Repository navigation
[RUN-4807] Serve the 2026-07-28 MCP protocol revision over stdio - #88
Merged
Merged
Conversation
Switches to serveStdio(() => server) so the server negotiates both the 2025-era protocol and 2026-07-28 from the same handler registrations, and reworks destructive-action confirmation off the deprecated (and, on a 2026-07-28-era request, throwing) Server.elicitInput onto the MRTR inputRequired() pattern, written once for both eras — the SDK's own legacy shim fulfills it on 2025-era connections via a real elicitation/create request, verified against both the SDK's runtime source and a real unpinned client in a new integration test. Also adds cacheHints for the 2026-07-28 CacheableResult fields (optional tuning, not a compliance requirement — the SDK fills safe defaults), a resources/templates/list handler (previously unregistered, causing a "Method not found" observed live via MCP Inspector), and an inspector.config.json + npm run inspect update to exercise Modern era. Full rationale, SDK-internals evidence, and review findings in PROTOCOL_2026_07_28_MIGRATION_PLAN.md. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Closed
10 of 15 tasks
rolldown 1.2.5 (a transitive dev dependency: @modelcontextprotocol/inspector -> vite -> rolldown) is caught by the internal registry's quarantine policy for recently-published packages, breaking npm ci in CI. 1.2.4 is a week older, still within vite's own declared ~1.2.1 range, and never touches this repo's own code (rolldown is only vite's bundler for the Inspector's web UI, not shipped or used at runtime). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…n in CLAUDE.md The Entry point section still said "all six MCP request types" and made no mention of serving two protocol eras or the elicitInput->MRTR rework, both introduced by the 2026-07-28 migration in this branch. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
fdevans
approved these changes
Aug 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
About this change
Jira Ticket: RUN-4807
Purpose of the Changes
Adds 2026-07-28 ("modern era") protocol support over stdio, alongside the existing 2025-era protocol, via
serveStdio(() => server). Reworks destructive-action confirmation (api_callDELETE/credential-regen,acl_managedelete/update) off the deprecatedServer.elicitInput(which throws on a 2026-07-28-era request) onto the MRTRinputRequired()pattern — written once for both eras, per the SDK's own migration guide: the SDK's built-in legacy shim fulfills it on 2025-era connections via a realelicitation/createrequest, verified both against the SDK's runtime source and a real unpinned client in a new integration test.Also:
cacheHintsfor the 2026-07-28CacheableResultfields (optional tuning — the SDK fills safe defaults on its own), aresources/templates/listhandler (was unregistered, causing a live "Method not found" via MCP Inspector), and aninspector.config.json+npm run inspectupdate to exercise Modern era.Supersedes #85 (targets this same
sdk-updatebase) — full rationale, SDK-internals evidence, and independent review findings (SDK-audit, changelog-completeness,update-protocol-branch comparison, official-guide cross-check) are inPROTOCOL_2026_07_28_MIGRATION_PLAN.md.Kind of Change
Development Checklist
npm run validatepasses locally (build + test + integration validations)confirmation.test.tsrewritten for the unified era-agnostic design; two new integration test files drive a real client against the built server on both erasserveStdio()/dual-era serving, the newresources/templates/listhandler, and the MRTR-based confirmation reworkRUNDECK_DOCS_PATHbehavior unaffected, or changes called out below — unaffectedTesting
Testing setup:
Acceptance Criteria:
npm run buildsucceeds with no TypeScript errorsnpm testpasses (390/390), including both 2025-era and 2026-07-28-pinned integration coveragenpm run validatepassesversionNegotiation: { mode: { pin: "2026-07-28" } }completes the full destructive-action MRTR round trip (input_required→ retry → resolved outcome)rundeck/mcp-ci:latest) rebuilt and smoke-tested clean, including a real MCPinitializeround trip