MCPHubBETA
v1.1.0Oct 3, 2026

v1.1.0

v1.1.0 marks completion of the dual-stack baseline and defined acceptance checks for the staged MCP 2026-07-28 migration tracked in #1220. MCPHub supports both 2025-11-25 and 2026-07-28: modern requests work without initialization or downstream transport sessions, while stateful tools can reuse isolated application state through an explicit state handle. This release fixes legacy-session interference with modern routing, completes protocol-validation, credential-isolation and state-lifecycle coverage, and adds bounded private list cache TTLs. Existing SSE and legacy Streamable HTTP sessions remain supported, with SSE migration documentation outlining the future deprecation path.

View release
FeatureFix
  • •Advertise positive private TTLs for modern tools, prompts, resources, and resource-template lists when upstream discovery freshness is trustworthy, capped by the shortest remaining discovery lifetime and a five-second gateway budget. Uncertain freshness keeps TTLs at zero. by @samanhappy in https://github.com/samanhappy/mcphub/pull/1277
  • •Document the bounded positive list TTL policy and legacy SSE deprecation and migration plan. by @samanhappy in https://github.com/samanhappy/mcphub/pull/1276 and https://github.com/samanhappy/mcphub/pull/1275
v1.0.46Oct 3, 2026

v1.0.46

This release strengthens server configuration isolation, adds conservative cache hints for modern MCP clients, and improves dashboard editing and readability. Ordinary-user server configuration no longer expands service-process environment values, and authorization metadata remains literal.

View release
FeatureFix
  • •Add private cache scope and conservative TTL hints for modern MCP responses.
  • •Document MCP protocol compatibility and migration, and clarify PostgreSQL connection-pool sizing.
v1.0.45Oct 2, 2026

v1.0.45

MCPHub v1.0.45 improves REST tool result fidelity, OpenAPI parameter handling, and MCP Apps compatibility for stateless clients. It also updates runtime and dashboard dependencies and fixes ESLint CI compatibility.

View release
Fix
v1.0.44Sep 30, 2026

v1.0.44

This release lets authenticated modern MCP clients reuse isolated state for session-dependent tools through X-MCPHub-State-Id, fixes upstream OAuth authorization callbacks after the SDK v2 migration, and improves routing compatibility coverage and contributor documentation. Modern application state is process-local and requires sticky routing across replicas.

View release
FeatureFix
  • •Enable isolated upstream connections and OpenAPI cookie state across modern MCP requests using a client-generated UUID v4 in X-MCPHub-State-Id. State is bound to the authenticated credential, user, and route, and expires after 30 minutes of inactivity. by @samanhappy in https://github.com/samanhappy/mcphub/pull/1245
v1.0.43Sep 30, 2026

v1.0.43

MCPHub v1.0.43 adds a dual-stack HTTP path for MCP 2026-07-28 requests while preserving legacy Streamable HTTP behavior. Smart routing gains scored search results, configurable matching and schema limits, and pinned group tools. This release also improves credential-server indexing, OAuth scope handling, configuration expansion, and preservation of tool and prompt settings after server renames.

View release
FeatureFix
  • •Add a stateless HTTP path for MCP 2026-07-28 requests alongside legacy Streamable HTTP. Stateful upstream compatibility remains limited.
  • •Show scores for search_tools results, configure the similarity threshold, clarify empty matches, and limit full schemas to the top N results.
  • •Pin selected group tools alongside meta-tools on the group's $smart endpoint.
v1.0.42Sep 28, 2026

v1.0.42

MCPHub v1.0.42 upgrades to MCP SDK v2.1 while preserving legacy protocol compatibility, fixes environment-variable expansion during tool-call reconnects, and restores OAuth compatibility with upstream servers that do not advertise issuer response support. The Dashboard now uses system fonts to avoid Google Fonts loading delays, and smart-routing documentation uses the correct connection-pool setting. Node.js 20 or later is required.

View release
Fix
v1.0.41Sep 26, 2026

v1.0.41

This release makes Smart Routing more flexible and more transparent. You can now attach an optional embedding query and document prefixes so your own documents are embedded and searched the way you intend, the server description mode set through the system config API is properly persisted, and environment variables that would otherwise silently shadow dashboard settings are surfaced in the UI. The marketplace hides the Cloud Support (MCPRouter) tab and button hover pointers are restored. The docs toolchain also hardens: every Mintlify MDX page is now validated in CI with broken pages repaired, while the agent guides gain the shell PATH and file-sandbox workarounds plus a new security advisory lifecycle workflow.

