6 | — | 575d |
| #2352 | riccardorispoli | `McpServer` does not implement server-side pagination for list operations | enhancement P2 | 2 | — | 70d |
| #34 | jspahrsummers | Make it easy to send progress notifications from a request handler | enhancement P2 | 1 | — | 666d |
| #1000 | younaman | Bug Report-2: Missing Periodic Ping Implementation | enhancement P2 | 1 | — | 334d |
| #1151 | pcarleton | Server SDK support for scope challenges on tool calls | enhancement P2 | 1 | — | 284d |
| #1587 | zero1zero | Published 2.0.0-rc/alpha version to npmjs.com? | enhancement P2 | 1 | — | 188d |
| #28 | jspahrsummers | Automate sending pings from SSE servers | enhancement P2 | 1 | — | 673d |
| #6 | jspahrsummers | `Host` abstraction for multiple client → server connections in one process | enhancement P2 | 1 | — | 698d |
| #892 | katjes733 | Issue: No Reliable Mapping Between sessionId and streamId for Stateless Resumability | enhancement P2 | — | — | 377d |
| #192 | wskish | consider defaulting resetTimeoutOnProgress to True | enhancement P2 | — | — | 537d |
| #1238 | ahammednibras8 | Feature Request: Middleware support for McpServer | enhancement P3 | 14 | — | 271d |
| #836 | danielsinai | Dynamic Tool Registration Based on Authentication Context | enhancement P3 | 8 | — | 394d |
| #1124 | nazoking | Support Secure Hashed Client Secrets in OAuthRegisteredClientsStore | enhancement P3 | 5 | — | 289d |
| #153 | mikesir87 | Expected manner to capture error details during startup | enhancement P3 | 5 | — | 561d |
| #1160 | clemmy | Call schema on inputSchema validation failure | enhancement P3 | 4 | — | 281d |
| #956 | jordan-burnett | Ability to pass custom context to tool handlers | enhancement P3 | 4 | — | 346d |
| #1046 | felixweinberger | Zod types via `infer` make TypeScript types a lot less readable | enhancement P3 | 4 | — | 309d |
| #688 | dudo | Resource Templates: Support for display names vs values in completion and better handling of special characters in URI paths | enhancement P3 | 3 | — | 435d |
| #927 | kentcdodds | Use types for tool annotations to reduce confusion | enhancement P3 | 2 | — | 358d |
| #1924 | klodr | Optional install of HTTP/SSE transport deps (express, hono) for stdio-only servers | enhancement P3 | 2 | — | 137d |
| #2298 | paztis | creation of a tool without any server instance knowledge | enhancement P3 | 2 | — | 78d |
| #1928 | mddaud | McpServer: add tool lifecycle hooks (beforeToolCall, afterToolCall) | enhancement P3 | 2 | — | 136d |
| #703 | KKonstantinov | Prompts - Metadata attributes in prompt registration, similar to resource metadata or tool annotations | enhancement P3 | 2 | — | 432d |
| #1039 | dmcwherter | Support upscoping on insufficient_scope 403 like in Python SDK | enhancement P3 | 2 | 1 | 313d |
| #1757 | tizmagik | Add hook or middleware for transforming tools/list responses | enhancement P3 | 2 | — | 160d |
| #2032 | jirispilka | Feature request: allow customizing `taskId` in `InMemoryTaskStore` | enhancement P3 | 1 | — | 116d |
| #2090 | RomKadria | Stateless mode: per-request McpServer+Protocol allocation causes memory leak at scale | enhancement P3 | 1 | — | 110d |
| #1882 | technicallychudi | Public API for multi-node session rehydration (e.g. transport.adoptSession(id)) | enhancement P3 | 1 | — | 143d |
| #88 | jspahrsummers | Increase default child process `maxBuffer`, and make configurable | enhancement P3 | 1 | — | 632d |
| #208 | jrieken | Add ways for server processes to self-terminate when host is gone | enhancement P3 | 1 | — | 531d |
| #577 | Rajesh-Narayanappa87 | Auth : Allow user provided routes to escape Auth middleware | enhancement P3 | 1 | — | 459d |
| #676 | alonhar | OAuth Request Should Accept client_id and client_secret via Headers, Not Just in the Request Body | enhancement P3 | 1 | — | 438d |
| #830 | jkorach | Need to handle GET and POST differently in OAuthServerProvider.authorize handler | enhancement P3 | 1 | — | 397d |
| #886 | weihaoxia-01 | Request guidance/feature to stream streaming tool responses back | enhancement P3 | 1 | — | 378d |
| #932 | yadav-prakhar | Elicitation with custom input [ SEP-1456 ] | enhancement P3 | 1 | — | 356d |
| #1036 | localconst | Simplify public access to McpServer registered tools | enhancement P3 | 1 | — | 315d |
| #1253 | felixweinberger | Type-first as opposed to Zod schema-first approach | enhancement P3 | 1 | — | 267d |
| #1268 | felixweinberger | MSW (Mock Service Worker) integration | enhancement P3 | 1 | — | 267d |
| #1361 | domdomegg | Consider type coercion for tool arguments | enhancement P3 | 1 | — | 238d |
| #1877 | yokonao | `createMcpHonoApp` should support generics for Env (Bindings and Variables) | enhancement P3 | 1 | — | 143d |
| #1883 | DrDexter6000 | Feature: add idle timeout to SSE stream reader in StreamableHTTPClientTransport | enhancement P3 | 1 | — | 142d |
| #370 | logan272 | Allow Custom Client Features for MCP Tools | enhancement P3 | 1 | — | 500d |
| #2020 | icopp | TaskStore interface should pass through authInfo and signal | enhancement P3 | — | — | 119d |
| #2025 | edge-ignacio-rojas | Proposal: Move examples to a separate repository to avoid dependency-related vulnerabilities | enhancement P3 | — | — | 118d |
| #2029 | icopp | Completables should pass through authInfo and signal | enhancement P3 | — | — | 117d |
| #2208 | bryant-eastham | One line change to enable fallback authentication | enhancement P3 | — | — | 95d |
| #1941 | misterwigglesworth | deps: include hono@4.12.14 in the next dependabot bump (GHSA-458j-xx4x-4375) | enhancement P3 | — | — | 133d |
| #741 | nataliapc | Feature: Retrieve info about registered Resources and execute them from a tool | enhancement P3 | — | — | 422d |
| #1059 | felixweinberger | Implement SEP-1649: MCP Server Cards (.well-known Discovery) | enhancement P3 | — | — | 306d |
| #1259 | felixweinberger | Class names - align with Python SDK (server, session, etc.) | enhancement P3 | — | — | 267d |
| #1263 | felixweinberger | Add custom onError config points for McpError handling | enhancement P3 | — | — | 267d |
| #1265 | felixweinberger | Clear abstracted way to define experimental features | enhancement P3 | — | — | 267d |
| #1316 | BestOwl | Support RFC 8252 dynamic loopback port selection for native OAuth clients | enhancement P3 | — | — | 257d |
| #1474 | mattzcarey | Completers as a first class option in Prompts | enhancement P3 | — | — | 210d |
| #1537 | josefaidt | consider consolidation of tooling, revise ts setup | enhancement P3 | — | — | 199d |
| #1847 | felixweinberger | Convert tool/prompt schemas eagerly at register time instead of on tools/list | enhancement P3 | — | — | 152d |
| #1860 | earonesty | mcpAuthRouter construction-time env is incompatible with request-scoped runtimes (Cloudflare Workers, Supabase Edge, etc.) | enhancement P3 | — | — | 147d |
| #1863 | haydenrear | Add MCP_TOOL_TIMEOUT_MSEC default value only for tool calls. | enhancement P3 | — | — | 146d |
| #1892 | MMoMM-org | Client transport: HTTP 429 responses are not retried with Retry-After | enhancement P3 | — | — | 139d |
| #387 | flippinjoe | Allow receiving messages per stream in client sdk | enhancement P3 | — | — | 496d |
| #674 | fxBrBowman | Please add the ability to supply the the registerClient and defaultScopes to the ProxyOAuthServerProvider | enhancement P3 | — | — | 438d |
| #10 | jspahrsummers | Add conveniences for MCP proxy pattern | enhancement P3 | — | — | 690d |
design (6) — needs design — approved direction, scope it before implementing.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #2505 | cliffhall | v2: setRequestHandler/setNotificationHandler require a method-string literal — re-accept the schema object (or export typed method tokens) | enhancement | — | — | 48d |
| #2569 | suavecito585 | subscriptions/listen cannot carry extension notifications (blocks notifications/tasks) | enhancement | 1 | — | 36d |
| #2628 | Ahmad-Faraj | Low-level Server API publishes inputSchema in tools/list but does not enforce it on tools/call | enhancement | 1 | — | 23d |
| #2656 | hadaromash | tools/call has no path to a protocol-level "Server errors" response, even for unhandled exceptions | enhancement | 1 | — | 20d |
| #2659 | itsjamie | [v2] StreamableHTTPClientTransport drops SSE stream provenance, so a server-initiated request cannot be attributed to the client request that provoked it | enhancement | — | — | 19d |
| #2685 | andreolf | Proposal: warn when a network-facing MCP server starts without authentication | enhancement | — | — | 15d |
ready (2) — ready for work — PR welcome.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #2036 | irparent | Bump hono and fast-uri to versions covering published GHSA advisories | enhancement P2 | 4 | — | 116d |
| #2576 | coding-bobo | Implement SEP-1933: Workload Identity Federation (Extension) | enhancement P2 | — | — | 34d |
close-candidates (5) — Bot flagged duplicate/out-of-scope, or confirmation expired.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #19 | jspahrsummers | Automatically create a new server from a template | enhancement P3 | — | — | 686d |
| #682 | ruturaj-browserstack | Dynamic MCP Tool Registration Not Available Mid-Chain or Same Cycle | enhancement P3 | 3 | 1 | 436d |
| #690 | dudo | Resource completion performance: Consider client-side caching and fuzzy filtering | enhancement P3 | 2 | — | 435d |
| #794 | ho3einmolavi | disconnect method for MCP client | enhancement P3 | 2 | — | 408d |
| #2250 | mohdgufran07 | MCP tool calls timeout after 60 seconds for long-running requests | enhancement | 2 | 1 | 91d |
backlog (6) — Acknowledged, not prioritized — explicit backlog label or no status yet.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #1231 | bhaveshpatel640 | Undici instrumentation marks successful MCP requests as aborted due to premature AbortController.abort() in SSE / StreamableHTTP transports | enhancement P2 | 8 | 1 | 272d |
| #2627 | giacomomaria81 | Docs: passing z.object() as inputSchema on v1 fails silently (empty schema) or cryptically (tools/list crash) — not covered in troubleshooting or migration guide | enhancement P3 | 4 | — | 23d |
| #740 | username7171 | Can we have a chatbot example that connected to multiple remote servers | enhancement P3 | 4 | — | 422d |
| #658 | ochafik | update server examples to cover external authentication servers | enhancement P3 | 1 | — | 440d |
| #2637 | AndresSaa | [v2] Tasks extension: tools/call rejects CreateTaskResult but accepts an omitted discriminator as complete | enhancement | — | — | 22d |
| #2507 | khandrew1 | Add a high-level MCP operation interceptor seam | enhancement | — | — | 47d |
Questions (6)
Inbox — answer, then close or convert to bug/enhancement.
