---
summary: "mcp-ts-core ^0.9.7 → ^0.9.13: HTTP body cap (413), session-init gate, quieter 401/403/400/404 logs, GET /mcp keywords; error-code reclassifications; dep refresh"
breaking: false
security: false
---

# 0.1.4 — 2026-05-28

## Changed

- **`canvas_not_found` error code** — reclassified from `InvalidParams` to `NotFound` on `socrata_dataframe_describe` and `socrata_dataframe_query`. More accurate: the canvas ID is well-formed but the canvas doesn't exist.
- **`sql_rejected` error code** — reclassified from `InvalidParams` to `ValidationError` on `socrata_dataframe_query`. Aligns with the framework's semantic intent for rejected-query errors.
- **`invalid_id` error code** — reclassified from `InvalidParams` to `ValidationError` on `socrata_get_dataset` and `socrata_query_dataset`. Consistent with pattern-validation errors across the surface.
- **`landing.requireAuth: false`** — explicitly set in `createApp()` so the full tool/resource/prompt inventory is served to unauthenticated callers on HTTP even when `MCP_AUTH_MODE` is jwt or oauth; aligns with the public-catalog posture of this server.
- **`package.json` keywords** — `"llm"` removed; already covered by `"ai"`.
- **`@cyanheads/mcp-ts-core`** ^0.9.7 → ^0.9.13 — framework adoption. User-facing changes picked up:
  - **`MCP_HTTP_MAX_BODY_BYTES`** — configurable inbound request-body cap (default 1 MiB); oversized bodies rejected with 413 before allocation.
  - **HTTP session-init gate** — stateful HTTP mode rejects non-`initialize` requests without `Mcp-Session-Id` with 400.
  - **Quieter 401/403/400/404 logs** — expected client errors use `logger.warning` instead of the full `ErrorHandler` pipeline; stack traces no longer emitted for auth or not-found responses.
  - **`GET /mcp` keywords** — `package.json` keywords now surfaced alongside `name`, `version`, and `description` on the status endpoint.
- **Dependency bumps:**
  - `@biomejs/biome` ^2.4.7 → ^2.4.16
  - `@types/node` ^25.6.0 → ^25.9.1
  - `tsc-alias` ^1.8.16 → ^1.8.17
  - `typescript` ^5.9.3 → ^6.0.3
  - `vitest` ^4.1.0 → ^4.1.7
