[v2] Decouple server from express and hono - http framework-agnostic MCP server - #1326

Merged
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server
Jan 16, 2026
Merged

[v2] Decouple server from express and hono - http framework-agnostic MCP server#1326
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server

Conversation

@KKonstantinov

@KKonstantinovKKonstantinov commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

v1 included express (and hono in recent version), forcing the dependency down to users. (express being >1MB along with middleware deps such as express-rate-limit etc.).

Achieving final & true implementation of #1299

This PR decouples @modelcontextprotocol/server from HTTP frameworks completely, and introduces three middleware packages: @modelcontextprotocol/node, @modelcontextprotocol/express, @modelcontextprotocol/hono.

The middleware packages are optional, and users could choose to use them or to map to the MCP SDK themselves and not using any of these plugins.

However, the @modelcontextprotocol/server is completely HTTP framework dependency-free.

Some additional changes:

  • Renamed StreamableHTTPServerTransport to NodeStreamableHTTPServerTransport
  • Added linting rule to avoid inline type imports (e.g. import { A, type B}). Prefer import type { B } and import { A } on separate lines.
  • Removed express dependency from @modelcontextprotocol/server completely
  • introduced @modelcontextprotocol/server-express and @modelcontextprotocol/server-hono - each having its own minimum dependencies
  • Removed sse transport for server (deprecated)
  • Removed server auth
  • Replaced examples for server auth with an OAuth library (e.g. better-auth)
  • Wrote up FAQ sections for removing SSE from server and removing auth from server
  • Tested better-auth server auth demo examples with @modelcontextprotocol/inspector
  • Updated express to 5.2.1 to get rid of CVE reported on 5.0.1 on the qs library (https://security.snyk.io/vuln/SNYK-JS-QS-14724253)
  • Updated existing docs, introduced new docs for middleware packages and general middleware doc

Motivation and Context

v2

How Has This Been Tested?

Unit tests

Breaking Changes

v2

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@changeset-bot

changeset-botBot commented Dec 20, 2025

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 7efc9ae

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Dec 20, 2025

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@1326

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@1326

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@1326

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@1326

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@1326

commit: 7efc9ae

@KKonstantinov
KKonstantinov marked this pull request as ready for review December 22, 2025 11:36
@KKonstantinov
KKonstantinov requested a review from a team as a code ownerDecember 22, 2025 11:36
@KKonstantinovKKonstantinov added breaking change Will break existing deployments when updated without changes auth Issues and PRs related to Authentication / OAuth v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes labels Dec 22, 2025
This was linked to issues Dec 22, 2025
Closed
@KKonstantinovKKonstantinov self-assigned this Dec 22, 2025
@KKonstantinovKKonstantinov added this to the v2 milestone Dec 22, 2025
@43081j

43081j commented Jan 9, 2026

Copy link
Copy Markdown

how are you calculating those sizes? they look too big to be the production install size, is it the size of your local server/node_modules including devDeps?

it might be worth including the production install size since that'll be what affects most people

a quick glance at it shows me the server is roughly ~9MB in main, and 6.5MB in your branch. huge saving!

Comment threadpackages/core/src/shared/protocol.ts Outdated
@43081j

Copy link
Copy Markdown

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auth pieces LGTM!

@KKonstantinov

KKonstantinov commented Jan 13, 2026

Copy link
Copy Markdown
ContributorAuthor

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

Nice catch, yes, all middlewares should have these in peers, including @modelcontextprotocol/server (which should be a peer dep and not baked into middlewares).

Comment thread.gitignore Outdated
pcarleton
pcarleton previously requested changes Jan 14, 2026

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry missed this earlier, but the PRM path needs to have the pathname after .well-known rather than before

Comment threadexamples/shared/src/authMiddleware.ts
felixweinberger
felixweinberger previously approved these changes Jan 15, 2026

@felixweinbergerfelixweinberger left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

Comment threadpackages/server/src/server/helper/body.ts Outdated
@KKonstantinov

Copy link
Copy Markdown
ContributorAuthor

Done!

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

@felixweinberger
felixweinberger dismissed pcarleton’s stale reviewJanuary 16, 2026 09:49

Dismissing @pcarleton's review as I believe his change request has been addressed

@KKonstantinov
KKonstantinov merged commit f495077 into modelcontextprotocol:mainJan 16, 2026
9 checks passed
mozmo15 pushed a commit to mozmo15/typescript-sdk that referenced this pull request Mar 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authIssues and PRs related to Authentication / OAuthbreaking changeWill break existing deployments when updated without changesv2Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Decouple from Express: support other HTTP frameworks SDK V2

4 participants

@KKonstantinov@43081j@pcarleton@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[v2] Decouple server from express and hono - http framework-agnostic MCP server - #1326

Merged
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server
Jan 16, 2026
Merged

[v2] Decouple server from express and hono - http framework-agnostic MCP server#1326
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server

Conversation

@KKonstantinov

@KKonstantinovKKonstantinov commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

v1 included express (and hono in recent version), forcing the dependency down to users. (express being >1MB along with middleware deps such as express-rate-limit etc.).

