title: "MCP Python SDK 2.2.0 ships with session and OAuth hardening" slug: "mcp-python-sdk-220-ships-with-session-and-oauth-hardening" published: "2026-09-28" beat: "Tools" tags: ["Tools"] creator: "Agentry Newsroom" editor: "Susanne Sperling, Editor — Human in the Loop" tools: ["Claude (Anthropic)", "Perplexity Sonar"] creativeWorkStatus: "verified" dateReviewed: "2026-09-28" aiActArticle50: "compliant" humanView: "https://agentry.news/tools/mcp-python-sdk-220-ships-with-session-and-oauth-hardening" agentView: "https://agentry.news/agent/mcp-python-sdk-220-ships-with-session-and-oauth-hardening"
The Model Context Protocol Python SDK version 2.2.0 released September 7, 2026, adds session expiration, connection limits, and OAuth issuer validation to tighten security for agent developers integra
Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. AI policy.
The Model Context Protocol Python SDK version 2.2.0 arrived September 7, 2026, with three significant hardening changes for developers building and deploying AI agents: stricter streamable HTTP session management, OAuth server validation, and origin-restricted HTTP redirects ai-tldr.dev.
Idle streamable HTTP sessions now expire after 30 minutes of inactivity, and servers can hold a maximum of 10,000 concurrent sessions GitHub. When a client attempts to reuse an expired session, the server responds with a 404 status. Requests that exceed the 10,000-session ceiling receive a 503 Service Unavailable response. These constraints prevent long-lived sessions from consuming unbounded memory and reduce the surface area for session hijacking or resource exhaustion attacks.
The SDK's OAuth client now validates the authorization server's issuer claim on the legacy authentication path. If the issuer in the server's metadata does not match expectations, the client raises an OAuthFlowError: Authorization server metadata issuer mismatch exception and halts the flow GitHub. This check prevents man-in-the-middle attacks where an attacker redirects an agent to a malicious authorization endpoint.
HTTP client redirects are now restricted to the originating endpoint's scheme, host, and port. Redirects that cross origin boundaries—for example, from https://api.example.com to https://api.attacker.com—are rejected with an MCPError GitHub. This mitigates open-redirect vulnerabilities that could trick agents into sending sensitive headers or credentials to unintended destinations.
These changes reflect growing maturity in the MCP ecosystem as agents assume broader responsibility for integrations with enterprise APIs and OAuth-protected services. Developers upgrading to 2.2.0 must audit existing session management code to handle the 404 and 503 responses, and OAuth flows to ensure issuer URIs are correctly configured. The 10,000-session limit is a soft architectural boundary; production deployments handling higher concurrency will need to scale horizontally or implement session pooling.
The release underscores a developer-tools beat priority: MCP is now prioritizing security guards in its runtime rather than leaving validation to individual agent implementations.