# @modelcontextprotocol/core

> Model Context Protocol for TypeScript — public Zod schemas (spec + OAuth/OpenID)

Latest version **2.3.1** (published 2026-10-05) · Apache-2.0 license · 0 weekly downloads

## Install

```sh
npm install @modelcontextprotocol/core
pnpm add @modelcontextprotocol/core
yarn add @modelcontextprotocol/core
bun add @modelcontextprotocol/core
```

## Health

**Score 80/100 (A)** — status: active.

Positive: has types; esm support; no vulnerabilities; has provenance; recently updated; high maintenance score; high quality score; popular repo.

Warnings: low downloads.

## Facts

| | |
|---|---|
| Version | 2.3.1 |
| Published | 2026-10-05 |
| First published | 2026-06-25 |
| Weekly downloads | 0 |
| License | Apache-2.0 |
| TypeScript types | bundled |
| Module format | ESM + CommonJS |
| Node | >=20 |
| Dependencies | 1 |
| Unpacked size | 1.3 MB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Provenance | attested (GitHub Actions) |
| GitHub stars | 13422 |
| Author | Anthropic, PBC |
| Maintainers | jspahrsummers, pcarleton, fweinberger, thedsp, ochafik-ant |
| Keywords | modelcontextprotocol, mcp, schemas, zod |

## Links

- npm: https://www.npmjs.com/package/@modelcontextprotocol/core
- Repository: https://github.com/modelcontextprotocol/typescript-sdk
- Homepage: https://modelcontextprotocol.io
- Issues: https://github.com/modelcontextprotocol/typescript-sdk/issues
- npm.io page: https://npm.io/package/@modelcontextprotocol/core

## Dependencies (1)

- [zod](https://npm.io/package/zod.md) ^4.2.0

## Alternatives

- [vest](https://npm.io/package/vest.md) — 50.1K weekly downloads
- [@regle/core](https://npm.io/package/@regle/core.md) — 47.0K weekly downloads
- [typeof-arguments](https://npm.io/package/typeof-arguments.md) — 12.5K weekly downloads
- [@lokalise/projects-engine-contracts](https://npm.io/package/@lokalise/projects-engine-contracts.md) — 978 weekly downloads
- [@osjwnpm/nam-laboriosam-quibusdam](https://npm.io/package/@osjwnpm/nam-laboriosam-quibusdam.md) — 70 weekly downloads

## Recent versions

- 2.3.1 (latest) — 2026-10-05
- 2.3.0 — 2026-10-02
- 2.2.0 — 2026-09-28
- 2.1.0 — 2026-09-23
- 2.0.0 — 2026-07-27
- 2.0.0-beta.5 — 2026-07-21
- 2.0.0-beta.4 — 2026-07-13
- 2.0.0-beta.3 — 2026-07-09
- 2.0.0-beta.2 — 2026-07-02
- 2.0.0-beta.1 — 2026-06-30
- 2.0.0-alpha.2 — 2026-06-30
- 2.0.0-alpha.1 — 2026-06-25
- 2.0.0-alpha.0 — 2026-06-25

## README

# @modelcontextprotocol/core

Canonical public home for the [Model Context Protocol](https://modelcontextprotocol.io) specification and OAuth/OpenID **Zod schemas**.

These are the exact schema constants the SDK validates protocol and OAuth/OpenID payloads against internally. The `@modelcontextprotocol/server` and `@modelcontextprotocol/client` packages keep a Zod-free public surface, so this package exists as the supported place to import the
raw schemas when you need to validate or parse MCP messages yourself.

## Install

```sh
npm install @modelcontextprotocol/core
```

## Usage

```ts
import { CallToolResultSchema } from '@modelcontextprotocol/core';

// Throws on invalid input; returns the typed result on success.
const result = CallToolResultSchema.parse(payload);

// Or non-throwing:
const parsed = CallToolResultSchema.safeParse(payload);
if (parsed.success) {
    // parsed.data is a fully typed CallToolResult
}
```

## Scope

This package exports **only** Zod schema constants (`*Schema`), in two groups:

- the MCP **spec** schemas — `CallToolResultSchema`, `ListToolsResultSchema`, …; and
- the **OAuth/OpenID** auth schemas — `OAuthTokensSchema`, `OAuthMetadataSchema`, `IdJagTokenExchangeResponseSchema`, … (the schemas v1 exposed from `@modelcontextprotocol/sdk/shared/auth.js`).

The corresponding TypeScript types, error classes, enums, and type guards are part of the public API of [`@modelcontextprotocol/server`](https://www.npmjs.com/package/@modelcontextprotocol/server) and
[`@modelcontextprotocol/client`](https://www.npmjs.com/package/@modelcontextprotocol/client).

> **Migrating from v1?** In v1 these schemas were imported from `@modelcontextprotocol/sdk/types.js` (spec schemas) and `@modelcontextprotocol/sdk/shared/auth.js` (OAuth/OpenID schemas). Point those `*Schema` imports at `@modelcontextprotocol/core` and your existing `.parse()` /
> `.safeParse()` calls keep working unchanged.

---
_Source: https://npm.io/package/@modelcontextprotocol/core · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
