---
title: "MCP TypeScript SDK 2.1.0 ships DPoP OAuth auth"
slug: "mcp-typescript-sdk-210-ships-dpop-oauth-auth"
published: "2026-10-09"
beat: "Tools"
tags: ["Tools"]
creator: "Agentry Newsroom"
editor: "Susanne Sperling, Editor — Human in the Loop"
tools: ["Claude (Anthropic)", "Perplexity Sonar"]
creativeWorkStatus: "verified"
dateReviewed: "2026-10-09"
aiActArticle50: "compliant"
humanView: "https://agentry.news/tools/mcp-typescript-sdk-210-ships-dpop-oauth-auth"
agentView: "https://agentry.news/agent/mcp-typescript-sdk-210-ships-dpop-oauth-auth"
---# MCP TypeScript SDK 2.1.0 ships DPoP OAuth auth

> The Model Context Protocol TypeScript SDK version 2.1.0 introduced optional sender-constrained access tokens via DPoP and request-time OAuth scope challenges on September 23, 2026, strengthening authe

*Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. [AI policy](/ai-policy).*

## MCP SDK 2.1.0 ships DPoP and OAuth scope challenges

The Model Context Protocol (MCP) TypeScript SDK version 2.1.0 was released on September 23, 2026, introducing two authentication upgrades that developers can now use to secure agent-to-server communications: optional DPoP (Demonstrating Proof of Possession) sender-constrained access tokens and request-time OAuth scope-challenge handling [Fluid Labs](https://fluidlabs.com/resources/mcp-sdk-2-1-0-oauth-dpop-scope-challenges).

DPoP support is opt-in and allows MCP clients to bind access tokens to a specific sender via cryptographic proof, preventing token replay attacks if credentials are intercepted. Developers implement this by configuring an `OAuthClientProvider.dpop()` hook that returns a `DpopSession`, and the SDK handles DPoP proof generation and nonce-challenge retry logic automatically [WorkOS Blog](https://workos.com/blog/mcp-sdk-dpop-and-scope-challenges). Existing OAuth integrations continue to work as bearer-token flows unless the DPoP provider capability is explicitly configured.

## Scope challenges and authorization gates

The release also added server-side request-time OAuth scope-challenge support, enabling MCP servers to enforce fine-grained permission checks before handler execution. When a client makes a request with insufficient scopes, the server responds with an `insufficient_scope` challenge and HTTP 403, triggering a scope-upgrade flow before the server processes the request or initiates Server-Sent Events (SSE) setup [Fluid Labs](https://fluidlabs.com/resources/mcp-sdk-2-1-0-oauth-dpop-scope-challenges).

This dual approach—client-side sender binding and server-side scope enforcement—addresses two common OAuth weaknesses in agent frameworks. Sender binding prevents token theft from being sufficient for attack; scope challenges ensure agents only receive permissions they explicitly requested and that servers can revoke or escalate permissions mid-session.

## Affected packages and rollout

The release touched four core MCP packages: `@modelcontextprotocol/core`, `@modelcontextprotocol/client`, `@modelcontextprotocol/server`, and `@modelcontextprotocol/node` [Fluid Labs](https://fluidlabs.com/resources/mcp-sdk-2-1-0-oauth-dpop-scope-challenges). Because DPoP is opt-in, existing agent deployments and integrations do not require immediate changes. Teams building new MCP clients or integrating with OAuth-protected resources can enable DPoP by adding the provider hook and configuring scope-challenge handlers on the server.

The MCP TypeScript SDK is the reference implementation for the Model Context Protocol, a standard for agentic tool use and data access. Improvements to its authentication layer directly affect security posture across the growing ecosystem of MCP-compatible agent platforms and enterprise integrations.