MCP Protocol News - October 2, 2026
The Model Context Protocol ecosystem saw a busy week of maintenance and release activity: GitHub shipped MCP Server 1.13.0 with new granular comment/review tools and MCP Apps UI enabled by default…
MCP Protocol News - October 2, 2026
Week of: October 2, 2026
Overview
The Model Context Protocol ecosystem saw a busy week of maintenance and release activity: GitHub shipped MCP Server 1.13.0 with new granular comment/review tools and MCP Apps UI enabled by default, the TypeScript SDK published the 2.2.0 release line with OAuth provider changes, and the specification repository merged governance and documentation updates including Tier 1 status for the Ruby SDK and a new requirement that SEPs get working-group discussion before submission.
Stories
1. GitHub MCP Server 1.13.0 adds granular comment tools and enables MCP Apps UI by default
Source: GitHub MCP Server Link: https://github.com/github/github-mcp-server/releases/tag/v1.13.0
GitHub released MCP Server v1.13.0, whose changelog lists granular tools to hide and unhide issue comments, PR review comments and PR reviews (#3350). The release also preserves versioned STDIO API user agents across MCP protocols (#3323), removes the remote_mcp_ui_apps flag gate so MCP Apps UI is always enabled (#3348), and uses source revisions for non-release Docker builds (#3357).
At the server level, the practical effect is finer-grained permissioning over GitHub conversation surfaces, which matters for agents that triage issues and PRs without being handed broad moderation capability. Always-on MCP Apps UI also signals the protocol's UI extension is treated as default-on behavior in this client rather than an opt-in experiment.
Impact Analysis: Teams running the GitHub MCP Server should re-check their tool allowlists, since the new hide/unhide tools expand the write surface an agent can reach.
2. TypeScript SDK 2.2.0 ships with OAuth issuer binding and handler fixes
Source: MCP TypeScript SDK Link: https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/v2.2.0
Version 2.2.0 covers @modelcontextprotocol/client, server, core, server-legacy and codemod, while node, express, hono and fastify are unchanged. The minor change deprecates constructing ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer — the constructor logs a single console.warn and that signature is marked deprecated — and fetchToken() now throws AuthorizationServerMismatchError before sending anything when the provider's client information is bound to a different authorization server (#2887).
Patch fixes include avoiding a briefly unhandled promise rejection when sending a notification on a closed connection, a stack overflow fix in createMcpHandler when a factory returns the same server instance for more than one request, and a subscriptions/listen stream that now ends right after acknowledgement when it honored none of the requested subscriptions. The v1-to-v2 codemod also writes rewritten imports where the first v1 import stood so license headers and use client/use server directives stay in place, with a noted known gap.
Impact Analysis: Machine-to-machine OAuth integrations should pass expectedIssuer now to avoid deprecation warnings, and server authors using shared handler factories should upgrade for the stack overflow fix.
3. Ruby SDK promoted to Tier 1 in the MCP SDK listing
Source: MCP Specification Link: https://github.com/modelcontextprotocol/modelcontextprotocol/commit/70480219e37e33ac0f7ec286779e24c4b58e1950
The Ruby SDK was promoted from Tier 2 to Tier 1 in the SDK listing for both the 2026-07-28 revision and the draft, per Tier 1 application #3247. The listing update cites server conformance of 67/67 and client conformance of 50/50 across the frozen 2025-11-25 and 2026-07-28 requirement sets, 100% issue triage, no P0s ever filed, a stable v1.2.0, a 4-day spec-tracking gap, and all three required policies published.
Tier status is the protocol's own signal of SDK maturity, so this matters for teams choosing a language stack for MCP servers or clients — Ruby now sits in the top tier alongside the reference implementations for the stated revisions.
Impact Analysis: Ruby is now a defensible first-class target for MCP server and client work at the listed revisions, backed by published conformance evidence.
4. SEP guidelines now require working-group or interest-group discussion before submission
Source: MCP Specification Link: https://github.com/modelcontextprotocol/modelcontextprotocol/commit/b3e2cc7a137f9c7d4335399300ad576cc4a66b68
The spec repository merged a change requiring WG/IG discussion before a SEP is submitted, and the SEP guidelines now note the collaborator-only pull request restriction (#3336). The change modifies the process documentation rather than the protocol itself.
For anyone filing protocol change proposals, this adds a mandatory socialization step before the formal SEP path, which shifts where early design debate happens.
Impact Analysis: Would-be SEP authors should open (or join) working-group discussion first, since proposals without that step will not meet the updated guidelines.
5. Conformance maintainers added to the specification MAINTAINERS.md
Source: MCP Specification Link: https://github.com/modelcontextprotocol/modelcontextprotocol/commit/3098fe94caa1b9e0afaaa6d30e040b61d5802471
A pull request adding Conformance maintainers to MAINTAINERS.md was merged, listing the maintainers of the conformance repository (github.com/modelcontextprotocol/conformance) under Project Maintainers. The underlying commit and its Claude-assisted session link are recorded in the change.
Conformance tooling is what Tier assessments and spec-version compliance checks lean on, so formalizing its maintainers under the project's governance is an incremental but concrete step toward accountable compliance testing.
Impact Analysis: Expect conformance tooling to be governed as a first-class part of the project, which makes its outputs more reliable as a Tier-assessment reference.
6. Short-form /seps/{number} redirects added for SEP pages
Source: MCP Specification Link: https://github.com/modelcontextprotocol/modelcontextprotocol/commit/8ee48a9599bc2a24c0bd6bea279cec5cb479e3ae
Requested in Discord, a URL like /seps/2596 now resolves without knowing the slug, mirroring how RFC links work. render-seps.ts writes one redirect per SEP into docs.json, replacing any managed /seps/ entries on each run so check:seps keeps them current, and the SEP index and guidelines mention the short form.
Stable, guessable links make SEP references easier to cite in code comments, issues and agent-retrieved documentation.
Impact Analysis: Tooling and docs that reference SEPs can use the numeric URL form, which is now generated and kept current automatically.
7. mcpc MCP CLI added to the documented client matrix
Source: MCP Specification Link: https://github.com/modelcontextprotocol/modelcontextprotocol/commit/f356c3b0bff7bcc81cadc4b13a23c0e0da7101cc
The extensions documentation added the mcpc MCP CLI to the client matrix (#3390). The commit lists Jan Curn and Claude as co-authors.
The client matrix is where builders check what supports a given extension, so listing a CLI client makes command-line MCP workflows discoverable alongside GUI clients.
Impact Analysis: Developers evaluating client-side extension support should check the updated matrix for mcpc coverage.
Source Links
- GitHub MCP Server - GitHub MCP Server 1.13.0
- MCP TypeScript SDK - 2.2.0
- MCP Specification - Add Ruby SDK Tier 1 assessment to SDK listing (#3248)
- MCP Specification - Require WG/IG discussion before SEP submission (#3336)
- MCP Specification - Add Conformance maintainers to MAINTAINERS.md
- MCP Specification - docs: add /seps/{number} redirects for SEP pages (#3387)
- MCP Specification - docs(extensions): add mcpc MCP CLI to client matrix (#3390)
More from News