answer (6) — No maintainer response yet, or reporter followed up.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #1126 | splincode | What is the recommended way of writing unit tests for MCP endpoints? | question P3 | 2 | 1 | 288d |
| #1132 | enesgules | Question: Tool list changed notification | question P3 | 5 | 1 | 288d |
| #1512 | mattzcarey | [TRACKING] non compliance with SEP-986 / tool name validation | question P2 | 6 | 1 | 204d |
| #2101 | joaquinmagneres-asana | Is there a way to pass request-scoped context to tool handlers via HTTP headers without modifying the tool schema? | question | 1 | 1 | 109d |
| #2636 | FelixBaum | zod v4: "additionalProperties: false" missing | question | 2 | — | 22d |
| #2639 | jss79 | [v2] No supported way to emit Mcp-Param-* headers on a legacy-era connection, but GitHub's hosted server requires them there | question | — | — | 22d |
Stats — volume, response time, staleness, labels
Volume
Response Time
Time to first maintainer response
Stale Issues
Issues with no activity
Issues by Label
| Label | Count |
|---|---|
| bug | 93 |
| v2 | 92 |
| P2 | 88 |
| enhancement | 73 |
| ready for work | 57 |
| P3 | 45 |
| needs decision | 43 |
| v1 | 38 |
| P1 | 37 |
| auth | 33 |
| needs confirmation | 25 |
| fix proposed | 15 |
| improves spec compliance | 8 |
| spec-2026-07-28 | 7 |
| documentation | 6 |
| good first issue | 6 |
| needs repro | 4 |
| breaking change | 3 |
| pending SEP approval | 3 |
| improves sdk consistency | 2 |
| potentially close | 2 |
| question | 2 |
| help wanted | 1 |
Untriaged (36)
No type label — bot pending or needs manual triage.
untriaged (36) — Bot has not labeled yet, or needs manual type assignment.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #1318 | Norcim133 | Critical Token Refresh Bugs - Prevents Proactive Refresh | P1 | 9 | — | 370d |
| #1450 | certainly-param | Response leak in SSE handlers | P2 | 3 | — | 328d |
| #1602 | maxisbey | OAuth: 403 responses without insufficient_scope incorrectly retry with same token | P3 | — | — | 295d |
| #2021 | maxisbey | Refactor handler context to be transport- and handler-type-aware | P1 | 1 | — | 204d |
| #2278 | maxisbey | Mark SSE transport as deprecated | P3 | 1 | — | 174d |
| #3209 | stayclosetothequestion | Bug: OAuth provider holds context.lock for the whole request, so the standalone GET SSE stream stalls the first tools/call by ~15s | P2 | 1 | — | 34d |
| #3226 | Silousr | Client-side support for the tasks extension (io.modelcontextprotocol/tasks, SEP-2663) | P2 | 3 | — | 33d |
| #3235 | morluto | Parameterized Context loses request state in resource and prompt handlers | P1 | 2 | — | 31d |
| #3238 | ProgrammerPlus1998 | Expose create_mcp_http_client and McpHttpClientFactory as public API (2.0 made them private-only) | P1 | 4 | — | 30d |
| #3240 | mfadul24 | OAuth token refresh hits the wrong endpoint when the auth server lives under a path | P1 | 2 | — | 29d |
| #3250 | draesthetic | OAuthClientProvider._initialize() breaks transparent refresh: missing update_token_expiry + missing oauth_metadata load | P1 | — | — | 28d |
| #3254 | squibloads | [v2] MCPServer reports empty experimental capabilities as {} via initialize but None via server/discover | P2 | 1 | — | 28d |
| #3257 | luiz00martins | `handle_get_stream` reconnects indefinitely when the server ends the GET stream normally (`attempt = 0` defeats `MAX_RECONNECTION_ATTEMPTS`) | P2 | 1 | — | 27d |
| #3269 | quotentiroler | Mcp-Name accepts an orphan header, while Mcp-Param-* rejects it as a routing spoof | P3 | 1 | — | 25d |
| #3287 | HaoChiBao | docs: clarify when Client(raise_exceptions=True) actually raises | P3 | 1 | — | 21d |
| #3297 | otiscuilei | resource_url_from_server_url preserves explicit default ports | P3 | 1 | — | 20d |
| #3298 | otiscuilei | find_context_parameter treats a Context return annotation as a parameter | P3 | 3 | — | 20d |
| #3309 | haiiibin | docs: no guidance for supporting SDK 1.x and 2.x at the same time | 6 | — | 18d | |
| #3330 | aartaria | streamable-http client: no size bound before JSONRPCMessage.model_validate_json — one large server message can OOM the client | 1 | — | 15d | |
| #3332 | Zhangs-11 | [v2] Expose the SSE max_event_size setting in Streamable HTTP clients | — | — | 14d | |
| #3333 | okapies | Add add_resource_template() to MCPServer | — | — | 14d | |
| #3335 | AbarnaaSree | Windows MCP SSH stdio transport closes after initialize when PROGRAMDATA is missing from inherited environment | 1 | — | 14d | |
| #3342 | rookie-z | Prompt validation errors are logged with an unnecessary traceback | 2 | — | 13d | |
| #3341 | jayhemnani9910 | A tool returning a non-finite float fails on the client with an error naming the tool | 2 | — | 13d | |
| #3345 | epistemedeus | Client treats JSON-null structuredContent as missing, skipping outputSchema validation | 2 | — | 12d | |
| #3351 | allableaidev | Server.call_tool()'s input-validation error result discards jsonschema.ValidationError's structured fields, leaving only free-text prose | 1 | — | 12d | |
| #3356 | AAH20 | bug(client/streamable_http): prevent infinite SSE reconnect loops with bounded exponential backoff | 1 | — | 11d | |
| #3357 | owlofjaylan | [v2] Allow MCPServer to disable subscriptions/listen | 3 | — | 11d | |
| #3358 | trickyfalcon | Client SSRF / protocol confusion: streamable HTTP transport follows server 3xx into internal+loopback services (follow_redirects=True, no host validation; #2106 closed but fix #2180 never merged) | 2 | — | 11d | |
| #3373 | jtauschl | pyjwt[crypto] as an unconditional dependency blocks installation on platforms without a cryptography wheel (e.g. Windows on ARM) | 3 | — | 8d | |
| #3382 | flanker-stack | OAuthClientProvider auth lock is permanently poisoned when httpx closes async_auth_flow from a different task (RuntimeError: The current task is not holding this lock) | 3 | — | 8d | |
| #3384 | jayhemnani9910 | ClientSessionGroup raises KeyError when a server exposes no tools, resources or prompts | 2 | — | 8d | |
| #3385 | jayhemnani9910 | A tool returning a non-finite float puts invalid JSON in the text content block | 1 | — | 8d | |
| #3389 | morluto | [v2] Expose request cancellation on MCPServer tool Context | 1 | — | 7d | |
| #3391 | wromansky | Tool input schemas carry a pydantic-derived title on every property | — | — | 7d | |
| #3408 | iam-kira | test_safe_join_rejects_symlink_escape fails on Windows without elevation or Developer Mode | 3 | — | 4d |
Bugs (93)
Queue — pick the top fix-ready and work it. Priority then age.
