osfeed.dev
Release / / with @upstash/[email protected], [email protected], mcpb-v4.1.2, [email protected], @upstash/[email protected], mcpb-v4.1.3, @upstash/[email protected], mcpb-v4.2.0, @upstash/[email protected], [email protected], mcpb-v4.2.1, [email protected], @upstash/[email protected], @upstash/[email protected], mcpb-v4.3.0, [email protected]

Context7 @upstash/[email protected]

Prioritize documentation examples in your programming language.

Before you upgrade to @upstash/[email protected]

3 to fix

Supply credentials for HTTP `/mcp`, now required by default. Use OAuth access tokens rather than Clerk ID/session JWTs, which return 401. Operators can set `MCP_AUTH_ENFORCEMENT=observe` for anonymous `/mcp` migration.

Action requiredSign in to a Context7 MCP connection using OAuth.Affects: Anonymous HTTP clients, callers using Clerk ID/session JWTs, and HTTP server operators.
Read the evidence

Remove `MCP_MAX_SUBSCRIPTIONS`; HTTP `subscriptions/listen` now acknowledges and completes immediately, with no change notifications. Use valid `observe` or `required` values for authentication enforcement settings.

Action requiredConnect coding clients to a locally run documentation server over stdio or HTTP.Affects: HTTP deployments configuring subscriptions or authentication enforcement.Inferred
Read the evidence

Expired OAuth tokens now receive HTTP 401 with an invalid-token challenge. JWT audience mismatches are logged by default; `MCP_OAUTH_AUDIENCE_ENFORCEMENT=required` rejects them, and `MCP_OAUTH_ALLOWED_AUDIENCES` overrides accepted audiences.

Behavior changedAffects: HTTP MCP clients refreshing expired OAuth tokens and operators configuring audience checks.
Read the evidence

What changed in @upstash/[email protected]

MCP `query-docs` adds `language`, and CLI `docs` adds `--language`. HTTP credentials are required by default, OAuth tokens are validated more strictly, and the CLI declares Node.js 22.13+.

MCP 4.1.2–4.3.0; CLI 0.5.13–0.6.0; SDK 0.5.1; OpenCode plugin 0.2.0.

New things you can do

Fixed and improved

Seeded by @iluxav with Codex, from the release's public sources. Each change links to its evidence.