Achieving final & true implementation of #1299

This PR decouples @modelcontextprotocol/server from HTTP frameworks completely, and introduces three middleware packages: @modelcontextprotocol/node, @modelcontextprotocol/express, @modelcontextprotocol/hono.

The middleware packages are optional, and users could choose to use them or to map to the MCP SDK themselves and not using any of these plugins.

However, the @modelcontextprotocol/server is completely HTTP framework dependency-free.

Some additional changes:

  • Renamed StreamableHTTPServerTransport to NodeStreamableHTTPServerTransport
  • Added linting rule to avoid inline type imports (e.g. import { A, type B}). Prefer import type { B } and import { A } on separate lines.
  • Removed express dependency from @modelcontextprotocol/server completely
  • introduced @modelcontextprotocol/server-express and @modelcontextprotocol/server-hono - each having its own minimum dependencies
  • Removed sse transport for server (deprecated)
  • Removed server auth
  • Replaced examples for server auth with an OAuth library (e.g. better-auth)
  • Wrote up FAQ sections for removing SSE from server and removing auth from server
  • Tested better-auth server auth demo examples with @modelcontextprotocol/inspector
  • Updated express to 5.2.1 to get rid of CVE reported on 5.0.1 on the qs library (https://security.snyk.io/vuln/SNYK-JS-QS-14724253)
  • Updated existing docs, introduced new docs for middleware packages and general middleware doc

Motivation and Context

v2

How Has This Been Tested?

Unit tests

Breaking Changes

v2

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@changeset-bot

changeset-botBot commented Dec 20, 2025

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 7efc9ae

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Dec 20, 2025

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@1326

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@1326

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@1326

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@1326

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@1326

commit: 7efc9ae

@KKonstantinov
KKonstantinov marked this pull request as ready for review December 22, 2025 11:36
@KKonstantinov
KKonstantinov requested a review from a team as a code ownerDecember 22, 2025 11:36
@KKonstantinovKKonstantinov added breaking change Will break existing deployments when updated without changes auth Issues and PRs related to Authentication / OAuth v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes labels Dec 22, 2025
This was linked to issues Dec 22, 2025
Closed
@KKonstantinovKKonstantinov self-assigned this Dec 22, 2025
@KKonstantinovKKonstantinov added this to the v2 milestone Dec 22, 2025
@43081j

43081j commented Jan 9, 2026

Copy link
Copy Markdown

how are you calculating those sizes? they look too big to be the production install size, is it the size of your local server/node_modules including devDeps?

it might be worth including the production install size since that'll be what affects most people

a quick glance at it shows me the server is roughly ~9MB in main, and 6.5MB in your branch. huge saving!

Comment threadpackages/core/src/shared/protocol.ts Outdated
@43081j

Copy link
Copy Markdown

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auth pieces LGTM!

@KKonstantinov

KKonstantinov commented Jan 13, 2026

Copy link
Copy Markdown
ContributorAuthor

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

Nice catch, yes, all middlewares should have these in peers, including @modelcontextprotocol/server (which should be a peer dep and not baked into middlewares).

Comment thread.gitignore Outdated
pcarleton
pcarleton previously requested changes Jan 14, 2026

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry missed this earlier, but the PRM path needs to have the pathname after .well-known rather than before

Comment threadexamples/shared/src/authMiddleware.ts
felixweinberger
felixweinberger previously approved these changes Jan 15, 2026

@felixweinbergerfelixweinberger left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

Comment threadpackages/server/src/server/helper/body.ts Outdated
@KKonstantinov

Copy link
Copy Markdown
ContributorAuthor

Done!

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

@felixweinberger
felixweinberger dismissed pcarleton’s stale reviewJanuary 16, 2026 09:49

Dismissing @pcarleton's review as I believe his change request has been addressed

@KKonstantinov
KKonstantinov merged commit f495077 into modelcontextprotocol:mainJan 16, 2026
9 checks passed
mozmo15 pushed a commit to mozmo15/typescript-sdk that referenced this pull request Mar 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authIssues and PRs related to Authentication / OAuthbreaking changeWill break existing deployments when updated without changesv2Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Decouple from Express: support other HTTP frameworks SDK V2

4 participants

@KKonstantinov@43081j@pcarleton@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v2] Decouple server from express and hono - http framework-agnostic MCP server - #1326

Merged
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server
Jan 16, 2026
Merged

[v2] Decouple server from express and hono - http framework-agnostic MCP server#1326
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server

Conversation

@KKonstantinov

@KKonstantinovKKonstantinov commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

v1 included express (and hono in recent version), forcing the dependency down to users. (express being >1MB along with middleware deps such as express-rate-limit etc.).