fix-proposed (15) — Bot posted a suggested fix — review the diff. P0/P1 first.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #915 | hzeus | Exception in `ClientSessionGroup` if `streamable_http` MCP server is not available | bug P1 | 12 | 1 | 448d |
| #1257 | 0x-Professor | Don’t use shell=True in mcp dev subprocess on Windows (command injection risk) | bug P1 | 3 | 1 | 388d |
| #2416 | bbarwik | Bug: AssertionError: Request already responded to — cancellation race in v1.27.0 | bug P2 | 13 | 1 | 145d |
| #2429 | kimsehwan96 | [v1.x] Server-side outputSchema validation blocks tool error reporting (isError: true) | bug P2 | 2 | 1 | 142d |
| #2431 | rain87 | McpError is not pickle-safe and fails to unpickle | bug P2 | 9 | 1 | 142d |
| #2432 | HenriChabert | Initialize call hangs forever if MCP server does not return a `Content-Type: text/plain` | bug P2 | 3 | 1 | 142d |
| #2433 | DonovanDeHart | Windows: TextIOWrapper in stdio_server() emits CRLF instead of LF, corrupting newline-delimited JSON messages | bug P2 | 8 | 1 | 141d |
| #2454 | shaun0927 | stdio_client crashes on malformed UTF-8 from child stdout instead of surfacing parse error | bug P2 | 3 | 1 | 138d |
| #2578 | ShaneFlag | OAuth token refresh sends RFC 8707 resource parameter that Entra ID v2.0 rejects (AADSTS9010010) | bug P2 | 6 | 1 | 113d |
| #2605 | cclabadmin | Duplicate `initialize` with changed parameters can overwrite `ServerSession.client_params` | bug P2 | 4 | 1 | 109d |
| #2629 | CrypticCortex | DCR registration accepts redirect_uris with non-HTTPS / non-loopback / fragmented schemes | bug P2 | 1 | 1 | 106d |
| #2655 | dexteradeus | Streamable HTTP server silently drops in-flight request when client reuses a JSON-RPC id | bug P2 | 3 | 1 | 103d |
| #2687 | ptrhrsch-arch | `OAuthClientInformationFull.redirect_uris`: pydantic strict-type-equality breaks `AnyUrl(x) != AnyHttpUrl(x)` round-trip | bug P2 | 3 | 1 | 98d |
| #2689 | mr-brobot | `ClientSessionGroup` attempts to use capabilities that were not advertised | bug P2 | 3 | 1 | 98d |
| #2663 | MikeNjoroge | FastMCP.run(transport="stdio") produces noisy traceback on KeyboardInterrupt instead of clean exit | bug P3 | 3 | 1 | 102d |
ready-for-work (34) — Triaged and reproducible — pick one up. P0/P1 first.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #262 | herrrX | cannot get response from await session.call_tool() | bug P1 | 16 | — | 539d |
| #577 | HMJiangGatech | `RuntimeError: Attempted to exit cancel scope in a different task` when cleaning up multiple MCPClient instances out-of-order | bug P1 | 11 | — | 496d |
| #795 | lizzzcai | Support for API Gateway Path Prefixes in SSE Client URL Handling | bug P1 | 2 | — | 466d |
| #883 | toughnoah | AssertionError: Unexpected message while using middlewares | bug P1 | 15 | — | 455d |
| #1250 | pematth | Framework does not handle refreshed tokens correctly | bug P1 | 12 | — | 390d |
| #1265 | FakeDocument | Trailing slash in `.well-known/oauth-protected-resource` response may violate “Canonical Server URI” requirement | bug P1 | 2 | — | 385d |
| #1272 | lindycoder | Server hangs when shutting down if a connection is still open | bug P1 | 2 | — | 383d |
| #1401 | Unshure | ClientSession Error Handling | bug P1 | 18 | — | 341d |
| #1675 | AydarDD | Streamable HTTP transport drops requests immediately after `initialize` | bug P1 | 1 | — | 279d |
| #1811 | ivanbelenky | client's `read_stream_writer` open after SSE disconnection hanging `.receive()` | bug P1 | 3 | — | 255d |
| #1919 | joar | Trailing slash in OAuthMetadata's `issuer` causes issues with clients | bug P1 | 4 | — | 224d |
| #423 | folkvir | MCP SSE Server: Received request before initialization was complete | bug P2 | 25 | — | 516d |
| #1060 | paxan | PydanticSchemaGenerationError: Unable to generate pydantic-core schema for Image type | bug P2 | 4 | — | 428d |
| #1264 | carlosemart | Protected Resource Metadata resource erroneous when setting up authentication on server | bug P2 | 6 | — | 385d |
| #1269 | chipkent | FastMCP server death on client HEAD calls | bug P2 | 6 | — | 384d |
| #1274 | rcxwhiz | Streamable HTTP client performance regression starting with v1.12.0 | bug P2 | 2 | — | 383d |
| #1295 | somaraani | 401 in Streamable HTTP should be handled gracefully | bug P2 | 1 | — | 375d |
| #1326 | Norcim133 | Clients Using Storage Face Deadlock on Token Refresh for SSE | bug P2 | 4 | — | 367d |
| #1333 | peteski22 | `stdio_server` uses unbuffered memory streams which can cause server to block and become unresponsive | bug P2 | 1 | — | 365d |
| #1405 | 0Delta | It is not possible to define a Resource that takes only the Context parameter as an argument. | bug P2 | 2 | — | 340d |
| #1523 | cfytrok | OAuthClientProvider._handle_token_response expect json | bug P2 | — | — | 308d |
| #1577 | gyang-xai | Client tool call hangs forever if server crashes or connection dies when using streamable-http | bug P2 | 3 | — | 301d |
| #1648 | FanisPapakonstantinou | ClientDisconnect returns HTTP 500 | bug P2 | 5 | — | 285d |
| #1656 | pfaion | FastMCP configures logging on init, which messes up application-level logging | bug P2 | 7 | — | 282d |
| #1664 | LucaButBoring | User-Agent header in sHTTP transport is not forwarded to auth flow | bug P2 | 3 | — | 281d |
| #1676 | david-nominal | MCP client doesn't not initialize new session when getting 404 session not found | bug P2 | 4 | — | 279d |
| #1873 | TommyVee | Bug: String parameters starting with digits coerced to numbers, causing UUID data loss | bug P2 | 4 | — | 229d |
| #2150 | emmahoggan | Active Streamable HTTP sessions are not terminated during shutdown | bug P2 | 3 | — | 187d |
| #2216 | nik1097 | Bug: validate_scope rejects client scopes when required scopes in None | bug P2 | 5 | — | 180d |
| #2678 | theone139344 | FastMCP/stdio: in-flight tool responses dropped on stdin EOF when input is bash-redirected from a file | bug P2 | 6 | 1 | 99d |
| #156 | grll | support logging to stderr in Jupyter Notebook Environments. | bug P3 | 12 | — | 593d |
| #514 | growler | FastMCP server with SSE transport fails to shut down on a signal | bug P3 | 11 | — | 505d |
| #1141 | abhishekgahlot2 | Progress notifications cause server to hang on stdio transport | bug P3 | 4 | — | 414d |
| #1307 | jennsun | Error & Mismatch in OAuth scope resolution between Claude.ai/MCP Python SDK and Inspector | bug | 1 | — | 372d |
needs-maintainer (4) — Reporter replied, or bot/triage flagged for maintainer judgment.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #2057 | clouatre | Requests with "id": null silently misclassified as notifications | bug P2 | 10 | — | 200d |
| #2376 | Kunyu-Chen | Image/ImageContent serialization fails in stateless HTTP mode | bug P2 | 3 | — | 156d |
| #2702 | hognek | FastMCP: streamable_http_app() silently breaks when BaseHTTPMiddleware is added | bug P3 | 5 | 1 | 97d |
| #1103 | kdheeraz | MCP client not able to initiate StdioServerParameters while running in Jupyter Notebook | bug | 6 | — | 421d |
close-candidates (21) — Bot says already-fixed/not-a-bug, or repro request expired (>14d).
