← Back to Playbooks
Agent Operations

MCP DPoP + Scope-Challenge Upgrade (TypeScript SDK 2.1.0+)

Sender-constrained tokens and call-time permission checks on MCP TypeScript stacks

Operator recipe for upgrading MCP TypeScript stacks to sender-constrained tokens and call-time permission checks. Official MCP TypeScript SDK 2.1.0 ships packages @modelcontextprotocol/core, client, server, and node. DPoP sender-constrained tokens per SEP-1932 / RFC 9449: client OAuthClientProvider.dpop() with helpers generateDpopKeyPair, accessTokenHash, isDpopNonceChallenge, and automatic nonce retry on use_dpop_nonce. Server side: scopeChallenge on tool/resource/prompt registration, requireScopes helper, HTTP 403 + WWW-Authenticate before the handler runs, and resourceMetadataUrl on AuthInfo. Legacy @modelcontextprotocol/sdk 1.30.1 adds request body size limits and JSON-RPC batch bounds. Spec does not mandate DPoP yet — decide authorization-server DPoP support now vs later; do not equate a valid token with permission for a specific tool; put destructive tools behind call-time scope challenges. As of 7 Oct 2026 the current v2 line is 2.3.1 and the legacy @modelcontextprotocol/sdk line is 1.32.1 (npm), so pin to a version at or above the one that introduced the feature you rely on. Primary: https://workos.com/blog/mcp-sdk-dpop-and-scope-challenges.

Core Workflows (4)

Each workflow represents a critical business function. Click any workflow to see detailed automation architecture.

01

Upgrade to MCP TypeScript SDK 2.1.0+

Led by: SDK Operator

Official MCP TypeScript SDK 2.1.0 ships packages @modelcontextprotocol/core, client, server, and node. As of 7 Oct 2026 the current v2 line is 2.3.1 and the legacy @modelcontextprotocol/sdk line is 1.32.1 (npm), so pin to a version at or above the one that introduced the feature you rely on. Legacy @modelcontextprotocol/sdk 1.30.1 adds request body size limits and JSON-RPC batch bounds.

Sub-Agents
Server OperatorClient Operator
Skills Required
@modelcontextprotocol/core@modelcontextprotocol/sdk
Human TouchpointPin v2 at or above 2.1.0 for DPoP / scopeChallenge; pin legacy at or above 1.30.1 for body and batch bounds
02

Enable DPoP on the client

Led by: Client Operator

DPoP sender-constrained tokens per SEP-1932 / RFC 9449: client OAuthClientProvider.dpop() with helpers generateDpopKeyPair, accessTokenHash, isDpopNonceChallenge, and automatic nonce retry on use_dpop_nonce. Spec does not mandate DPoP yet — decide authorization-server DPoP support now vs later.

Sub-Agents
Authorization Server
Skills Required
DPoPSEP-1932RFC 9449
Human TouchpointDecide authorization-server DPoP support now vs later; the spec does not mandate DPoP yet
03

Add scopeChallenge on tool, resource, and prompt registration

Led by: Server Operator

Server side: scopeChallenge on tool/resource/prompt registration, requireScopes helper, HTTP 403 + WWW-Authenticate before the handler runs, and resourceMetadataUrl on AuthInfo.

Sub-Agents
SDK Operator
Skills Required
scopeChallengerequireScopes
Human TouchpointConfirm 403 + WWW-Authenticate fires before the handler when required scopes are missing
04

Do not equate a valid token with tool permission

Led by: Server Operator

Do not equate a valid token with permission for a specific tool. Put destructive tools behind call-time scope challenges.

Sub-Agents
Client Operator
Skills Required
Call-time scope challenges
Human TouchpointPut destructive tools behind call-time scope challenges; a valid token is not enough