---
summary: "@cyanheads/mcp-ts-core ^0.9.7 → ^0.9.13; HTTP 413 body cap, session-init gate, quieter 401/403/400/404 logging, GET /mcp surfaces keywords; dep refresh; landing requireAuth fix"
breaking: false
security: false
---

# 0.1.4 — 2026-05-28

## Added

- **`MCP_HTTP_MAX_BODY_BYTES`** — configurable inbound request-body cap on the HTTP MCP endpoint (default 1 MiB); oversized requests rejected with `413` before the SDK parses the body. Documented in `.env.example`. (via `@cyanheads/mcp-ts-core` 0.9.13)
- **`GET /mcp` keywords** — `package.json` `keywords` now surfaced on the HTTP status response alongside name, version, and description. (via `@cyanheads/mcp-ts-core` 0.9.12)

## Changed

- **`landing.requireAuth: false`** set in `createApp()` — ensures the full tool/resource/prompt inventory is served without an auth gate on this public hosted instance, overriding the new secure-by-default behavior from `@cyanheads/mcp-ts-core` 0.9.13.
- **HTTP session-init gate** — stateful HTTP mode now rejects non-`initialize` requests without `Mcp-Session-Id` with `400`, preventing uninitialized sessions from being minted on first contact. (via `@cyanheads/mcp-ts-core` 0.9.10)
- **`httpErrorHandler` log levels** — expected client errors (`401`, `403`, `400`, `404`) use `logger.warning` instead of the full error pipeline with stack traces, reducing noise in production logs. (via `@cyanheads/mcp-ts-core` 0.9.10)

## Dependencies

- `@cyanheads/mcp-ts-core` ^0.9.7 → ^0.9.13
- `@biomejs/biome` ^2.4.7 → ^2.4.16
- `@types/node` ^25.6.0 → ^25.9.1
- `tsc-alias` ^1.8.16 → ^1.8.17
- `typescript` ^5.9.3 → ^6.0.3
- `vitest` ^4.1.0 → ^4.1.7