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #1805 | h-filzer | Possible ressource leak / race condition in streamable_http_client | bug | 10 | — | 256d |
| #1842 | aiwebb | ClientAuthenticator ignores token_endpoint_auth_method="none" when client_secret is stored | bug P2 | 6 | — | 236d |
| #2610 | mlorentedev | RequestResponder.__exit__ leaks CancelledError on cancelled request, killing the stdio receive loop | bug P2 | 3 | 1 | 109d |
| #2653 | colinlabrooy | mcp.server.fastmcp.FastMCP HTTP transport deadlocks after ~5 sequential client sessions on Windows (companion to PrefectHQ/fastmcp#4192) | bug | 3 | 1 | 104d |
| #2741 | SingingOwl | Stateful Streamable HTTP: in-session exceptions are masked as an empty -32603; real cause only in a separate "Session crashed" log | bug P2 | 2 | — | 93d |
| #2751 | cclabadmin | Deep JSON-RPC request over stdio logs a validation error and leaves the original request pending | bug P2 | 1 | — | 92d |
| #2847 | EnGassa | Bug: anyio.Lock in async_auth_flow causes RuntimeError under concurrent OAuth MCP connections | bug P1 | 4 | — | 82d |
| #2848 | cclabadmin | Invalid JSON-RPC envelope errors are not correlated with the original request id | bug P2 | 1 | — | 81d |
| #2958 | simpson1045 | StreamableHTTP server accumulates CLOSE_WAIT sockets behind reverse proxy due to missing disconnect cleanup | bug P2 | 1 | — | 70d |
| #2965 | Robin1987China | [Bug] check_capability does not validate elicitation sub-capabilities (form/url) | bug P2 | 2 | — | 68d |
| #3065 | mayankbohradev | [v2] RFC 9728 PRM URLs and resource matching drop query components | bug P2 | 1 | — | 58d |
| #3099 | destire-mio | Field alias is published in the tool schema but forwarded as an invalid Python keyword | bug P2 | 7 | — | 48d |
| #3100 | destire-mio | Generated output schema uses Pydantic's validation shape while structured output uses its serialization shape | bug P2 | 2 | — | 48d |
| #3102 | fgranata | Streamable HTTP server never returns the spec-mandated 405 for GET requests it won't serve as SSE (406/400 instead) — breaks client SSE-probe fallback | bug P2 | 5 | — | 48d |
| #3103 | velias | RequireAuthMiddleware omits RFC 6750 scope in WWW-Authenticate on 401/403 | bug P2 | 2 | — | 47d |
| #3126 | ayaangazali | Dispatcher mints a request id already used by a completed caller-supplied request (spec: ids MUST NOT be reused in a session) | bug P2 | 1 | — | 46d |
| #3138 | benmiller-SC | OAuth client sends client_id in token body under client_secret_basic (strict servers reject as multiple auth methods) | bug P1 | 6 | — | 43d |
| #3154 | dchou1618 | Fix Streamable HTTP Accept header quality-factor handling | bug P3 | 1 | — | 40d |
| #3174 | HarperZ9 | [v2] JSON-RPC error responses leave client OpenTelemetry spans UNSET | bug P2 | 9 | — | 38d |
| #3303 | Choppaaahh | check_resource_allowed(): path matching skips dot-segment/percent-encoding normalization (auth-boundary bypass) | bug P2 | 4 | — | 20d |
| #3307 | jstar0 | Streamable HTTP clean EOF reconnects can exceed the request retry budget | bug P2 | 5 | — | 19d |
waiting (1) — Reporter owes repro/confirmation, or a PR is in flight, or blocked.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #1332 | dsp-ant | Implement consistent structuredContent handling per specification clarification | bug P3 | 1 | — | 365d |
backlog (18) — Triaged bug, no status — plan into a sprint or label.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #2110 | maxisbey | HTTP transport swallows non-2xx status codes causing client to hang | bug P1 | 7 | — | 194d |
| #2114 | maxisbey | ExceptionGroup wrapping obscures real errors from task groups | bug P1 | 3 | — | 194d |
| #3256 | carrotRakko | OAuth client can never recover from an expired DCR client secret — even though the SDK's own server issues and enforces one | bug P1 | 1 | — | 28d |
| #2393 | jeffplourde | StreamableHTTP client: _handle_reconnection resets attempt counter to 0, causing infinite retry loop | bug P2 | 2 | — | 150d |
| #2474 | itomise | Return 405 on GET when stateless_http=True | bug P2 | 4 | — | 136d |
| #2473 | 0717376 | MCPServer unconditionally declares `prompts`, `resources`, `tools` capabilities on `initialize` | bug P2 | — | — | 136d |
| #2776 | artdent | OAuth handler doesn't support redirect URLs with params | bug P2 | 2 | — | 90d |
| #2826 | nikodemas | `simple-auth` is not working as expected | bug P2 | — | — | 84d |
| #3009 | VihaanAgarwal | WWW-Authenticate parsing matches a field name as a substring of another auth-param | bug P2 | 2 | — | 66d |
| #3055 | vientooscuro | FuncMetadata.pre_parse_json mis-detects str | None as non-string and corrupts JSON-looking string arguments | bug P2 | 2 | — | 61d |
| #3060 | scottmsilver | streamable HTTP (stateful): concurrent requests with duplicate JSON-RPC ids cross-wire responses — one request receives another's payload, the other hangs | bug P2 | 5 | — | 60d |
| #3281 | pvarshh | streamable_http (legacy mode): early response.aclose() discards a TCP connection per JSON-RPC exchange — deterministic reproduction for #2707 | bug P2 | 1 | — | 22d |
| #1795 | maxisbey | Make JSON-RPC ID type coercion configurable | bug P3 | 2 | — | 258d |
| #1933 | hyn0027 | Using transport="stdio" closes real stdio, causing ValueError after server exits | bug P3 | 8 | — | 222d |
| #1974 | mjahr | find_context_parameter() fails to detect Context parameter in callable class instances | bug P3 | 1 | — | 215d |
| #2564 | blackwell-systems | raise without from discards exception chain in 12 remaining sites | bug P3 | 3 | — | 116d |
| #2935 | zlucas03 | dict[str, T] tool return types lose Annotated/Field metadata in output schema | bug P3 | 2 | — | 73d |
| #3146 | maxisbey | Deeply-nested-body test fails on macOS: rejected as INVALID_REQUEST (-32600) instead of PARSE_ERROR (-32700) | bug P3 | — | — | 41d |
Enhancements (72)
Decisions — say yes/no, then design or implement.
in-progress (9) — Assigned — someone is on it.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #1240 | yannj-fr | Implement OAuth relying on Authlib | enhancement P1 | 7 | — | 392d |
| #1253 | Kludex | Python SDK v2 | enhancement P1 | 2 | — | 389d |
| #1701 | dgenio | Define and document the public Python SDK API surface | enhancement P1 | 4 | — | 277d |
| #1739 | maxisbey | Support clean server shutdown | enhancement P1 | 1 | — | 270d |
| #2896 | maxisbey | Capabilities API + server/discover handler | enhancement P2 | — | — | 76d |
| #348 | ezyang | No way to set isError=True for arbitrary tool result content | enhancement P3 | 6 | — | 528d |
| #1315 | Mars9934 | OAuth TokenHandler should check Authorization header for client credentials | enhancement | 6 | — | 370d |
| #2121 | martimfasantos | Allow `OAuthClientProvider` to accept a pre-configured auth server URL | enhancement | — | — | 192d |
| #2141 | enkidulan | Add wildcard pattern support for `allowed_hosts` in transport security | enhancement | 1 | — | 189d |
decide (41) — needs decision — say yes (→ ready/design/backlog) or no (→ close). P1 first.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #420 | carlosemart | Option to not rewrite the logging configuration | enhancement P1 | 11 | — | 516d |
| #1429 | maxisbey | feat: enhance dynamic tool management with notifications and enable/disable | enhancement P1 | 4 | — | 330d |
| #1233 | dsp-ant | Middleware Support in MCP | enhancement P1 | 3 | — | 394d |
| #299 | john0312 | Low-level Server support for mcp dev and mcp run command | enhancement P1 | 2 | — | 534d |
| #12 | jspahrsummers | Add conveniences for MCP proxy pattern | enhancement P1 | — | — | 690d |
| #226 | salman1993 | Improving how function docstring gets converted to tool's jsonschema for FastMCP | enhancement P2 | 13 | — | 557d |
| #1335 | whitewg77 | Using /.well-known/ OAuth endpoints behind custom path on GKE | enhancement P2 | 4 | — | 364d |
| #1374 | ochafik | No default timeout for requests (unlike TS SDK) | enhancement P2 | 4 | — | 349d |
| #1801 | maxisbey | Implement server-side support for Client ID Metadata Documents (CIMD) | enhancement P2 | 3 | — | 257d |
| #2384 | felixweinberger | Inline $ref in tool inputSchema for LLM consumption (parity with typescript-sdk) | enhancement P2 | 2 | — | 152d |
| #2354 | maxisbey | Design: future of `dependencies` parameter on MCPServer | enhancement P2 | 2 | — | 159d |
| #1671 | maxisbey | ServerSession methods (create_message, elicit_form) don't expose progress_callback parameter | enhancement P2 | 2 | — | 280d |
| #1126 | chrisagrams | Specifying capabilities w/ FastMCP Server | enhancement P2 | 2 | — | 417d |
| #1281 | FallenDeity | Modular system to define MCP Primitives | enhancement P2 | 2 | — | 379d |
| #1723 | erwang01 | `auth` specification in `ClientSessionGroup` | enhancement P2 | 2 | — | 271d |
| #3305 | hchittanuru3 | A tool returning an empty list produces a CallToolResult with zero content blocks | enhancement P2 | 1 | — | 19d |
| #3067 | ramonahl | FastMCP tool argument models silently ignore unknown/misspelled arguments (extra=ignore default) | enhancement P2 | 1 | — | 58d |
| #2317 | artdent | Don't override client_metadata.scopes if they are already set | enhancement P2 | 1 | — | 166d |
| #2233 | sergeykad | pywin32 installation fails on Windows — hard dep only needed for client stdio, but pulled in for all users via eager import in __init__.py | enhancement P2 | 1 | — | 179d |
| #1821 | maxisbey | Clarify JSON-RPC error code for 'session not found' responses | enhancement P2 | — | — | 244d |
| #1393 | caffeinism | Lazy HTTP connections seem to make error handling difficult. | enhancement P2 | — | — | 343d |
| #235 | yu-iskw | Official Adapter Functions for LLM Providers in MCP Python SDK | enhancement P3 | 8 | — | 552d |
| #193 | mconflitti-pbc | Add default /docs route to list information about the HTTP MCP server | enhancement P3 | 5 | — | 571d |
| #2673 | danielgshea | ClientSession receive loop swallows callback exceptions, replying "Invalid request parameters" to the server instead of propagating to the call_tool awaiter | enhancement P3 | 4 | — | 101d |
| #2486 | leiserfg | Split the core from the server and client implementations | enhancement P3 | 4 | — | 134d |
| #2331 | rgoldstein1989 | Add remove_prompt() and remove_resource() for parity with remove_tool() | enhancement P3 | 4 | — | 163d |
| #2422 | DevonFulcher | Specific ToolNotFoundError for easier handling than ToolError in multi-tenant environments | enhancement P3 | 4 | — | 144d |
| #3145 | steditt | Add `ClientSession.register_tool_schema()` for dynamic tool discovery patterns | enhancement P3 | 3 | — | 42d |
| #3089 | scotthibbs | Heavy sync init work (e.g. local ML models) starves stdio initialize/tool calls even with threadpool offload -- Windows GIL contention | enhancement P3 | 3 | — | 51d |
| #2379 | dgenio | ClientSession: add public API for updating callbacks after initialization | enhancement P3 | 3 | — | 155d |
| #2727 | fede-kamel | streamable_http client does not send `Origin` header → rejected with 403 by spec-compliant servers (e.g. go-sdk `CrossOriginProtection`) | enhancement P3 | 3 | — | 95d |
| #2626 | germanbecker | Add option to skip output validation for mcp client | enhancement P3 | 3 | — | 107d |
| #762 | surister | Allow installing mcp servers from pypi | enhancement P3 | 3 | — | 469d |
| #817 | huang-sh | STDIO hangs forever when the using multiprocessing in tools | enhancement P3 | 3 | — | 462d |
| #3 | dsp-ant | Specific transports could be Python package extras | enhancement P3 | 1 | — | 706d |
| #622 | bendavis78 | [Feature] De-couple Starlette from FastMCP to make it easier to implement MCP endpoints in other frameworks | enhancement P3 | 1 | — | 486d |
| #1700 | dgenio | Refactor func_metadata() into smaller components for schema & metadata generation | enhancement P3 | 1 | — | 277d |
| #1806 | sesajad | More control over stderr in stdio client | enhancement P3 | 1 | — | 256d |
| #3136 | sandole | perf: JSONRPCMessage smart union scores all four branches on every inbound message | enhancement P3 | — | — | 44d |
| #2582 | leowonglaw | Expose `schema_generator` on `FastMCP` for tool params schema generation | enhancement P3 | — | — | 112d |
| #2588 | fuyu-quant | `ClientConfig` has inconsistent naming: `message_handler` should be `message_callback` | enhancement P3 | — | — | 111d |
close-candidates (1) — Bot flagged duplicate/out-of-scope, or confirmation expired.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #1705 | dgenio | Document and provide hooks for sandboxing file and network access in MCP tools | enhancement | 28 | — | 277d |
waiting (6) — Reporter owes detail, or PR in flight, or SEP/hold.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #309 | mattzh72 | Synchronous Python Client | enhancement P2 | 8 | — | 533d |
| #881 | SoldierSacha | Client Credentials In the token Handler | enhancement P1 | 1 | — | 455d |
| #1691 | dgenio | Simplify and harden session lifecycle with an explicit state machine | enhancement P2 | 2 | — | 277d |
| #1966 | somaraani | Per-Request Transport Configuration for MCP Clients | enhancement | 2 | — | 217d |
| #2556 | CJGjr | Add `list_all_*` helpers to drain pagination | enhancement P3 | 3 | — | 117d |
| #2806 | localden | Implement SEP-2663: Tasks Extension | enhancement | 9 | — | 88d |
backlog (15) — Acknowledged, not prioritized — explicit backlog label or no status yet.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #1743 | maxisbey | Extract OAuth flow logic into reusable components for proxy use cases | enhancement P1 | 9 | — | 270d |
| #2098 | maxisbey | Expose session, auth, and transport information on handler Context | enhancement P1 | 1 | — | 194d |
| #2116 | sr07asthana | Support MCP client session resumption (sessionId reuse) in Python SDK | enhancement P2 | 2 | — | 193d |
| #1475 | maxisbey | FastMCP: Support dynamic annotation updates | enhancement P2 | 2 | — | 323d |
| #1744 | maxisbey | Improve exception tracebacks for easier debugging | enhancement P2 | 1 | — | 270d |
| #1734 | maxisbey | Audit and document the MCP server publishing experience | enhancement P2 | 1 | — | 270d |
| #1742 | maxisbey | Introduce typed error classes with metadata | enhancement P2 | 1 | — | 270d |
| #2329 | kingpanther13 | Improve log clarity for "Terminating session: None" in stateless mode | enhancement P3 | 1 | — | 163d |
| #1745 | maxisbey | Remove jsonschema dependency | enhancement P3 | 1 | — | 270d |
| #1031 | davemssavage | Enable FastMCP to filter tools, prompts, resources using a fine grained policy | enhancement | 3 | — | 433d |
| #2053 | maxisbey | Replace Field(description=...) with proper docstrings in auth models | enhancement | 1 | — | 200d |
| #2052 | maxisbey | Audit MCPServer constructor parameters | enhancement | 1 | — | 200d |
| #2202 | maxisbey | Type the MCPServer handler pipeline: tool/resource/prompt return types | enhancement | — | — | 183d |
| #2153 | maxisbey | MCPServer handlers should raise exceptions, not return error objects | enhancement | — | — | 186d |
| #1319 | localden | Support selection of authorization servers from PRM document | enhancement | — | — | 370d |
Questions (1)
Inbox — answer, then close or convert to bug/enhancement.
answer (1) — No maintainer response yet, or reporter followed up.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #3283 | saurabhlalsaxena | Authentication in High Level MCPServer | question P3 | 3 | — | 21d |
Docs (3)
Documentation issues.
docs (3) — Documentation issues — fold into a docs sprint.