Achieving final & true implementation of #1299

This PR decouples @modelcontextprotocol/server from HTTP frameworks completely, and introduces three middleware packages: @modelcontextprotocol/node, @modelcontextprotocol/express, @modelcontextprotocol/hono.

The middleware packages are optional, and users could choose to use them or to map to the MCP SDK themselves and not using any of these plugins.

However, the @modelcontextprotocol/server is completely HTTP framework dependency-free.

Some additional changes:

  • Renamed StreamableHTTPServerTransport to NodeStreamableHTTPServerTransport
  • Added linting rule to avoid inline type imports (e.g. import { A, type B}). Prefer import type { B } and import { A } on separate lines.
  • Removed express dependency from @modelcontextprotocol/server completely
  • introduced @modelcontextprotocol/server-express and @modelcontextprotocol/server-hono - each having its own minimum dependencies
  • Removed sse transport for server (deprecated)
  • Removed server auth
  • Replaced examples for server auth with an OAuth library (e.g. better-auth)
  • Wrote up FAQ sections for removing SSE from server and removing auth from server
  • Tested better-auth server auth demo examples with @modelcontextprotocol/inspector
  • Updated express to 5.2.1 to get rid of CVE reported on 5.0.1 on the qs library (https://security.snyk.io/vuln/SNYK-JS-QS-14724253)
  • Updated existing docs, introduced new docs for middleware packages and general middleware doc

Motivation and Context

v2

How Has This Been Tested?

Unit tests

Breaking Changes

v2

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@changeset-bot

changeset-botBot commented Dec 20, 2025

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 7efc9ae

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Dec 20, 2025

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@1326

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@1326

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@1326

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@1326

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@1326

commit: 7efc9ae

@KKonstantinov
KKonstantinov marked this pull request as ready for review December 22, 2025 11:36
@KKonstantinov
KKonstantinov requested a review from a team as a code ownerDecember 22, 2025 11:36
@KKonstantinovKKonstantinov added breaking change Will break existing deployments when updated without changes auth Issues and PRs related to Authentication / OAuth v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes labels Dec 22, 2025
This was linked to issues Dec 22, 2025
Closed
@KKonstantinovKKonstantinov self-assigned this Dec 22, 2025
@KKonstantinovKKonstantinov added this to the v2 milestone Dec 22, 2025
@43081j

43081j commented Jan 9, 2026

Copy link
Copy Markdown

how are you calculating those sizes? they look too big to be the production install size, is it the size of your local server/node_modules including devDeps?

it might be worth including the production install size since that'll be what affects most people

a quick glance at it shows me the server is roughly ~9MB in main, and 6.5MB in your branch. huge saving!

Comment threadpackages/core/src/shared/protocol.ts Outdated
@43081j

Copy link
Copy Markdown

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auth pieces LGTM!

@KKonstantinov

KKonstantinov commented Jan 13, 2026

Copy link
Copy Markdown
ContributorAuthor

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

Nice catch, yes, all middlewares should have these in peers, including @modelcontextprotocol/server (which should be a peer dep and not baked into middlewares).

Comment thread.gitignore Outdated
pcarleton
pcarleton previously requested changes Jan 14, 2026

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry missed this earlier, but the PRM path needs to have the pathname after .well-known rather than before

Comment threadexamples/shared/src/authMiddleware.ts
felixweinberger
felixweinberger previously approved these changes Jan 15, 2026

@felixweinbergerfelixweinberger left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

Comment threadpackages/server/src/server/helper/body.ts Outdated
@KKonstantinov

Copy link
Copy Markdown
ContributorAuthor

Done!

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

@felixweinberger
felixweinberger dismissed pcarleton’s stale reviewJanuary 16, 2026 09:49

Dismissing @pcarleton's review as I believe his change request has been addressed

@KKonstantinov
KKonstantinov merged commit f495077 into modelcontextprotocol:mainJan 16, 2026
9 checks passed
mozmo15 pushed a commit to mozmo15/typescript-sdk that referenced this pull request Mar 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authIssues and PRs related to Authentication / OAuthbreaking changeWill break existing deployments when updated without changesv2Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Decouple from Express: support other HTTP frameworks SDK V2

4 participants

@KKonstantinov@43081j@pcarleton@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v2] Decouple server from express and hono - http framework-agnostic MCP server - #1326

Merged
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server
Jan 16, 2026
Merged

[v2] Decouple server from express and hono - http framework-agnostic MCP server#1326
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server

Conversation

@KKonstantinov

@KKonstantinovKKonstantinov commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

v1 included express (and hono in recent version), forcing the dependency down to users. (express being >1MB along with middleware deps such as express-rate-limit etc.).

