Repository navigation
chore: bump mcp SDK to 2.3.0 - #130
Merged
Merged
Conversation
Raise the floor to >=2.3 so installs can no longer resolve 2.0.0, which rejects notification POSTs on the 2026-07-28 HTTP entry with a 400 and lacks Server(get_tool_input_schema=...). Pulls httpx2/httpcore2 2.13.1 and mcp-types 2.3.0 transitively.
Drive the real hosted app and assert a POSTed notifications/cancelled is answered with 202 on both / and /mcp. mcp 2.0.0 rejected it with a 400 JSON-RPC error (python-sdk#3326).
On the 2026-07-28 HTTP entry the SDK validates Mcp-Param-* headers on every tools/call. Without Server(get_tool_input_schema=...) it does that by running our tools/list handler, which recorded a phantom tools/list in telemetry for each tool call. mcp 2.3.0 (python-sdk#3630) lets the server answer the lookup by name instead.
run_stdio hand-built InitializationOptions, so stdio clients got a different serverInfo name than HTTP clients, no instructions, icons or website URL, and an empty experimental capability that mcp 2.3.0 now omits everywhere else (python-sdk#3614). Use Server.create_initialization_options() like the HTTP transport does.
🟢 Tier S · Ready to merge
Raises the MCP SDK minimum to 2.3.0 and updates the lockfile’s resolved SDK dependencies. The server now supplies direct tool-schema lookup and builds stdio initialization metadata through the SDK, with regression coverage for hosted notifications, tool-call telemetry, and stdio metadata.
📂 Walkthrough · 5
Reviewed |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Bumps the
mcpPython SDK from 2.0.0 to 2.3.0 and raises the floor inpyproject.tomlfrommcp[cli]>=2,<3tomcp[cli]>=2.3,<3. The floor is required: the server now passesServer(get_tool_input_schema=...), which only exists from 2.3.0 (11 unit tests fail withTypeErroron 2.0.0). It also stops installs from resolving the 2.0.0 release that answers notification POSTs with a 400.Transitive lockfile changes:
mcp-types2.0.0 -> 2.3.0,httpx2andhttpcore22.9.1 -> 2.13.1 (2.3.0 requireshttpx2>=2.10), andhttpx2-jsfetch1.0 is added, but only forsys_platform == 'emscripten', so nothing changes on Linux or macOS.Two small fixes ride along because the upgrade exposed them:
tools/listtelemetry. On the 2026-07-28 HTTP entry the SDK checksMcp-Param-*headers on everytools/callthat has arguments. With no schema lookup it ran ourtools/listhandler to get the schema, so each tool call also recorded atools/listinmcp.*metrics. The server now passesget_tool_input_schema, which finds the schema by name (python-sdk#3630).run_stdiobuiltInitializationOptionsby hand. That gave stdio clients a differentserverInfo.name(appwrite) from the one HTTP clients see (Appwrite MCP Server), left outinstructions, icons andwebsiteUrl, and sent"experimental": {}, which 2.3.0 drops everywhere else (python-sdk#3614). It now callsserver.create_initialization_options(), the same path the HTTP transport uses. Visible effect: stdio clients now receive the server instructions and see the same server name as HTTP clients.This prepares for #127 (MCP events) by moving us to the current 2.x line, but it does not complete it: 2.3.0 still has no events support (modelcontextprotocol/python-sdk#3640).
What we gain
notifications/cancelled) on the hosted 2026-07-28 entry now gets202instead of a400JSON-RPC error, on both/and/mcp. Covered by a new regression test that drives the real Starlette app.Server(get_tool_input_schema=...). We use it sotools/callno longer runs a hiddentools/list(which inflatedtools/listcounts in telemetry). Covered by a regression test.initializestops sending an emptyexperimentalcapability. stdio now does the same because it shares the SDK path (see Summary). Covered by a regression test._metaorparams._client_identity_from_ctxalready handlesctx.meta is None, andMCPIdentityMiddlewarealready handles missingparams. No test or wire assertion relied on the empty forms.Not applicable
Stateful-session changes (#3395 idle expiry and session cap,
DELETEand refused-open cleanup): we runStreamableHTTPSessionManager(stateless=True). MCPServer-only changes (#3314 handler-exception logging, #3320 content-block returns, #3620x-mcp-headerregistration, #3626subscriptions=False, #3624); client-side changes (#3394outputSchema$refresolution: our catalogs have nooutputSchema; #3223 cache-hint fields: we emit none; #3397 redirects, #3398/#3435 OAuth client issuer, #3600max_sse_event_size, #3627, #3635); #3447AuthSettings.validate_token_resource: we useBearerAuthBackenddirectly, so no deprecation warning; #3336 SSE/OAuth body limit: no SSE transport and no SDK OAuth endpoints; #3354 boolean sub-schemas: none in our generated schemas.Verification
All commands ran on Python 3.12.8, matching CI:
uv lock --upgrade-package mcp: mcp 2.0.0 -> 2.3.0uv run --group dev ruff check src tests: passeduv run --group dev black --check src tests: 48 files unchangeduv run --group dev pyright: 0 errors, 0 warningsuv run python -m unittest discover -s tests/unit -v: 265 tests OKmcp==2.0.0(uv run --with mcp==2.0.0 --with mcp-types==2.0.0 ...): the notification test fails with400 != 202 : {"code":-32600,"message":"Body must be a single JSON-RPC request object"}. The two fix tests fail on the parent commit without their fix (['tools/list', 'tools/call'] != ['tools/call']and'appwrite' != 'Appwrite MCP Server').mcp.types.Toolvalidation andDraft202012Validator.check_schema, with 0outputSchema, 0$refand 0 boolean sub-schemas. An in-processmcp.Clientconnected inlegacymode (2025-11-25) andautomode (2026-07-28) lists the public tools and callsappwrite_search_toolswithout errors.docker build -t appwrite-mcp:ci .: image built successfully locally, and the CIDocker buildjob passed.APPWRITE_*credentials were available. In CI: 24 tests, 10 passed, 14 skipped because CI also has no live Appwrite credentials (skipped 'Valid Appwrite credentials are required...').Changelog
notifications/cancelledare now accepted with202instead of rejected with400.tools/listin usage metrics.initialize, and reports the same server name as the hosted server.