| # | Author | Title | Labels | 💬 | 🤖 | Age |
|---|---|---|---|---|---|---|
| #1464 | felixweinberger | Improve docs on how to use `instructions` on `InitializeResult` | documentation P1 | 4 | — | 326d |
| #339 | exeex | [docs] How to run FastMCP with args or env vars? | documentation P2 | 3 | — | 530d |
| #3272 | fede-kamel | New example: examples/servers/admission-gate — a real approve/deny ServerMiddleware demo | documentation P3 | 3 | — | 24d |
Volume
Response Time
Time to first maintainer response
Stale Issues
Issues with no activity
Issues by Label
| Label | Count |
|---|---|
| enhancement | 76 |
| needs confirmation | 56 |
| ready for work | 46 |
| P3 | 43 |
| P2 | 38 |
| bug | 36 |
| area-auth | 28 |
| help wanted | 13 |
| documentation | 8 |
| area-tests | 6 |
| P1 | 2 |
| blocked | 2 |
| needs repro | 2 |
| question | 2 |
| area-infrastructure | 1 |
Issues Awaiting Maintainer Response
Sorted by longest wait time first
| Issue | Title | Labels | Comments | Waiting |
|---|---|---|---|---|
| #236 | Pass context from request endpoint to message handler | enhancementneeds confirmation | 2 | 511d |
| #433 | McpServerPrimitiveCollection needs transactions/updates | enhancementneeds confirmation | 0 | 471d |
| #450 | Resource-based authorization on tools | enhancementarea-auth+1 | 0 | 463d |
| #623 | Allow tools to continue running when session is closed | enhancementneeds confirmation | 1 | 414d |
| #640 | Dictionary<string, JsonElement> overload for CallToolAsync | enhancementneeds confirmation | 0 | 407d |
| #659 | AspNetCore TestHost client transport | enhancementneeds confirmation | 0 | 398d |
| #657 | Release signed binaries in nuget package | enhancementneeds confirmation | 0 | 398d |
| #681 | Not able to authenticate MCP Servers | bugarea-auth+2 | 6 | 391d |
| #720 | Passing ACR_VALUES TO Token Endpoint | enhancementneeds confirmation | 0 | 377d |
| #752 | How can a server using the SSE (Server-Sent Events) model over HTTP support additional content like images within the conversational context? | enhancementneeds confirmation | 2 | 363d |
| #788 | Passing a malformed body throws a 500 error instead of 400. Very hard to figure out what is incorrect in the request being issued by the caller | bughelp wanted+2 | 1 | 349d |
| #814 | Is there a way to run multiple stateful MCP servers? | enhancementneeds confirmation | 4 | 342d |
| #842 | OAuth Flow not working for Atlassian MCP and Github MCP | bugarea-auth+2 | 4 | 327d |
| #889 | Make EverythingServer capable of running either stdio or http | enhancementhelp wanted+3 | 0 | 320d |
| #887 | Scopes not forwarded to DCR endpoint and duplication of RedirectUris | bugarea-auth+2 | 0 | 320d |
| #917 | Support externally sourced JWT in Auth header from MCP client | enhancementarea-auth+2 | 2 | 313d |
| #1126 | Request for Sample: ASP.NET Core MCP Client with One Persisted Connection Per User Session | documentationenhancement+3 | 6 | 246d |
| #1166 | Github copilot not setting bearer token on acces to tools. | bughelp wanted+3 | 2 | 225d |
| #1172 | Support using WithStreamServerTransport for multiple in-process mcp servers | enhancementneeds confirmation+1 | 0 | 222d |
| #1287 | Add DeleteStreamsForSessionAsync to ISseEventStreamStore | enhancementready for work+1 | 2 | 197d |
| #1314 | Custom filters | enhancementready for work+1 | 0 | 194d |
| #1389 | Sample: stdio-to-HTTP bridge for AI clients that only support stdio transport | documentationenhancement+2 | 1 | 188d |
| #1446 | [Auth] OAuth proxy / DCR facade for non-DCR providers (e.g. Entra ID + Claude Code) | enhancementarea-auth+2 | 5 | 167d |
| #1470 | McpClient.CreateAsync times out behind APIM in .NET SDK while MCP Inspector/Azure AI Foundry succeed | bugready for work+1 | 0 | 158d |
| #1487 | Authorization Server & Protected Resource Metadata inspection | enhancementarea-auth+2 | 0 | 153d |
| #1494 | [Documentation request] Authentication architecture suggestions | documentationenhancement+2 | 3 | 152d |
| #1587 | OAuth token refresh fails with AADSTS9010010 | bugarea-auth+1 | 0 | 105d |
| #1602 | McpServerToolCreateOptions miss MarshalResult option. | enhancementready for work+1 | 1 | 98d |
| #1607 | MCP Apps: Add ergonomic WithAppTool helper to reduce wiring boilerplate | enhancementready for work+1 | 1 | 96d |
| #1606 | the context.RequestAborted not reliable in HandleSseRequestAsync | bugneeds confirmation+1 | 0 | 96d |
| #1612 | Can't implement a CIMD client if auth provider doesn't put "none" first in it's list of supported token auth methods | bugarea-auth+1 | 0 | 95d |
| #1636 | MCP Apps: Add [McpAppResource] attribute and resource-collection processing in WithMcpApps() | enhancementready for work+1 | 1 | 84d |
| #1690 | Optional exception summarization for server-side logging | enhancementready for work+1 | 4 | 57d |
| #1730 | Provide extensions for calling McpClientTools as tasks | enhancementready for work+1 | 2 | 39d |
| #1774 | server/discover advertises deprecated `logging` unconditionally, but logging/setLevel rejects 2026-07-28+ with MethodNotFound | bugready for work+1 | 0 | 34d |
| #1781 | Streaming HTTP MCP server integration tests | documentationhelp wanted+2 | 1 | 30d |
| #1806 | Flaky on windows-latest: OAuth metadata fetch times out in in-memory tests (same class as #1701, not covered by #1702) | bughelp wanted+3 | 3 | 23d |
| #1811 | Support the OAuth 2.0 Device Authorization Grant (RFC 8628) for headless clients | enhancementarea-auth | 0 | 21d |
| #1820 | Add a stable server-side MCP Task execution extension point | enhancementready for work+1 | 5 | 16d |
| #1830 | Interactive OAuth flow is aborted by DiscoverProbeTimeout during dual-path connect, then fails with an authorization state mismatch | bugarea-auth+1 | 1 | 12d |
| #1835 | 2.2.0: binary content blocks (ImageContentBlock, BlobResourceContents) serialize invalid base64 - client-side CallToolResult deserialization throws (regression of #1340) | (unlabeled) | 1 | 7d |
| #1836 | stdio client never closes the server's stdin, so every client dispose burns the full ShutdownTimeout (5s by default) | (unlabeled) | 0 | 7d |
| #1840 | HTTP+SSE client: POST responses are never disposed, leaking one connection per sent message | (unlabeled) | 1 | 5d |
| #1842 | MCP Server is unstable when deployed to AWS AgentCore | bug | 0 | 5d |
| #1846 | Serialization exception when invoking a tool with an array parameter | bug | 1 | 3d |
| #1848 | SDK Client: `ConnectAsync` discover→initialize fallback unreachable when `AutoDetect` transport fails with `HttpRequestException` | bug | 1 | 0d |
Volume
Response Time
Time to first maintainer response
Stale Issues
Issues with no activity
Issues by Label
| Label | Count |
|---|---|
| bug | 10 |
| enhancement | 8 |
Issues Awaiting Maintainer Response
Sorted by longest wait time first
| Issue | Title | Labels | Comments | Waiting |
|---|---|---|---|---|
| #151 | tier-check: support monorepos with multiple SDK packages | (unlabeled) | 0 | 198d |
| #182 | tier-check reports 0/30 server conformance despite all tests passing | (unlabeled) | 0 | 180d |
| #223 | Workload Identity Federation (SEP-1933) - Client Conformance | (unlabeled) | 0 | 144d |
| #226 | Add scenario option to authorization server conformance test | enhancement | 1 | 139d |
| #225 | Add JSON-based setup option to authorization server conformance test | enhancement | 0 | 139d |
| #244 | Proposal: Tasks conformance scenarios (spec 2025-11-25) | (unlabeled) | 1 | 131d |
| #258 | Add support for a stdio testing | enhancement | 2 | 125d |
| #266 | Add SEP-2575 conformance tests | (unlabeled) | 1 | 112d |
| #274 | initialize scenario test server violates specification causing client failure | bug | 0 | 110d |
| #312 | server-stateless doesn't set `mcp-method` etc. | bug | 1 | 101d |
| #315 | caching scenario should use DRAFT-2026-v1 | bug | 1 | 100d |
| #323 | SEP-2243: ServerRejectsMissingMethodHeader contradicts TypeScript SDK behavior | (unlabeled) | 7 | 95d |
| #338 | dns-rebinding-protection client never sends notifications/initialized after a successful initialize (2025-11-25 path) | (unlabeled) | 0 | 82d |
| #345 | CI does not smoke-test client CLI path; everything-client drift on elicitation-sep1034-client-defaults and sse-retry | bug | 1 | 76d |
| #370 | Authorization Server Auth: DPoP Token Binding (SEP-1932) | (unlabeled) | 0 | 68d |
| #369 | Server Auth: DPoP Proof Validation (SEP-1932) | (unlabeled) | 0 | 68d |
| #379 | Fix SEP-986(-ish) strict tool name checks: align with SHOULD semantics and 2025-11-25 spec | bug | 0 | 62d |
| #378 | Add conformance test (2025-06-18+): servers MUST reject JSON-RPC batch requests | bug | 0 | 62d |
