---
summary: "@cyanheads/mcp-ts-core ^0.9.6 → ^0.9.13: 413 body cap, HTTP session-init gate, quieter client-error logging, GET /mcp surfaces keywords; dep refresh; package.json keyword additions"
breaking: false
security: false
---

# 0.5.6 — 2026-05-28

## Changed

- **`@cyanheads/mcp-ts-core` ^0.9.6 → ^0.9.13** — framework adoption covering:
  - **`MCP_HTTP_MAX_BODY_BYTES`** — configurable inbound body cap (default 1 MiB); oversized requests rejected with HTTP 413 before session allocation or body parsing.
  - **HTTP session-init gate** — stateful HTTP mode rejects non-`initialize` requests that arrive without an `Mcp-Session-Id` header with HTTP 400, preventing uninitialized sessions from being minted on first contact.
  - **Quieter client-error logging** — expected 401, 403, 400, and 404 responses now logged at `warning` instead of full error-pipeline with stack traces.
  - **`GET /mcp` keywords** — `package.json` `keywords` now included in the status JSON alongside `name`, `version`, and `description`.
- **`src/index.ts`** — `landing: { requireAuth: false }` added; restores full tool-inventory visibility on the landing page for this public-catalog deployment (framework 0.9.13 default gates inventory behind auth when `MCP_AUTH_MODE` is `jwt` or `oauth`).
- **`manifest.json`** — `repository`, `homepage`, and `license` fields added.
- **`package.json` keywords** — `typescript`, `bun`, `stdio`, `streamable-http` added.
- **Skill sync** — `git-wrapup`, `code-simplifier` skills added; `migrate-mcp-ts-template` removed; bulk refresh across field-test, maintenance, polish-docs-meta, design-mcp-server, api-canvas, api-config, release-and-publish, report-issue-framework.

## Dependencies

- `@cyanheads/mcp-ts-core` ^0.9.6 → ^0.9.13
- `hono` ^4.12.22 → ^4.12.23
- `@biomejs/biome` ^2.4.15 → ^2.4.16
