---
summary: "mcp-ts-core ^0.13.6: canvas_id is validated as a minted token at the argument level, tool errors close with a reason/retryable suffix, and Socrata HTTP errors drop the request URL from client-facing data. The dev skill tree moves to framework-skills/."
breaking: false
security: false
---

# 0.1.16 — 2026-09-20

## Changed

- **`canvas_id` is validated as a minted token at argument validation** — `socrata_query_dataset`, `socrata_dataframe_describe`, and `socrata_dataframe_query` now declare it with the framework's `CanvasIdSchema`. A blank or malformed value is an argument rejection (`InvalidParams`), never a canvas lookup.
- **Tool error text closes with a reason/retryable suffix** — `(reason <reason> · not retryable)` when `data.reason` or `data.retryable` is set, so a caller can branch on the tail of the message as well as the structured `data`.
- **Argument rejections classify as `InvalidParams`, with a recovery hint and a `reason`** — an unknown key, wrong type, or missing field returns `data.reason: "invalid_arguments"` and a `Recovery:` hint derived from the schema, in place of a bare validation error.
- **HTTP session posture is declared in source** — `createApp({ sessionMode: 'stateless' })`, matching that no handler gates on `ctx.requestInput`, instead of relying on `MCP_SESSION_MODE` being set in the deployment environment.

## Security

- **The upstream Socrata request URL no longer appears in client-facing error data** — only the host does. A SODA URL can carry the caller's SoQL in its query string.

## Dependencies

- `@cyanheads/mcp-ts-core` `^0.12.3` → `^0.13.6`
- `@duckdb/node-api` `^1.5.5-r.4` → `^1.5.5-r.5`
- `zod` `^4.4.3` → `^4.6.5`
- Dev: `@biomejs/biome` `^2.5.9` → `^2.5.14`, `@types/node` `^26.2.0` → `^26.6.1`, `ignore` `^7.0.6` → `^7.0.9`, `tsc-alias` `^1.9.2` → `^1.9.5`
- Bun engines floor raised to `>=1.4.0`