View release
FeatureFix
  • •Hide the Cloud Support (MCPRouter) tab in the marketplace by @samanhappy in https://github.com/samanhappy/mcphub/pull/1218
  • •Add an optional embedding query and document prefixes to Smart Routing by @SelfRef in https://github.com/samanhappy/mcphub/pull/1212
v1.0.40Sep 24, 2026

v1.0.40

This release makes Smart Routing observable and the server more resilient under load. The maintenance endpoints the docs already advertised — performance diagnostics and a forced reindex — are now actually exposed, with a dashboard panel to drive them. Reliability work hardens database reconnection against pool wedges with bounded teardown, health-check and connection timeouts, preserves safe upstream failure diagnostics instead of blaming credentials, and makes explicit servers win over prefix matches in personal-credential routing. Authentication is more robust: OIDC sign-in no longer fails for providers that omit the name claim, and OAuth clients keep their token endpoint auth method. Smart Routing search now honors per-tool description overrides in its embedded text, and the docs dropped a JWTEXPIRESIN setting the server never reads.

View release
FeatureFix
  • •Add Smart Routing performance diagnostics and forced-reindex API endpoints with a dashboard panel by @myml in https://github.com/samanhappy/mcphub/pull/1199
v1.0.39Sep 19, 2026

v1.0.39

This release makes MCPHub easier to share and operate. Copy actions now generate ready-to-paste MCP configuration snippets tailored to each client — Codex, VS Code, Claude Code, Cursor, and a dozen more — in a single dialog, and any server can be duplicated into a pre-filled Add Server form to spin up a near-identical instance in seconds. For stdio servers launched via npx/uvx, the dashboard now shows the resolved package version and flags when a newer version is available, so you can see at a glance what is actually running. Reliability also improved: a Smart Routing bug that could return no results for group-scoped searches is fixed by scoping the vector search in SQL, the Chinese monitoring guide is realigned with the implementation, and the frontend is now type-checked in CI.

View release
FeatureFix
  • •Copy actions now offer per-client MCP configuration presets, generating ready-to-paste snippets for Codex, VS Code, Claude Code, Cursor, and more by @SAXEM1997 in https://github.com/samanhappy/mcphub/pull/1191
  • •Duplicate any server into a pre-filled Add Server form to quickly create a near-identical instance by @SAXEM1997 in https://github.com/samanhappy/mcphub/pull/1190
  • •Show the resolved npx/uvx package version on server cards and flag when an update is available by @samanhappy in https://github.com/samanhappy/mcphub/pull/1186
v1.0.38Sep 16, 2026

v1.0.38

This release improves operational stability and dashboard clarity. Smart Routing no longer shows as Inactive when it is enabled purely through environment variables, idle dynamically-registered OAuth clients are now reaped automatically, and the npx/uvx reinstall is scoped to the server being reinstalled so package-cache churn stays isolated. On the dashboard, OpenAPI endpoint URLs now appear alongside MCP endpoints, and you can bound how many servers connect at once during startup to ease load. A build fix keeps shell scripts at LF so Windows checkouts produce a working image, and new Docker docs explain how to persist the npx/uvx package cache.

View release
FeatureFix
  • •feat(dashboard): surface OpenAPI endpoint URLs alongside MCP endpoints by @flatlinebb in https://github.com/samanhappy/mcphub/pull/1180
  • •feat(mcp): allow bounding how many servers connect at once on startup by @11113127 in https://github.com/samanhappy/mcphub/pull/1162
v1.0.37Sep 13, 2026

v1.0.37

This release closes a critical security hole: disabling a tool only filtered tools/list, leaving it executable through tools/call — so "read-only" connections to Gmail, Microsoft 365, or Nextcloud could be silently bypassed, including via prompt injection. Disabled tools are now enforced at execution time. Login rate limiting counts only failed attempts and is now tunable, so API consumers and service accounts renewing tokens are no longer locked out by successful logins. Group visibility controls arrive with private, group, and public scopes plus selected-user sharing, enforced across group APIs, MCP/SSE routes, and nested server metadata. Reliability and polish: OAuth clients are cached only after credential persistence succeeds, the Docker quick start is simplified while legacy mounts still work, and console logs render timestamps with the process-local UTC offset.

View release
FeatureFix
  • •feat: add visibility controls for groups by @samanhappy in https://github.com/samanhappy/mcphub/pull/1175
v1.0.36Sep 10, 2026

v1.0.36

This release brings per-user credentials to shared MCP servers: a single shared server definition can now require each caller's own API keys or tokens, managed through the new My Credentials page with bindings encrypted at rest (AES-256-GCM) — so multiple users share one server instead of maintaining duplicate private copies. Reliability is hardened across the board: on-demand servers stay alive while their tools are running, overlapping initialization no longer strands servers in a "connecting" state, transport creation failures are isolated to the affected server, the log-stream reconnect backoff resets correctly, and public auth routes no longer consume the shared /api rate limiter. Interoperability and polish: OpenAPI query arrays serialize correctly, copied MCP configuration uses group names, single-route tool calls survive session rebuilds, and the js-yaml, hono, and multer dependencies are updated.

View release
FeatureFix
  • •add per-user credentials for shared MCP servers by @samanhappy in https://github.com/samanhappy/mcphub/pull/1129
v1.0.35Sep 7, 2026

v1.0.35

This release hardens MCPHub's reliability and interoperability. Upstream OAuth servers now reconnect cleanly after reauthorization, and on-demand server settings (startOnDemand/idleTimeoutMs) are correctly persisted when running in database mode. Multipart file uploads are decoded and validated more robustly, and embedding dimensions are only forwarded to models that support them. Smart-routing configuration has also been modernized to provider-neutral field names with automatic migration of legacy persisted values, while existing OPENAI_* environment aliases keep working.

View release
FeatureFix
  • •use provider-neutral smart routing config names by @atirna in https://github.com/samanhappy/mcphub/pull/1133
v1.0.34Sep 2, 2026

v1.0.34

This release expands embedding configuration and provider support, clarifies MCPHub’s positioning as a self-hosted gateway and management platform, and improves Smart Routing, SSRF validation, and deployment reliability. It also refreshes agent guidance and dependency versions.

View release
FeatureFix
  • •feat(embeddings): add provider presets and configurable dimensions by @samanhappy in https://github.com/samanhappy/mcphub/pull/1113
  • •feat: update documentation and descriptions to clarify MCPHub as a se… by @samanhappy in https://github.com/samanhappy/mcphub/pull/1115
v1.0.33Aug 30, 2026

v1.0.33

This release rounds out OpenAPI integration and tightens security boundaries. OpenAPI imports now support urlencoded and multipart request bodies, serialize array query parameters per the spec, encode path parameters before URL substitution, and can prefill security from the spec's securitySchemes or a dedicated openapi.specSecurity credential. Security-wise, shared-server use is separated from config disclosure, template import enforces the privileged config check, and hidden-server tool calls return a unified "not available" error. Server names are now validated against the MCP tool-name charset, OAuth gains RFC 9207 issuer identification and CIMD client support, and the share-candidates picker scales better for large user sets.

View release
FeatureFix
  • •feat(oauth): add RFC 9207 issuer identification and CIMD client support by @samanhappy in https://github.com/samanhappy/mcphub/pull/1075
  • •feat: surface OpenAPI import tool-list size with context-window warning by @samanhappy in https://github.com/samanhappy/mcphub/pull/1092
  • •feat: prefill OpenAPI security from the spec's securitySchemes when importing by @samanhappy in https://github.com/samanhappy/mcphub/pull/1093
  • •feat(openapi): separate spec download credential via openapi.specSecurity by @samanhappy in https://github.com/samanhappy/mcphub/pull/1097
v1.0.32Aug 23, 2026

v1.0.32

This release closes the remaining security alerts flagged by CodeQL and Dependabot, including path injection, prototype pollution, rate limiting, SSRF, and OAuth PKCE findings, and hardens the logging pipeline by redacting sensitive data. Log messages are now stringified for better readability.