Achieving final & true implementation of #1299

This PR decouples @modelcontextprotocol/server from HTTP frameworks completely, and introduces three middleware packages: @modelcontextprotocol/node, @modelcontextprotocol/express, @modelcontextprotocol/hono.

The middleware packages are optional, and users could choose to use them or to map to the MCP SDK themselves and not using any of these plugins.

However, the @modelcontextprotocol/server is completely HTTP framework dependency-free.

Some additional changes:

  • Renamed StreamableHTTPServerTransport to NodeStreamableHTTPServerTransport
  • Added linting rule to avoid inline type imports (e.g. import { A, type B}). Prefer import type { B } and import { A } on separate lines.
  • Removed express dependency from @modelcontextprotocol/server completely
  • introduced @modelcontextprotocol/server-express and @modelcontextprotocol/server-hono - each having its own minimum dependencies
  • Removed sse transport for server (deprecated)
  • Removed server auth
  • Replaced examples for server auth with an OAuth library (e.g. better-auth)
  • Wrote up FAQ sections for removing SSE from server and removing auth from server
  • Tested better-auth server auth demo examples with @modelcontextprotocol/inspector
  • Updated express to 5.2.1 to get rid of CVE reported on 5.0.1 on the qs library (https://security.snyk.io/vuln/SNYK-JS-QS-14724253)
  • Updated existing docs, introduced new docs for middleware packages and general middleware doc

Motivation and Context

v2

How Has This Been Tested?

Unit tests

Breaking Changes

v2

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@changeset-bot

changeset-botBot commented Dec 20, 2025

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 7efc9ae

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Dec 20, 2025

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@1326

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@1326

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@1326

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@1326

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@1326

commit: 7efc9ae

@KKonstantinov
KKonstantinov marked this pull request as ready for review December 22, 2025 11:36
@KKonstantinov
KKonstantinov requested a review from a team as a code ownerDecember 22, 2025 11:36
@KKonstantinovKKonstantinov added breaking change Will break existing deployments when updated without changes auth Issues and PRs related to Authentication / OAuth v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes labels Dec 22, 2025
This was linked to issues Dec 22, 2025
Closed
@KKonstantinovKKonstantinov self-assigned this Dec 22, 2025
@KKonstantinovKKonstantinov added this to the v2 milestone Dec 22, 2025
@43081j

43081j commented Jan 9, 2026

Copy link
Copy Markdown

how are you calculating those sizes? they look too big to be the production install size, is it the size of your local server/node_modules including devDeps?

it might be worth including the production install size since that'll be what affects most people

a quick glance at it shows me the server is roughly ~9MB in main, and 6.5MB in your branch. huge saving!

Comment threadpackages/core/src/shared/protocol.ts Outdated
@43081j

Copy link
Copy Markdown

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auth pieces LGTM!

@KKonstantinov

KKonstantinov commented Jan 13, 2026

Copy link
Copy Markdown
ContributorAuthor

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

Nice catch, yes, all middlewares should have these in peers, including @modelcontextprotocol/server (which should be a peer dep and not baked into middlewares).

Comment thread.gitignore Outdated
pcarleton
pcarleton previously requested changes Jan 14, 2026

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry missed this earlier, but the PRM path needs to have the pathname after .well-known rather than before

Comment threadexamples/shared/src/authMiddleware.ts
felixweinberger
felixweinberger previously approved these changes Jan 15, 2026

@felixweinbergerfelixweinberger left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

Comment threadpackages/server/src/server/helper/body.ts Outdated
@KKonstantinov

Copy link
Copy Markdown
ContributorAuthor

Done!

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

@felixweinberger
felixweinberger dismissed pcarleton’s stale reviewJanuary 16, 2026 09:49

Dismissing @pcarleton's review as I believe his change request has been addressed

@KKonstantinov
KKonstantinov merged commit f495077 into modelcontextprotocol:mainJan 16, 2026
9 checks passed
mozmo15 pushed a commit to mozmo15/typescript-sdk that referenced this pull request Mar 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authIssues and PRs related to Authentication / OAuthbreaking changeWill break existing deployments when updated without changesv2Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Decouple from Express: support other HTTP frameworks SDK V2

4 participants

@KKonstantinov@43081j@pcarleton@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[v2] Decouple server from express and hono - http framework-agnostic MCP server - #1326

Merged
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server
Jan 16, 2026
Merged

[v2] Decouple server from express and hono - http framework-agnostic MCP server#1326
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server

Conversation

@KKonstantinov

@KKonstantinovKKonstantinov commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

v1 included express (and hono in recent version), forcing the dependency down to users. (express being >1MB along with middleware deps such as express-rate-limit etc.).

