Skip to content

ci(deps): update dependency mcp to v2 - #1184

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-python-deps
Open

ci(deps): update dependency mcp to v2#1184
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-python-deps

Conversation

@renovate

@renovate renovate Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
mcp >=1.9,<2>=2,<3 age adoption passing confidence

Release Notes

modelcontextprotocol/python-sdk (mcp)

v2.0.0

Compare Source

MCP Python SDK v2 Stable Release

This is v2.0.0, the stable v2 release of the MCP Python SDK. It supports the 2026-07-28 revision of the Model Context Protocol and serves every earlier revision from the same server. pip install mcp now installs 2.x.

pip install "mcp[cli]"

# or
uv add "mcp[cli]"
Documentation Rewrite

The documentation has the full tutorial and API reference. Coming from v1? What's new in v2 is the tour of what changed and why, and the migration guide lists every breaking change with before-and-after code.

V1 Maintenance mode

v1.x is in maintenance mode and will only receive security fixes from now on The 1.x line lives on the v1.x branch, continues to receive critical bug fixes and security patches, and is documented at https://py.sdk.modelcontextprotocol.io/v1/. If your project is not ready to migrate, keep a <2 upper bound on your requirement (for example mcp>=1.28,<2).

Highlights

One SDK, both protocol eras

v2 speaks the 2026-07-28 revision (stateless requests with no handshake, server/discover, subscriptions/listen, multi-round-trip requests) and still serves every 2025-era client from the same MCPServer, over Streamable HTTP and stdio, with nothing to configure. Client(target) negotiates the version automatically.

FastMCP is now MCPServer, and there is a first-class Client

The decorator API is unchanged; the low-level Server is rebuilt around a shared dispatcher engine, and one Client object replaces v1's transport-plus-ClientSession-plus-initialize() layering. It connects to a URL, a stdio subprocess, a custom transport, or straight to a server object in memory for tests.

Multi-round-trip requests and resolver dependency injection

At 2026-07-28 the server can no longer call the client, so tools return the question instead. A Resolve(fn) parameter is filled by your function invisibly to the model and can put a question to the user; one tool body serves both eras.

Extension APIs, OpenTelemetry, and a standalone types package

Servers and clients compose protocol extensions through pluggable extension APIs (MCP Apps built in); OpenTelemetry tracing ships on by default; every protocol type is its own package, mcp-types (imported as mcp_types), published in lock-step with mcp.

Hardened stdio and auth

stdio servers keep handler subprocesses and stray prints off the wire, and stdout is diverted to stderr while serving. OAuth adds RFC 9207 issuer validation, the SEP-990 identity-assertion flow, and the client-credentials extension.

Coming from a v2 pre-release

Since the last release candidate: the per-version wire packages are private (mcp_types._v*), mcp.types is a permanent alias for mcp_types, the auth registration request model is split from the registered-client record, cancelled requests are no longer answered, and log notifications are gated on the per-request log-level opt-in at 2026-07-28. Since the betas: Client(cache=False) is now cache=None with CacheConfig() the default; Context.client_id, RFC7523OAuthClientProvider, and OAuthClientProvider(timeout=) are removed; the client-credentials providers take scope=; message_handler receives notifications and exceptions only; FileResource(is_binary=) becomes encoding; MCP_* env vars are gone with pydantic-settings; Streamable HTTP servers reject bodies over 4 MiB with HTTP 413. The migration guide covers all of it.

Known gaps

The tasks extension (SEP-2663) is not part of this release. On the client, the DPoP proof binding (SEP-1932) and the workload-identity jwt-bearer grant are not implemented; both are additive and can land in 2.x.

Feedback

Something rough, confusing, or broken? Open an issue or find us in #python-sdk-dev on the MCP Contributors Discord.

Full Changelog: modelcontextprotocol/python-sdk@v2.0.0rc1...v2.0.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/major-python-deps branch from eefb2c2 to 58286ed Compare August 6, 2026 12:00
@deadlock1bot

Copy link
Copy Markdown

Clean rebase detected — no code changes compared to previous head (eefb2c2).

@rnetser

rnetser commented Aug 9, 2026

Copy link
Copy Markdown
Collaborator

/approve
/lgtm

Comment thread pyproject.toml

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tests to Run

The following tests should be run to verify this PR:

Critical (directly affected)

  • webhook_server/tests/test_app.py::TestLifespan::test_lifespan_mcp_init — Tests MCP initialization in app lifespan, which imports and uses mcp.server.streamable_http_manager.StreamableHTTPSessionManager — the mcp v1->v2 major upgrade could change this class's API or location (High confidence)

Standard (regression safety)

  • webhook_server/tests/test_logging_separation.py::test_mcp_logging_configuration — Tests MCP logger configuration and handler setup; mcp v2 may change logger names or logging behavior referenced in the test (Medium confidence)
  • webhook_server/tests/test_logging_separation.py::test_mcp_logger_without_hook_id_is_noise — Tests filtering of mcp.server.streamable_http logger — logger name may change in mcp v2 (Medium confidence)
  • webhook_server/tests/test_logging_separation.py::test_mcp_server_log_without_hook_id_is_noise — Tests filtering of mcp_server.log infrastructure logger — mcp v2 may alter logging patterns (Medium confidence)
  • webhook_server/tests/test_logging_separation.py::test_infra_logger_with_hook_id_is_not_noise — Tests that MCP infrastructure loggers with hook_id are preserved — verifies MCP logger name constants still valid after v2 upgrade (Medium confidence)

Summary

  • 2 test files recommended (1 critical, 4 standard)
  • AI Provider: Claude (claude-opus-4-6[1m])

@myakove-bot1

Copy link
Copy Markdown

Clean rebase detected — no code changes compared to previous head (58286ed).
The following labels were preserved: approved-rnetser, lgtm-rnetser, commented-myakove-bot.

@myakove

myakove commented Aug 10, 2026

Copy link
Copy Markdown
Collaborator

/approve
/lgtm

Comment thread pyproject.toml

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tests to Run

The following tests should be run to verify this PR:

Critical (directly affected)

  • webhook_server/tests/test_app.py::TestLifespan::test_lifespan_mcp_init — Tests MCP initialization in app lifespan, which imports from mcp.server.streamable_http_manager — the mcp v1→v2 major upgrade may change this module's API (High confidence)
  • webhook_server/tests/test_app.py — app.py imports mcp and fastapi_mcp; the full test suite for app.py should run to catch any breakage from the mcp v2 upgrade affecting app startup, routing, or error handling (High confidence)

Standard (regression safety)

  • webhook_server/tests/test_logging_separation.py — Tests MCP logging configuration and mcp.server.streamable_http logger filtering — mcp v2 may change logger names or logging behavior (Medium confidence)

Summary

  • 2 test files recommended (2 critical, 1 standard)
  • AI Provider: Claude (claude-opus-4-6[1m])

@rnetser

rnetser commented Aug 10, 2026

Copy link
Copy Markdown
Collaborator

/approve
/lgtm

@myakove-bot

Copy link
Copy Markdown
Collaborator

Test Oracle server is not responding, skipping test analysis

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants