← September 2026
News 2026-09-11

MCP Protocol News - September 11, 2026

The Model Context Protocol ecosystem saw coordinated release activity this week, led by a Python SDK 2.2.0 update that changes default HTTP client redirect behavior and a maintenance release…

MCP Protocol News - September 11, 2026

MCP Protocol News - September 11, 2026

Week of: September 11, 2026


Overview

The Model Context Protocol ecosystem saw coordinated release activity this week, led by a Python SDK 2.2.0 update that changes default HTTP client redirect behavior and a maintenance release backporting the same change to the 1.x line. On the specification side, a filesystems working group proposal was merged into the MCP repository, and the GitHub MCP Server shipped a bugfix release tightening its OAuth metadata.

Stories

1. MCP Python SDK 2.2.0 ships with changed HTTP client redirect defaults

Source: MCP Python SDK Link: https://github.com/modelcontextprotocol/python-sdk/releases/tag/v2.2.0

The MCP Python SDK released v2.2.0, installable via pip install -U mcp, with documentation at the project's Python SDK site. The release notes flag that "a few defaults changed," with the highlighted behavior change being that HTTP client redirects are only followed within the endpoint's origin: Client("https://..."), streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host). A redirect anywhere else is not followed — the call fails with MCPError and the session stays usable, while an SSE connect fails with httpx2.HTTPStatusError.

This matters for teams running MCP servers or clients on the 2.x line, since redirect handling that previously worked transparently may now surface as an error unless the final endpoint is used directly. Anyone deploying MCP clients behind proxies, gateways, or URL-shortening layers should review how their endpoints redirect before upgrading. The release notes state that further defaults changed, so operators are advised to skim the full notes before rolling out — see source.

Impact Analysis: Audit your MCP client endpoint configuration for cross-origin redirects before upgrading to 2.2.0, as they will now fail rather than resolve silently.

2. Filesystems working group proposal merged into the MCP specification repository

Source: MCP Specification Link: https://github.com/modelcontextprotocol/modelcontextprotocol/commit/aa8ce049f089f92618340190d4ece141f663310d

A pull request (#3282, from contributor DanielTemesgen) adding a proposal for a filesystems working group was merged into the modelcontextprotocol repository. The merge commit lands the proposal in the specification project's history.

Working groups are the mechanism through which the MCP project scopes and standardizes new capability areas, so a filesystem-focused group is a signal that file access patterns are being treated as a first-class part of the protocol's roadmap. For builders shipping file-oriented MCP servers, this is worth tracking early, since working group output typically shapes later spec work and SDK conventions. Details of the proposal's scope are in the merged commit — see source.

Impact Analysis: File-access server authors should follow this working group, as its output is likely to inform future spec and SDK expectations for filesystem tools.

3. GitHub MCP Server 1.12.1 fixes overly permissive OAuth scope advertising

Source: GitHub MCP Server Link: https://github.com/github/github-mcp-server/releases/tag/v1.12.1

GitHub MCP Server released v1.12.1, a bugfix release addressing a case where OAuth protected resource metadata became "too permissive in the supported scopes advertised." The fix advertises only default scopes in protected resource metadata (PR #3251). The release also returns a clear error for missing owner/repo/issue_number in the Copilot assignment tools (#3221) and bumps the base image from golang 1.27.0-alpine to 1.27.1-alpine (#3239), and it welcomes a first-time contributor.

The OAuth metadata change matters for anyone wiring GitHub's MCP server into an agent stack with scoped credentials, since advertising broader scopes than intended can affect what clients discover and request during authorization. Tightening the advertised scope set reduces the risk of over-broad consent surfaces in automated integrations.

Impact Analysis: Update to 1.12.1 if you expose GitHub's MCP server to OAuth clients, so advertised scopes match the intended default set.

4. MCP Python SDK 1.30.0 maintenance release backports redirect behavior change

Source: MCP Python SDK Link: https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.30.0

The MCP Python SDK published v1.30.0, described as a maintenance release of the 1.x line, with 2.x noted as the current line and 1.x documentation hosted at a versioned docs path. Like 2.2.0, this release changes defaults: HTTP client redirects are only followed within the endpoint's origin (#3448), where streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host), and a redirect anywhere else now fails the request with httpx.HTTPStatusError.

For teams still maintaining 1.x deployments, this is a behavior change rather than a pure bugfix, and the same guidance as the 2.x release applies: if the redirect target is the server you actually meant, use it as the endpoint. Teams that have already migrated to 2.x can treat this as confirmation that the redirect semantics are consistent across supported lines.

Impact Analysis: Treat 1.30.0 as a behavior-changing upgrade on the 1.x line and verify endpoint URLs before deploying it to existing agents.

Source Links

More from News