Achieving final & true implementation of #1299

This PR decouples @modelcontextprotocol/server from HTTP frameworks completely, and introduces three middleware packages: @modelcontextprotocol/node, @modelcontextprotocol/express, @modelcontextprotocol/hono.

The middleware packages are optional, and users could choose to use them or to map to the MCP SDK themselves and not using any of these plugins.

However, the @modelcontextprotocol/server is completely HTTP framework dependency-free.

Some additional changes:

  • Renamed StreamableHTTPServerTransport to NodeStreamableHTTPServerTransport
  • Added linting rule to avoid inline type imports (e.g. import { A, type B}). Prefer import type { B } and import { A } on separate lines.
  • Removed express dependency from @modelcontextprotocol/server completely
  • introduced @modelcontextprotocol/server-express and @modelcontextprotocol/server-hono - each having its own minimum dependencies
  • Removed sse transport for server (deprecated)
  • Removed server auth
  • Replaced examples for server auth with an OAuth library (e.g. better-auth)
  • Wrote up FAQ sections for removing SSE from server and removing auth from server
  • Tested better-auth server auth demo examples with @modelcontextprotocol/inspector
  • Updated express to 5.2.1 to get rid of CVE reported on 5.0.1 on the qs library (https://security.snyk.io/vuln/SNYK-JS-QS-14724253)
  • Updated existing docs, introduced new docs for middleware packages and general middleware doc

Motivation and Context

v2

How Has This Been Tested?

Unit tests

Breaking Changes

v2

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@changeset-bot

changeset-botBot commented Dec 20, 2025

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 7efc9ae

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Dec 20, 2025

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@1326

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@1326

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@1326

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@1326

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@1326

commit: 7efc9ae

@KKonstantinov
KKonstantinov marked this pull request as ready for review December 22, 2025 11:36
@KKonstantinov
KKonstantinov requested a review from a team as a code ownerDecember 22, 2025 11:36
@KKonstantinovKKonstantinov added breaking change Will break existing deployments when updated without changes auth Issues and PRs related to Authentication / OAuth v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes labels Dec 22, 2025
This was linked to issues Dec 22, 2025
Closed
@KKonstantinovKKonstantinov self-assigned this Dec 22, 2025
@KKonstantinovKKonstantinov added this to the v2 milestone Dec 22, 2025
@43081j

43081j commented Jan 9, 2026

Copy link
Copy Markdown

how are you calculating those sizes? they look too big to be the production install size, is it the size of your local server/node_modules including devDeps?

it might be worth including the production install size since that'll be what affects most people

a quick glance at it shows me the server is roughly ~9MB in main, and 6.5MB in your branch. huge saving!

Comment threadpackages/core/src/shared/protocol.ts Outdated
@43081j

Copy link
Copy Markdown

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auth pieces LGTM!

@KKonstantinov

KKonstantinov commented Jan 13, 2026

Copy link
Copy Markdown
ContributorAuthor

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

Nice catch, yes, all middlewares should have these in peers, including @modelcontextprotocol/server (which should be a peer dep and not baked into middlewares).

Comment thread.gitignore Outdated
pcarleton
pcarleton previously requested changes Jan 14, 2026

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry missed this earlier, but the PRM path needs to have the pathname after .well-known rather than before

Comment threadexamples/shared/src/authMiddleware.ts
felixweinberger
felixweinberger previously approved these changes Jan 15, 2026

@felixweinbergerfelixweinberger left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

Comment threadpackages/server/src/server/helper/body.ts Outdated
@KKonstantinov

Copy link
Copy Markdown
ContributorAuthor

Done!

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

@felixweinberger
felixweinberger dismissed pcarleton’s stale reviewJanuary 16, 2026 09:49

Dismissing @pcarleton's review as I believe his change request has been addressed

@KKonstantinov
KKonstantinov merged commit f495077 into modelcontextprotocol:mainJan 16, 2026
9 checks passed
mozmo15 pushed a commit to mozmo15/typescript-sdk that referenced this pull request Mar 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authIssues and PRs related to Authentication / OAuthbreaking changeWill break existing deployments when updated without changesv2Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Decouple from Express: support other HTTP frameworks SDK V2

4 participants

@KKonstantinov@43081j@pcarleton@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v2] Decouple server from express and hono - http framework-agnostic MCP server - #1326

Merged
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server
Jan 16, 2026
Merged

[v2] Decouple server from express and hono - http framework-agnostic MCP server#1326
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server

Conversation

@KKonstantinov

@KKonstantinovKKonstantinov commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

v1 included express (and hono in recent version), forcing the dependency down to users. (express being >1MB along with middleware deps such as express-rate-limit etc.).

Achieving final & true implementation of #1299

This PR decouples @modelcontextprotocol/server from HTTP frameworks completely, and introduces three middleware packages: @modelcontextprotocol/node, @modelcontextprotocol/express, @modelcontextprotocol/hono.

The middleware packages are optional, and users could choose to use them or to map to the MCP SDK themselves and not using any of these plugins.

However, the @modelcontextprotocol/server is completely HTTP framework dependency-free.

Some additional changes:

  • Renamed StreamableHTTPServerTransport to NodeStreamableHTTPServerTransport
  • Added linting rule to avoid inline type imports (e.g. import { A, type B}). Prefer import type { B } and import { A } on separate lines.
  • Removed express dependency from @modelcontextprotocol/server completely
  • introduced @modelcontextprotocol/server-express and @modelcontextprotocol/server-hono - each having its own minimum dependencies
  • Removed sse transport for server (deprecated)
  • Removed server auth
  • Replaced examples for server auth with an OAuth library (e.g. better-auth)
  • Wrote up FAQ sections for removing SSE from server and removing auth from server
  • Tested better-auth server auth demo examples with @modelcontextprotocol/inspector
  • Updated express to 5.2.1 to get rid of CVE reported on 5.0.1 on the qs library (https://security.snyk.io/vuln/SNYK-JS-QS-14724253)
  • Updated existing docs, introduced new docs for middleware packages and general middleware doc

Motivation and Context

v2

How Has This Been Tested?

Unit tests

Breaking Changes

v2

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@changeset-bot

changeset-botBot commented Dec 20, 2025

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 7efc9ae

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Dec 20, 2025

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@1326

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@1326

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@1326

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@1326

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@1326

commit: 7efc9ae

@KKonstantinov
KKonstantinov marked this pull request as ready for review December 22, 2025 11:36
@KKonstantinov
KKonstantinov requested a review from a team as a code ownerDecember 22, 2025 11:36
@KKonstantinovKKonstantinov added breaking change Will break existing deployments when updated without changes auth Issues and PRs related to Authentication / OAuth v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes labels Dec 22, 2025
This was linked to issues Dec 22, 2025
Closed
@KKonstantinovKKonstantinov self-assigned this Dec 22, 2025
@KKonstantinovKKonstantinov added this to the v2 milestone Dec 22, 2025
@43081j

43081j commented Jan 9, 2026

Copy link
Copy Markdown

how are you calculating those sizes? they look too big to be the production install size, is it the size of your local server/node_modules including devDeps?

it might be worth including the production install size since that'll be what affects most people

a quick glance at it shows me the server is roughly ~9MB in main, and 6.5MB in your branch. huge saving!

Comment threadpackages/core/src/shared/protocol.ts Outdated
@43081j

Copy link
Copy Markdown

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auth pieces LGTM!

@KKonstantinov

KKonstantinov commented Jan 13, 2026

Copy link
Copy Markdown
ContributorAuthor

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

Nice catch, yes, all middlewares should have these in peers, including @modelcontextprotocol/server (which should be a peer dep and not baked into middlewares).

Comment thread.gitignore Outdated
pcarleton
pcarleton previously requested changes Jan 14, 2026

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry missed this earlier, but the PRM path needs to have the pathname after .well-known rather than before

Comment threadexamples/shared/src/authMiddleware.ts
felixweinberger
felixweinberger previously approved these changes Jan 15, 2026

@felixweinbergerfelixweinberger left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

Comment threadpackages/server/src/server/helper/body.ts Outdated
@KKonstantinov

Copy link
Copy Markdown
ContributorAuthor

Done!

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

@felixweinberger
felixweinberger dismissed pcarleton’s stale reviewJanuary 16, 2026 09:49

Dismissing @pcarleton's review as I believe his change request has been addressed

@KKonstantinov
KKonstantinov merged commit f495077 into modelcontextprotocol:mainJan 16, 2026
9 checks passed
mozmo15 pushed a commit to mozmo15/typescript-sdk that referenced this pull request Mar 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authIssues and PRs related to Authentication / OAuthbreaking changeWill break existing deployments when updated without changesv2Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Decouple from Express: support other HTTP frameworks SDK V2

4 participants

@KKonstantinov@43081j@pcarleton@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v2] Decouple server from express and hono - http framework-agnostic MCP server - #1326

Merged
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server
Jan 16, 2026
Merged

[v2] Decouple server from express and hono - http framework-agnostic MCP server#1326
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server

Conversation

@KKonstantinov

@KKonstantinovKKonstantinov commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

v1 included express (and hono in recent version), forcing the dependency down to users. (express being >1MB along with middleware deps such as express-rate-limit etc.).

