---
summary: "mcp-ts-core ^0.9.13: HTTP body cap (413), session-init gate, quieter client-error logging, GET /mcp keywords; manifest user_config wiring; error code alignment"
breaking: false
security: false
---

# 0.1.6 — 2026-05-28

## Changed

- **`@cyanheads/mcp-ts-core`** `^0.9.9` → `^0.9.13` — picks up four releases:
  - **HTTP body cap** — inbound requests over 1 MiB rejected with `413` before SDK parsing (`MCP_HTTP_MAX_BODY_BYTES`, default 1 MiB; set to `0` to disable).
  - **Session-init gate** — stateful HTTP mode now rejects non-`initialize` requests that arrive without an `Mcp-Session-Id` header with HTTP `400`.
  - **Quieter client-error logging** — `401`, `403`, `400`, `404` responses now use `logger.warning` instead of the full error pipeline with stack traces.
  - **`GET /mcp` keywords** — `package.json` `keywords` surfaced on the HTTP status endpoint alongside name, version, and description.
- **`manifest.json` `user_config`** — `CENSUS_API_KEY` now wired into `mcp_config.env` as `${user_config.CENSUS_API_KEY}` and given `"default": ""` for optional field safety in MCPB bundle installs.
- **Error codes** — `InvalidParams` replaced with `ValidationError` on `census_query_data`, `census_list_geographies`, `census_resolve_geography`, and `census_compare_geographies` tool error contracts; `invalidParams()` factory call replaced with `validationError()`.
- **`src/index.ts`** — `landing: { requireAuth: false }` set to serve the full tool/resource/prompt inventory without authentication (this server uses `MCP_AUTH_MODE=none` by default; the flag is a forward-compatibility guard).
- **`package.json` keywords** — `"typescript"` added.
- **Dependency bumps:**
  - `@biomejs/biome` ^2.4.7 → ^2.4.16
  - `@types/node` ^25.6.0 → ^25.9.1
  - `tsc-alias` ^1.8.16 → ^1.8.17
  - `typescript` ^5.9.3 → ^6.0.3
  - `vitest` ^4.1.0 → ^4.1.7
