---
summary: "mcp-ts-core ^0.9.13: HTTP 413 body cap, session-init gate, quieter auth error logging, GET /mcp keywords; ValidationError reclassifications for pagination cap and invalid taxon key"
breaking: false
security: false
---

# 0.2.2 — 2026-05-28

## Changed

- **`gbif_search_occurrences` `pagination_cap_exceeded`** — error code reclassified from `InternalError` to `ValidationError` (JSON-RPC -32602). The pagination cap (offset + limit > 100,000) is a client-supplied constraint violation, not a server fault; clients observing the error code should update accordingly.
- **`gbif://species/{taxonKey}` invalid key** — error reclassified from `NotFound` to `ValidationError`. A non-numeric `taxonKey` is a malformed input, not a missing resource.
- **`@cyanheads/mcp-ts-core`** `^0.9.9` → `^0.9.13`:
  - **`MCP_HTTP_MAX_BODY_BYTES`** (default 1 MiB) — oversized inbound requests are rejected with HTTP 413 before the body is buffered, before the SDK parses, and before a per-request server is allocated. Set to `0` to disable.
  - **HTTP session-init gate** — stateful HTTP mode rejects non-`initialize` requests without an `Mcp-Session-Id` header with HTTP 400, preventing uninitialized sessions from being minted on first contact.
  - **Quieter auth error logging** — 401, 403, 400, and 404 HTTP errors now log at `warning` instead of going through the full `ErrorHandler` pipeline with stack traces.
  - **`GET /mcp` keywords** — `package.json` `keywords` now surfaced in the status JSON alongside `name`, `version`, and `description`. Overrideable via `PACKAGE_KEYWORDS` env var (comma-separated).
  - **`landing.requireAuth`** — landing page inventory now gated behind auth by default when `MCP_AUTH_MODE` is `jwt` or `oauth`; this server sets `landing: { requireAuth: false }` to serve the full public catalog regardless.

## Dependencies

- `@cyanheads/mcp-ts-core` ^0.9.9 → ^0.9.13
- `@biomejs/biome` ^2.4.15 → ^2.4.16