Achieving final & true implementation of #1299

This PR decouples @modelcontextprotocol/server from HTTP frameworks completely, and introduces three middleware packages: @modelcontextprotocol/node, @modelcontextprotocol/express, @modelcontextprotocol/hono.

The middleware packages are optional, and users could choose to use them or to map to the MCP SDK themselves and not using any of these plugins.

However, the @modelcontextprotocol/server is completely HTTP framework dependency-free.

Some additional changes:

  • Renamed StreamableHTTPServerTransport to NodeStreamableHTTPServerTransport
  • Added linting rule to avoid inline type imports (e.g. import { A, type B}). Prefer import type { B } and import { A } on separate lines.
  • Removed express dependency from @modelcontextprotocol/server completely
  • introduced @modelcontextprotocol/server-express and @modelcontextprotocol/server-hono - each having its own minimum dependencies
  • Removed sse transport for server (deprecated)
  • Removed server auth
  • Replaced examples for server auth with an OAuth library (e.g. better-auth)
  • Wrote up FAQ sections for removing SSE from server and removing auth from server
  • Tested better-auth server auth demo examples with @modelcontextprotocol/inspector
  • Updated express to 5.2.1 to get rid of CVE reported on 5.0.1 on the qs library (https://security.snyk.io/vuln/SNYK-JS-QS-14724253)
  • Updated existing docs, introduced new docs for middleware packages and general middleware doc

Motivation and Context

v2

How Has This Been Tested?

Unit tests

Breaking Changes

v2

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@changeset-bot

changeset-botBot commented Dec 20, 2025

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 7efc9ae

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Dec 20, 2025

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@1326

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@1326

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@1326

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@1326

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@1326

commit: 7efc9ae

@KKonstantinov
KKonstantinov marked this pull request as ready for review December 22, 2025 11:36
@KKonstantinov
KKonstantinov requested a review from a team as a code ownerDecember 22, 2025 11:36
@KKonstantinovKKonstantinov added breaking change Will break existing deployments when updated without changes auth Issues and PRs related to Authentication / OAuth v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes labels Dec 22, 2025
This was linked to issues Dec 22, 2025
Closed
@KKonstantinovKKonstantinov self-assigned this Dec 22, 2025
@KKonstantinovKKonstantinov added this to the v2 milestone Dec 22, 2025
@43081j

43081j commented Jan 9, 2026

Copy link
Copy Markdown

how are you calculating those sizes? they look too big to be the production install size, is it the size of your local server/node_modules including devDeps?

it might be worth including the production install size since that'll be what affects most people

a quick glance at it shows me the server is roughly ~9MB in main, and 6.5MB in your branch. huge saving!

Comment threadpackages/core/src/shared/protocol.ts Outdated
@43081j

Copy link
Copy Markdown

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auth pieces LGTM!

@KKonstantinov

KKonstantinov commented Jan 13, 2026

Copy link
Copy Markdown
ContributorAuthor

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

Nice catch, yes, all middlewares should have these in peers, including @modelcontextprotocol/server (which should be a peer dep and not baked into middlewares).

Comment thread.gitignore Outdated
pcarleton
pcarleton previously requested changes Jan 14, 2026

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry missed this earlier, but the PRM path needs to have the pathname after .well-known rather than before

Comment threadexamples/shared/src/authMiddleware.ts
felixweinberger
felixweinberger previously approved these changes Jan 15, 2026

@felixweinbergerfelixweinberger left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

Comment threadpackages/server/src/server/helper/body.ts Outdated
@KKonstantinov

Copy link
Copy Markdown
ContributorAuthor

Done!

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

@felixweinberger
felixweinberger dismissed pcarleton’s stale reviewJanuary 16, 2026 09:49

Dismissing @pcarleton's review as I believe his change request has been addressed

@KKonstantinov
KKonstantinov merged commit f495077 into modelcontextprotocol:mainJan 16, 2026
9 checks passed
mozmo15 pushed a commit to mozmo15/typescript-sdk that referenced this pull request Mar 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authIssues and PRs related to Authentication / OAuthbreaking changeWill break existing deployments when updated without changesv2Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Decouple from Express: support other HTTP frameworks SDK V2

4 participants

@KKonstantinov@43081j@pcarleton@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[v2] Decouple server from express and hono - http framework-agnostic MCP server - #1326

Merged
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server
Jan 16, 2026
Merged

[v2] Decouple server from express and hono - http framework-agnostic MCP server#1326
KKonstantinov merged 34 commits into
modelcontextprotocol:mainfrom
KKonstantinov:feature/v2-decouple-web-servers-from-server

Conversation

@KKonstantinov

@KKonstantinovKKonstantinov commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

v1 included express (and hono in recent version), forcing the dependency down to users. (express being >1MB along with middleware deps such as express-rate-limit etc.).

Achieving final & true implementation of #1299

This PR decouples @modelcontextprotocol/server from HTTP frameworks completely, and introduces three middleware packages: @modelcontextprotocol/node, @modelcontextprotocol/express, @modelcontextprotocol/hono.

The middleware packages are optional, and users could choose to use them or to map to the MCP SDK themselves and not using any of these plugins.

However, the @modelcontextprotocol/server is completely HTTP framework dependency-free.

Some additional changes:

  • Renamed StreamableHTTPServerTransport to NodeStreamableHTTPServerTransport
  • Added linting rule to avoid inline type imports (e.g. import { A, type B}). Prefer import type { B } and import { A } on separate lines.
  • Removed express dependency from @modelcontextprotocol/server completely
  • introduced @modelcontextprotocol/server-express and @modelcontextprotocol/server-hono - each having its own minimum dependencies
  • Removed sse transport for server (deprecated)
  • Removed server auth
  • Replaced examples for server auth with an OAuth library (e.g. better-auth)
  • Wrote up FAQ sections for removing SSE from server and removing auth from server
  • Tested better-auth server auth demo examples with @modelcontextprotocol/inspector
  • Updated express to 5.2.1 to get rid of CVE reported on 5.0.1 on the qs library (https://security.snyk.io/vuln/SNYK-JS-QS-14724253)
  • Updated existing docs, introduced new docs for middleware packages and general middleware doc

Motivation and Context

v2

How Has This Been Tested?

Unit tests

Breaking Changes

v2

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@changeset-bot

changeset-botBot commented Dec 20, 2025

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 7efc9ae

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Dec 20, 2025

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@1326

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@1326

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@1326

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@1326

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@1326

commit: 7efc9ae

@KKonstantinov
KKonstantinov marked this pull request as ready for review December 22, 2025 11:36
@KKonstantinov
KKonstantinov requested a review from a team as a code ownerDecember 22, 2025 11:36
@KKonstantinovKKonstantinov added breaking change Will break existing deployments when updated without changes auth Issues and PRs related to Authentication / OAuth v2 Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes labels Dec 22, 2025
This was linked to issues Dec 22, 2025
Closed
@KKonstantinovKKonstantinov self-assigned this Dec 22, 2025
@KKonstantinovKKonstantinov added this to the v2 milestone Dec 22, 2025
@43081j

43081j commented Jan 9, 2026

Copy link
Copy Markdown

how are you calculating those sizes? they look too big to be the production install size, is it the size of your local server/node_modules including devDeps?

it might be worth including the production install size since that'll be what affects most people

a quick glance at it shows me the server is roughly ~9MB in main, and 6.5MB in your branch. huge saving!

Comment threadpackages/core/src/shared/protocol.ts Outdated
@43081j

Copy link
Copy Markdown

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auth pieces LGTM!

@KKonstantinov

KKonstantinov commented Jan 13, 2026

Copy link
Copy Markdown
ContributorAuthor

I noticed the node middleware declares the server as a peer, but the other two declare it as a dependency.

should the three be consistent?

also - might it be a good idea to set hono and express as peers rather than dependencies? since these middlewares are meant to be used with them

Nice catch, yes, all middlewares should have these in peers, including @modelcontextprotocol/server (which should be a peer dep and not baked into middlewares).

Comment thread.gitignore Outdated
pcarleton
pcarleton previously requested changes Jan 14, 2026

@pcarletonpcarleton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry missed this earlier, but the PRM path needs to have the pathname after .well-known rather than before

Comment threadexamples/shared/src/authMiddleware.ts
felixweinberger
felixweinberger previously approved these changes Jan 15, 2026

@felixweinbergerfelixweinberger left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

Comment threadpackages/server/src/server/helper/body.ts Outdated
@KKonstantinov

Copy link
Copy Markdown
ContributorAuthor

Done!

Nice refactor! Looked through and this LGTM except for @pcarleton's point above which would be great to address.

@felixweinberger
felixweinberger dismissed pcarleton’s stale reviewJanuary 16, 2026 09:49

Dismissing @pcarleton's review as I believe his change request has been addressed

@KKonstantinov
KKonstantinov merged commit f495077 into modelcontextprotocol:mainJan 16, 2026
9 checks passed
mozmo15 pushed a commit to mozmo15/typescript-sdk that referenced this pull request Mar 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

authIssues and PRs related to Authentication / OAuthbreaking changeWill break existing deployments when updated without changesv2Ideas, requests and plans for v2 of the SDK which will incorporate major changes and fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Decouple from Express: support other HTTP frameworks SDK V2

4 participants

@KKonstantinov@43081j@pcarleton@felixweinberger