| #424 | wire-schema validation rejects SEP-2663 task envelopes - no resultType "task" branch | (unlabeled) | 1 | 34d |
| #422 | auth/pre-registration: scenario context omits the issuer, so a client implementing the 2026-07-28 spec's Authorization Server Binding cannot pass | bug | 0 | 34d |
| #426 | tier-check: final 2026-07-28 is still treated as draft and legacy scenarios score by default | (unlabeled) | 1 | 32d |
| #435 | Add conformance scenario: logging/setLevel and log notifications | (unlabeled) | 3 | 30d |
| #434 | Add conformance scenario: progress notification edge cases | (unlabeled) | 0 | 30d |
| #433 | Add conformance scenario: notifications/cancelled | (unlabeled) | 0 | 30d |
| #437 | Cover CIMD-only client authorization with no DCR endpoint | enhancement | 1 | 29d |
| #439 | input-required-result: sampling/roots scenarios vs SEP-2577, and capability-check accepting no inputRequests | (unlabeled) | 1 | 29d |
| #441 | tier-audit docs coverage: evaluate the feature list against the spec revision an SDK targets | (unlabeled) | 1 | 28d |
| #440 | input-required-result: harness sends the literal string `"undefined"` as an inputResponses key when round 1 names no input requests | (unlabeled) | 0 | 28d |
| #451 | Expose expected-vs-emitted check coverage per scenario | (unlabeled) | 0 | 22d |
| #453 | feat: Allow fixed request headers in server conformance tests | (unlabeled) | 1 | 19d |
| #461 | Bundled everything-server omits resultType on streamed tools/call responses | (unlabeled) | 0 | 14d |
| #465 | `authorization-code-grant` never sends the RFC 8707 `resource` parameter | (unlabeled) | 0 | 11d |
| #467 | Prevent false greens when a negative check rejects for the wrong reason | (unlabeled) | 0 | 7d |
| #470 | Add initial conformance tests for Resource AS of EMA | enhancement | 3 | 4d |
| #472 | HTTPS | (unlabeled) | 0 | 3d |
| #471 | HTTPS | bug | 0 | 3d |
| #475 | sep-2322 absent-resultType probe is an invalid stimulus on the 2026-07-28 wire it negotiates | (unlabeled) | 0 | 2d |
| #474 | http-standard-headers referee returns an invalid resources/templates/list result | (unlabeled) | 0 | 2d |
| #480 | Add server conformance for SEP-2350 scope challenges | (unlabeled) | 0 | 1d |
| #482 | feat(tier-check): support configurable label taxonomy and aliases for Tier 1 repo checks | enhancement | 0 | 0d |
Volume
Response Time
Time to first maintainer response
Stale Issues
Issues with no activity
Issues by Label
| Label | Count |
|---|---|
| bug | 23 |
| enhancement | 20 |
| question | 1 |
Issues Awaiting Maintainer Response
Sorted by longest wait time first
| Issue | Title | Labels | Comments | Waiting |
|---|---|---|---|---|
| #10 | How to specify platform-specific overrides based on CPU architecture? | enhancement | 5 | 431d |
| #9 | What does "bundle a complete virtual environment" mean? | question | 3 | 431d |
| #35 | Local development workflow doesn't work | bug | 1 | 428d |
| #54 | ENOENT no such file or directory, open '/path/to/manifest.json' | bug | 1 | 419d |
| #68 | Proposal: Add `post_install` and `post_uninstall` script hooks to DXT manifest | enhancement | 3 | 415d |
| #71 | Code signing requires private key PEM, but providers (e.g., Certum) don’t provide private key for download | enhancement | 2 | 413d |
| #91 | Low severity vulnerabilities introduced by dxt | bug | 0 | 376d |
| #149 | Feat: Tool icons | enhancement | 0 | 303d |
| #164 | Support oauth settings | enhancement | 2 | 280d |
| #165 | Feature Request: Add enum/dropdown support for user_config fields | enhancement | 1 | 273d |
| #177 | Feature Request: Declarative Filesystem Permissions in MCPB Manifest | enhancement | 1 | 237d |
| #176 | Support for remote MCP servers (streamable HTTP transport) | enhancement | 1 | 237d |
| #179 | Feature Request: Add server.type = "bash" for Bash-based MCP servers | enhancement | 1 | 229d |
| #180 | Incompatibility with native modules (ABI mismatch) in Node.js bundles | (unlabeled) | 2 | 228d |
| #182 | Feature Request: Support for MCP servers integrated with native applications | enhancement | 2 | 226d |
| #202 | support configuration of an already installed MCP server | enhancement | 1 | 175d |
| #218 | [BUG] mcpb validate warns about icon size even for 512x512 PNGs | bug | 1 | 164d |
| #219 | Filesystem MCP write_file returns success but files don't exist (Claude Desktop 1.1.8308, macOS) | bug | 1 | 162d |
| #223 | [BUG] Claude Desktop (Windows MSIX) — MSIX registry silo prevents all C:\Windows\System32\OpenSSH\ binaries from executing in child processes | bug | 0 | 155d |
| #224 | Feature Request: Bundle Attestation for API Backend Verification | (unlabeled) | 4 | 151d |
| #225 | Claude Desktop (Store): stdio MCP tools discovered but tools/call never reaches server (regression) | bug | 0 | 148d |
| #226 | Claude Desktop crashes on invalid semver in manifest version field | (unlabeled) | 0 | 140d |
| #229 | macOS: UtilityProcess rejects third-party native Node modules due to library validation (distinct from #180) | (unlabeled) | 1 | 139d |
| #232 | Desktop Extension submission status inquiry — Overboard Studio | (unlabeled) | 0 | 135d |
| #236 | Claude Desktop: Local DXT connector tool calls never dispatched after MCP handshake (silent timeout) | bug | 0 | 125d |
| #235 | mcpb pack on Windows produces .mcpb without Unix file permissions | bug | 0 | 125d |
| #238 | Freeze on mounting folders in claude coworkers | bug | 1 | 121d |
| #240 | 채팅 검색 시 프로젝트에 속한 채팅분류 | enhancement | 0 | 120d |
| #239 | 채팅 일부 삭제기능 건의 | enhancement | 0 | 120d |
| #241 | Default EXCLUDE_PATTERNS in mcpb pack is too broad | bug | 0 | 117d |
| #244 | Claude Desktop: sensitive user_config fields displayed in plain text in environment variables panel | (unlabeled) | 2 | 112d |
| #247 | Feature request: Native connector for Bloom.io | enhancement | 0 | 110d |
| #250 | Claude Desktop: substitute `user_config` options with no value | bug | 0 | 96d |
| #251 | Claude Desktop: substitute `${HOME}` in `user_config` defaults | bug | 0 | 95d |
| #256 | Textos en ingles con idioma español | bug | 0 | 88d |
| #260 | Signing/verification is non-functional: PKCS#7 signature never verified (node-forge stub), fails closed | (unlabeled) | 1 | 85d |
| #267 | Minor correctness/robustness fixes: empty-string override, secret logging, version precedence, ZIP bounds | (unlabeled) | 0 | 85d |
| #266 | mcpb unpack: unbounded in-memory decompression (zip-bomb DoS) | (unlabeled) | 0 | 85d |
| #265 | Resolved mcp_config still contains the full platform_overrides map | (unlabeled) | 0 | 85d |
| #264 | mcpb clean silently drops unknown nested manifest keys (loose .passthrough() is top-level only) | (unlabeled) | 0 | 85d |
| #263 | Strict 0.4 schema still requires server.mcp_config for uv type (contradicts spec + loose schema; incomplete fix of #201) | (unlabeled) | 0 | 85d |
| #262 | replaceVariables interpolates the variable key into a RegExp unescaped (over-match + crash/ReDoS) | (unlabeled) | 0 | 85d |
| #261 | mcpb unpack fails on archives containing directory entries (unusable on standard ZIP/.mcpb files) | (unlabeled) | 0 | 85d |
| #258 | replaceVariables corrupts user_config values containing $ (String.replace replacement-pattern footgun) | (unlabeled) | 0 | 85d |
| #276 | verifyMcpbFile always reports signed extensions as "unsigned" (node-forge pkcs7.verify() is an unimplemented stub) | (unlabeled) | 0 | 82d |
| #278 | `mcpb sign` produces bundles that strict zip parsers reject - including Claude Desktop itself ("Invalid comment length") | bug | 4 | 81d |
| #277 | `mcpb verify` reports every signed bundle as "Extension is not signed" (node-forge `p7.verify` is unimplemented) | bug | 1 | 81d |
| #281 | Installing .mcpb | bug | 1 | 81d |
| #280 | Register an icon for the .mcpb document type in Claude Desktop | (unlabeled) | 0 | 81d |
| #282 | Claude Desktop (macOS): an "Install Unpacked" type: binary extension is never launched — host falls back to "basic execution" and fails with ENOENT | bug | 0 | 80d |
| #283 | [Bug] User-level MCPB install silently never completes (org-level succeeds) | (unlabeled) | 1 | 78d |
| #284 | Drag-to-Settings install silently fails; double-click works (docs mismatch) | bug | 0 | 78d |
| #285 | Cowork: tool-call markup rendered as raw text + executions stall with no progress indicator | bug | 0 | 75d |
| #288 | "HRESULT 0x80073D28 설치 실패 - 레지스트리 키 손상" | bug | 0 | 63d |
| #289 | Add advanced agent workflow features from CLI to VS Code extension | enhancement | 0 | 62d |
| #292 | `mcpb pack` fails with a cryptic ELOOP error when the extension directory contains a symlink cycle | (unlabeled) | 2 | 50d |
| #294 | Claude Desktop (macOS) discards ZIP-stored Unix modes on extension extraction and writes 0600 — type: binary servers fail with EACCES | bug | 0 | 47d |
| #297 | Claude Desktop records manifest `mcp_config.env` but doesn't pass it to the spawned server process | (unlabeled) | 0 | 25d |
| #298 | manifest tools entries forbid inputSchema, so consumers that expect MCP's Tool shape reject the bundle | (unlabeled) | 0 | 9d |
| #299 | Add mcptoon: cross-agent MCP management CLI | (unlabeled) | 0 | 6d |
Volume
Response Time
Time to first maintainer response
Stale Issues
Issues with no activity
Issues by Label
| Label | Count |
|---|---|
| enhancement | 44 |
| bug | 21 |
| protocol | 7 |
| v2 | 3 |
| documentation | 2 |
| needs more work | 1 |
| needs spec change | 1 |
| upstream-host | 1 |
| v1 | 1 |
Issues Awaiting Maintainer Response
Sorted by longest wait time first
| Issue | Title | Labels | Comments | Waiting |
|---|---|---|---|---|
| #26 | ui:// protocol needs to be registered with IANA | bug | 1 | 280d |
| #269 | SEP: Duplicate placement of `McpUiResourceMeta` in the resource metadata and the resource read value leads to confusion. | bug | 0 | 230d |
| #412 | Side Panels For Interactive Documents | enhancement | 0 | 217d |
| #423 | Angular based MCP apps example | enhancement | 1 | 211d |
| #481 | MCP Apps: No shared session identity between AppBridge and Model sub-connections | (unlabeled) | 1 | 199d |
| #458 | Multiple `initialize` calls per conversation breaks `Mcp-Session-Id` linking | (unlabeled) | 2 | 198d |
| #465 | Feature parity with Apps SDK setWidgetState | enhancement | 0 | 196d |
| #500 | Proposal: Slot-based updateModelContext() for independent context channels | (unlabeled) | 0 | 189d |
| #511 | [Proposal] Rich UI elicitation — attach an MCP App to an elicitation/create request | enhancement | 4 | 186d |
| #513 | [Proposal] Features for speeding up slow Python/ Pyodide based apps | enhancement | 1 | 184d |
| #515 | CSP: Clarify/Allow '*' and scheme-based policies | enhancement | 1 | 182d |
| #542 | PostMessageTransport: Race condition with srcdoc iframes — host misses ui/initialize | (unlabeled) | 2 | 177d |
| #558 | ui/update-model-context: How should hosts handle multiple instances of the same app resource? | (unlabeled) | 1 | 165d |
| #566 | [Proposal] Support web workers (`worker-src`) via `workerDomains` on `McpUiResourceCsp` | enhancement | 0 | 160d |
| #574 | `downloadFile` not implemented on Claude iOS (error -32601) | (unlabeled) | 1 | 156d |
| #598 | Feature Request: Contextual Inline Citations with Modal/Dialog Popups for MCP Apps | enhancement | 0 | 151d |
| #599 | 💡 Idea: Growth strategy for MCP extension ecosystem | (unlabeled) | 0 | 150d |
| #611 | Version negotiation mechanism exists but HOST behavior doesn't change based on negotiated version | (unlabeled) | 0 | 141d |
| #617 | server-pdf: get_viewer_state always returns pageCount: 1 and get_text returns empty in VS Code | (unlabeled) | 0 | 135d |
| #633 | bug: Safari/WebKit event.source identity mismatch in sandbox.ts relay breaks PostMessageTransport | (unlabeled) | 0 | 133d |
| #635 | Feature: Add Angular basic example | enhancement | 3 | 132d |
| #634 | Spec 2026-01-26: misleading "View initialize" example uses `initialize` + `clientInfo` instead of `ui/initialize` + `appInfo` | bug | 0 | 132d |
| #644 | v1.7.0 refreshRoots() clears allowedLocalDirs when host advertises roots capability but returns empty list — wipes CLI-arg directories | (unlabeled) | 1 | 127d |
| #646 | basic-host does not forward toolResult _meta to the ui. | bug | 0 | 126d |
| #647 | `tools/call` requests no longer echo `Mcp-Session-Id` (violates Streamable HTTP spec) | bug | 1 | 124d |
| #649 | app-bridge pulls in entire Zod library (~1.4MB pre-minified) - most of it unused | (unlabeled) | 0 | 123d |
| #652 | unsafe-eval warning is thrown from AJV via @modelcontextprotocol/sdk dependency | bug | 0 | 118d |
| #655 | McpUiHostCapabilities missing tools field — widget-declared tools unimplementable by hosts | (unlabeled) | 0 | 117d |
| #659 | Proposal: Allow Views to subscribe to server resource updates via resources/subscribe | (unlabeled) | 2 | 115d |
| #661 | ,. | enhancement | 1 | 106d |
| #664 | Clarification Request: Standardized Guidance for Detecting Malicious Patterns in Widget HTML | (unlabeled) | 0 | 102d |
| #665 | @modelcontextprotocol/ext-apps consumers ship ~140K of unused zod v4 locale files in browser bundles | (unlabeled) | 1 | 100d |
| #671 | Bug Report: MCP Apps UI Resource Not Rendering in Claude Desktop / claude.ai | bug | 20 | 97d |
| #676 | Should hostCapabilities.appTools exist? | (unlabeled) | 2 | 96d |
| #678 | Support configuring approved redirect domains for ui/open-link | enhancement | 4 | 95d |
| #682 | د | enhancement | 0 | 91d |
| #684 | Pinned or Split Screen MCP Apps | enhancement | 3 | 90d |
| #686 | autoResize misses absolutely-positioned portal growth (popover opens → no size-changed) | (unlabeled) | 0 | 83d |
| #688 | Minimal preferred size | (unlabeled) | 2 | 82d |
| #687 | fresh install of basic-host example fails | bug | 0 | 82d |
| #689 | Guidelines for hosts to support Command Line (CLI) MCP Apps | enhancement | 0 | 78d |
| #694 | Clarify host behavior for rendering an MCP App view when the tool result is an error (isError: true) | (unlabeled) | 2 | 62d |
| #696 | Claude Desktop strips structuredContent from ui/notifications/tool-result — views built per SDK examples render blank | (unlabeled) | 2 | 56d |
| #702 | Migrate `ext-apps` to `@modelcontextprotocol/server` v2 SDK | enhancement | 2 | 55d |
| #701 | Bug: file_manager widget renders content then infinite re-render loop (oncalltool handler replaced storm) in Claude Desktop | (unlabeled) | 3 | 55d |
| #703 | Add ui.homepage field for redirecting to the app's homepage | (unlabeled) | 0 | 53d |
| #704 | Emitted .d.ts use extensionless relative imports — types break under NodeNext/Node16 (addEventListener invisible, TS2339) | (unlabeled) | 0 | 52d |
| #708 | Align MCP Apps capability negotiation with SEP-2133 | (unlabeled) | 0 | 50d |
| #707 | Help | bug | 0 | 50d |
| #706 | Spec: Deprecate Sampling | (unlabeled) | 0 | 50d |
| #711 | Add your HVTrust badge to the README? | (unlabeled) | 0 | 48d |
| #731 | Proposal: Guidelines for hosts to implement API for collapsible MCP Apps | enhancement | 0 | 34d |
| #732 | No way to mark a secondary tool as visible only to app | bug | 0 | 34d |
| #734 | Claude iOS: template renders but host delivers no lifecycle notifications to MCP App iframes (tool-input, tool-result, size-changed all absent) | (unlabeled) | 0 | 32d |
| #737 | [RFC] Session Resilience & Lifecycle Management for Heavy Server-Side Rendered UIs (WebRTC/CAD) | enhancement | 0 | 29d |
| #738 | Standardize provenance for app-initiated server tool calls | (unlabeled) | 1 | 28d |
| #740 | App view frame is labeled with the tool `name`, not its `title` — no `_meta.ui` field to name a view | (unlabeled) | 0 | 27d |
| #742 | Documentation for MCP Apps does not match 2026-07-28 specification | bug | 1 | 20d |
| #743 | MCP Apps Conformance Test - Host Interface Requirements | (unlabeled) | 0 | 19d |
| #744 | Add UI "preload" Control and "ui/close" Signal for MCP Apps Tool-Driven Widgets | enhancement | 1 | 18d |
| #746 | No way to distinguish an app-initiated tools/call from a model-initiated one | (unlabeled) | 0 | 17d |
| #745 | Apps cannot call their server's tools through a namespacing aggregator | (unlabeled) | 0 | 17d |
| #750 | Grok host: MCP Apps iframe rendering unstable for Paybox connector (custom BYO MCP) | (unlabeled) | 1 | 13d |
| #753 | Widget callServerTool calls hardcode bare tool names, breaking under multi-server MCP hosts | (unlabeled) | 0 | 9d |
| #754 | Host support for persistent (pip/pinned) app views: clinical use case where inline rendering breaks the core loop | (unlabeled) | 1 | 8d |
| #756 | MCP spec conformance: 5 requirements violated (via @hasmcp/mcp-spec-test) — spec 2025-11-25 | (unlabeled) | 0 | 8d |
| #755 | MCP spec conformance: 10 requirements violated (via @hasmcp/mcp-spec-test) — spec 2026-07-28 | (unlabeled) | 0 | 8d |
| #758 | API documentation | bug | 0 | 7d |
| #757 | Extend permission-policy negotiation for media/video widgets (fullscreen, presentation/Cast, remote-playback, PiP, encrypted-media) | (unlabeled) | 0 | 7d |
| #761 | Sandbox proxy does not apply _meta.ui.csp from the UI resource, so resourceDomains has no effect | (unlabeled) | 0 | 4d |
| #764 | Example proposal: review and select web sources | enhancement | 0 | 0d |