NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #1275 most downloaded on NuGet
.NET SDK for the Model Context Protocol (MCP) with hosting and dependency injection extensions.
Last release 1 months ago
13 Aug 2026
Ships fairly regularly
a new release about every 3 weeks
Some releases are documented
notes for 5 of 9 stable releases
Nothing withdrawn
no release was ever pulled
7 months old
9 releases · first in 2026
One column per month.
This release adds hybrid stateful/stateless HTTP serving so clients using the 2025-11-25 and 2026-07-28 protocol revisions can share an endpoint, and
This release adds hybrid stateful/stateless HTTP serving so clients using the 2025-11-25 and 2026-07-28 protocol revisions can share an endpoint, and fixes a malformed header-decoding edge case.
Full Changelog: v2.1.0...v2.2.0
Note
These release notes were drafted with GitHub Copilot and reviewed before publishing.
This release adds an opt-in subscriptions/listen handler for custom server-side notification streams, improves HTTP transport fallback reliability, an
This release adds an opt-in subscriptions/listen handler for custom server-side notification streams, improves HTTP transport fallback reliability, and expands guidance and samples for telemetry and binary resources.
> [!NOTE] alert example #1771 by @PranavSenthilnathan (co-authored by @Copilot)Full Changelog: v2.0.0...v2.1.0
Deprecate Roots, Sampling, and Logging APIs #1651
Version 2.0.0 brings the C# SDK into stable alignment with the MCP 2026-07-28 specification.
This major release introduces discovery-first negotiation, multi-round-trip requests, stateless-by-default HTTP, caching hints, standardized headers, stronger OAuth and token-cache safety, and dedicated MCP Apps and Tasks extension packages, with down-level interoperability for peers negotiating 2025-11-25 and earlier. Review the migration guidance below.
Refer to the C# SDK Versioning documentation for details on versioning and breaking-change policies.
HttpServerTransportOptions.Stateless now defaults to true. Stateless servers do not create transport sessions, expose the standalone SSE GET/DELETE endpoints, or support unsolicited server-to-client requests.Stateless = false when an existing server requires legacy stateful behavior. Stateful-only options now produce MCP9006 warnings and apply only to down-level initialize-handshake connections.server/discover first and automatically fall back to the legacy initialize handshake for down-level servers.MCP9005 warnings because these features are deprecated by the 2026-07-28 specification.MCP9005 temporarily if continued use is required while planning migration.ModelContextProtocol.Extensions.Tasks #1693
ModelContextProtocol.Extensions.Tasks, import its namespace, register Tasks with WithTasks(...), and replace Core RequestMethods.Tasks* constants with TasksProtocol members.AuthorizationRedirectDelegate and ClientOAuthOptions.AuthorizationRedirectDelegate now produce MCP9007 warnings. Migrate to ClientOAuthOptions.AuthorizationCallbackHandler so callbacks can return the authorization code, state, and issuer.UseStructuredContent = true and a non-object return type now emit the raw value and matching schema, such as structuredContent: 72, instead of wrapping it as { "result": 72 }.result property.Tool.inputSchema during deserialization #1600
Tool payload without inputSchema now throws JsonException instead of silently defaulting the schema.inputSchema; an empty {} is sufficient.S256 in code_challenge_methods_supported.application_type during dynamic client registration #1613
application_type.DynamicClientRegistrationOptions.ApplicationType explicitly when the inferred value is not appropriate.HttpRequestException, TimeoutException, or genuine I/O exception instead of always wrapping failures in IOException.IOException("Failed to connect transport.") wrapper. In AutoDetect mode, inspect the outer HttpRequestException and its inner SSE failure.insufficient_scope challenge that introduces no new scopes now throws McpException instead of retrying indefinitely.InheritEnvironmentVariables to StdioClientTransportOptions #1563 by @halter73offline_access to authorization scope when advertised (SEP-2207) #1479 by @stephentoub (co-authored by @Copilot)McpErrorCode.ResourceNotFound per SEP-2164 #1558 by @jayaraman-venkatesanMcpClient tool cache #1590 by @tarekghScopeSelectorDelegate to OAuth options #1596 by @hallloMinVersionForStandardHeaders to DraftProtocolVersion #1603 by @halter73x-mcp-header behavior with SEP-2243 clarifications #1619 by @tarekgh$ref pointer resolution after output-schema wrapping #1435 by @weinongMcpClientOptions.InitializeMeta #1599 by @adityasingh2400charset=utf-8 from HTTP application/json content types #1528 by @jayaraman-venkatesaninputSchema during deserialization #1600 by @DragonFSKYTimeToLive instead of TtlMs in public APIs #1644 by @PranavSenthilnathan (co-authored by @halter73 @Copilot)DeferChangedEvents() for batched primitive-change notifications #1689 by @jeffhandley (co-authored by @Copilot)complete result discriminator #1684 by @PranavSenthilnathan (co-authored by @Copilot @tarekgh)ModelContextProtocol.Extensions.Tasks #1693 by @jeffhandley (co-authored by @Copilot @tarekgh)application_type to dynamic client registration #1613 by @jayaraman-venkatesanClientOAuthProvider #1605 by @mikekistlerClientOAuthProvider client ID availability on cold start #1705 by @halter73 (co-authored by @Copilot)AddIncomingMessageFilter_Multiple_Filters_Execute_In_Order test #1627 by @tarekghReadEventsAsync_InStreamingMode_YieldsNewlyWrittenEvents #1491 by @ericstj (co-authored by @Copilot)DiagnosticTests.Session_TracksActivities #1495 by @ericstj (co-authored by @Copilot)http-custom-headers conformance scenario #1691 by @tarekgh_meta.ui serialization round-trip tests #1698 by @yayayouyou (co-authored by @jeffhandley)Tool.Execution reference from the main build #1660 by @halter73Note truncated.
This release backports a memory-leak fix for HTTP/SSE-based MCP servers. StreamableHttpServerTransport now releases its Server-Sent Events response st
This release backports a memory-leak fix for HTTP/SSE-based MCP servers. StreamableHttpServerTransport now releases its Server-Sent Events response stream reference as soon as a GET request ends, instead of holding it until the session is disposed via explicit DELETE or idle timeout. Long-lived SSE clients that disconnect without sending DELETE no longer pin the underlying Kestrel connection and its associated memory-pool buffers (~20 MiB per session), preventing the sustained memory growth that could accumulate under connect/disconnect churn.
Full Changelog: v1.4.0...v1.4.1
v1.4.0 introduces support for the Identity Assertion Authorization Grant (ID-JAG) flow via the new IdentityAssertionGrantProvider , enabling enterpris
v1.4.0 introduces support for the Identity Assertion Authorization Grant (ID-JAG) flow via the new IdentityAssertionGrantProvider, enabling enterprise SSO scenarios where users authenticate once via their enterprise Identity Provider and access MCP servers without per-server authorization prompts. The release also adds a new InheritEnvironmentVariables option on StdioClientTransportOptions for controlling the child server's environment, alongside two security hardening fixes: the stdio client transport no longer enumerates child-process environment variables in Trace logs, and DELETE on a Streamable HTTP session now requires the same authenticated user that initiated the session.
InheritEnvironmentVariables to StdioClientTransportOptions #1563 by @halter73 (co-authored by @Copilot)HandleDeleteRequestAsync now mirrors the HasSameUserId check already enforced on GET and POST. A DELETE with a valid Mcp-Session-Id but a different authenticated user now returns 403 Forbidden instead of terminating the session — defense-in-depth against a leaked session ID being used to DoS the original owner.IdentityAssertionGrantProvider and supporting option/response types in ModelContextProtocol.Authentication implementing the Identity Assertion Authorization Grant flow: RFC 8693 token exchange at the enterprise IdP (ID Token → JWT Authorization Grant) followed by RFC 7523 JWT bearer grant at the MCP authorization server (JAG → access token). See the new Cross-Application Access section in the transport docs for full usage details.Full Changelog: v1.3.0...v1.4.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →