MCP DPoP + Scope-Challenge Upgrade (TypeScript SDK 2.1.0+)
Sender-constrained tokens and call-time permission checks on MCP TypeScript stacks
Operator recipe for upgrading MCP TypeScript stacks to sender-constrained tokens and call-time permission checks. Official MCP TypeScript SDK 2.1.0 ships packages @modelcontextprotocol/core, client, server, and node. DPoP sender-constrained tokens per SEP-1932 / RFC 9449: client OAuthClientProvider.dpop() with helpers generateDpopKeyPair, accessTokenHash, isDpopNonceChallenge, and automatic nonce retry on use_dpop_nonce. Server side: scopeChallenge on tool/resource/prompt registration, requireScopes helper, HTTP 403 + WWW-Authenticate before the handler runs, and resourceMetadataUrl on AuthInfo. Legacy @modelcontextprotocol/sdk 1.30.1 adds request body size limits and JSON-RPC batch bounds. Spec does not mandate DPoP yet — decide authorization-server DPoP support now vs later; do not equate a valid token with permission for a specific tool; put destructive tools behind call-time scope challenges. As of 7 Oct 2026 the current v2 line is 2.3.1 and the legacy @modelcontextprotocol/sdk line is 1.32.1 (npm), so pin to a version at or above the one that introduced the feature you rely on. Primary: https://workos.com/blog/mcp-sdk-dpop-and-scope-challenges.
Core Workflows (4)
Each workflow represents a critical business function. Click any workflow to see detailed automation architecture.
Upgrade to MCP TypeScript SDK 2.1.0+
Led by: SDK OperatorOfficial MCP TypeScript SDK 2.1.0 ships packages @modelcontextprotocol/core, client, server, and node. As of 7 Oct 2026 the current v2 line is 2.3.1 and the legacy @modelcontextprotocol/sdk line is 1.32.1 (npm), so pin to a version at or above the one that introduced the feature you rely on. Legacy @modelcontextprotocol/sdk 1.30.1 adds request body size limits and JSON-RPC batch bounds.
Enable DPoP on the client
Led by: Client OperatorDPoP sender-constrained tokens per SEP-1932 / RFC 9449: client OAuthClientProvider.dpop() with helpers generateDpopKeyPair, accessTokenHash, isDpopNonceChallenge, and automatic nonce retry on use_dpop_nonce. Spec does not mandate DPoP yet — decide authorization-server DPoP support now vs later.
Add scopeChallenge on tool, resource, and prompt registration
Led by: Server OperatorServer side: scopeChallenge on tool/resource/prompt registration, requireScopes helper, HTTP 403 + WWW-Authenticate before the handler runs, and resourceMetadataUrl on AuthInfo.
Do not equate a valid token with tool permission
Led by: Server OperatorDo not equate a valid token with permission for a specific tool. Put destructive tools behind call-time scope challenges.