---
summary: "mcp-ts-core ^0.9.6 → ^0.9.13: body limit guard, session-init gate, quieter client-error logs, GET /mcp keywords; dep refresh"
breaking: false
security: false
---

# 0.6.15 — 2026-05-28

## Added

- **`landing.requireAuth: false`** set explicitly in `src/index.ts` to preserve the full landing-page inventory on the hosted HTTP endpoint (framework default changed in mcp-ts-core 0.9.13).

## Changed

- **`@cyanheads/mcp-ts-core`** ^0.9.6 → ^0.9.13. User-facing changes adopted:
  - **`MCP_HTTP_MAX_BODY_BYTES`** — inbound HTTP request-body cap (default 1 MiB); oversized requests rejected with `413` before the SDK parses the body.
  - **HTTP session-init gate** — stateful HTTP mode now rejects non-`initialize` requests that arrive without `Mcp-Session-Id` with HTTP 400.
  - **Client error log levels** — 401/403/400/404 responses now use `warning`-level logging rather than full error pipeline; reduces noise in production logs.
  - **`GET /mcp` keywords** — `package.json` `keywords` surfaced on the HTTP status JSON alongside `name`, `version`, and `description`.
- **`package.json` keywords** — `bun`, `stdio`, `streamable-http` added; picked up by `GET /mcp` keywords surface.
- **`@biomejs/biome`** ^2.4.15 → ^2.4.16.