View release
Fix
v1.0.31Aug 22, 2026

v1.0.31

This release brings the OAuth consent screen into the React dashboard as a full SPA experience, showing the resource being requested and the client metadata so users can make informed approval decisions. It also ships security and reliability fixes: stricter full-containment enforcement for scoped bearer keys on group routes (GHSA-454m-4vm6-842f), a fix for per-request abort-signal listener leaks in MCP, header parameters exposed in the generated MCP input schema, BASE_PATH support for local development, and clearer database configuration documentation.

View release
FeatureFix
  • •Render OAuth consent screen inside the React dashboard (SPA) by @samanhappy in https://github.com/samanhappy/mcphub/pull/1060
  • •Surface resource target and client metadata on consent screen by @samanhappy in https://github.com/samanhappy/mcphub/pull/1061
v1.0.30Aug 20, 2026

v1.0.30

This release focuses on the server and auth layers. It adds the ability to configure the Better Auth base URL, implements group visibility and shared user functionality for servers, and avoids unnecessary runtime reloads when editing a server. It also aligns the project's license metadata with Apache-2.0.

View release
FeatureFix
  • •feat(auth): make Better Auth base URL configurable in settings by @samanhappy in https://github.com/samanhappy/mcphub/pull/1053
  • •feat: Implement group visibility and shared user functionality for servers by @samanhappy in https://github.com/samanhappy/mcphub/pull/1054
v1.0.29Aug 17, 2026

v1.0.29

This release improves OpenAPI and OAuth reliability: Set-Cookie is now persisted across calls per downstream session, OpenAPI spec document downloads authenticate with configured credentials, and 401 auto-discovery is restored for URL-only Streamable HTTP servers. It also bounds graceful shutdown for long-lived connections, removes stale vector embeddings when renaming a server, fixes a broken star history chart, and bumps the js-yaml dependency.

View release
FeatureFix
  • •Feat(openapi): persist Set-Cookie across calls per downstream session by @samanhappy in https://github.com/samanhappy/mcphub/pull/1047
v1.0.28Aug 8, 2026

v1.0.28

This release hardens JSON schema handling, improves the reliability of on-demand MCP servers, and streamlines the server configuration experience. A new ResilientJsonSchemaValidator gracefully handles unresolvable $refs, on-demand servers are now properly woken to serve tool calls, resource description/enabled overrides are correctly reflected in the dashboard list, and the server edit form is reorganized into three clearer sections. It also includes OAuth/import validation polish and routine dependency updates.

View release
FeatureFix
  • •Add ResilientJsonSchemaValidator to handle unresolvable $refs gracefully by @samanhappy in https://github.com/samanhappy/mcphub/pull/1028
  • •Restructure server edit form into 3 sections by @samanhappy in https://github.com/samanhappy/mcphub/pull/1034
v1.0.27Aug 3, 2026

v1.0.27

This release adds MCP Apps passthrough for multi-server groups and on-demand stdio server spawning to lower memory usage, and improves diagnostics by including upstream stderr in connection errors. It also hardens OAuth handling by stripping static Authorization headers when an OAuth provider is active, cleans up duplicated lockfile entries, and adds unit tests for smartRouting config resolution.

View release
FeatureFix
  • •feat: support MCP Apps passthrough on multi-server groups by @jcollas in https://github.com/samanhappy/mcphub/pull/1010
  • •feat: on-demand stdio server spawning to reduce memory usage by @Rahulsharma0810 in https://github.com/samanhappy/mcphub/pull/1012
v1.0.26Jul 28, 2026

v1.0.26

This release adds an MCP Toplist rank badge, fixes stdio server handling when no arguments are provided, and improves error reporting for invalid vector embedding writes.

View release
FeatureFix
  • •Add MCP Toplist rank badge by @chrstphe in https://github.com/samanhappy/mcphub/pull/1001
v1.0.25Jul 24, 2026

v1.0.25

This release focuses on security hardening and stability improvements, including a fix for a command injection vulnerability in proxychains4, recovery of stale PostgreSQL connections, and updated Docker image glibc compatibility.

View release
Fix
v1.0.24Jul 11, 2026

v1.0.24

This release adds upstream OAuth disconnect support and per-session upstream client isolation for stateful MCP servers, along with a fix for preserving in-flight OAuth state on full page reloads.

View release
FeatureFix
  • •add upstream OAuth disconnect by @samanhappy in https://github.com/samanhappy/mcphub/pull/984
  • •per-session upstream client isolation for stateful MCP servers by @isc30 in https://github.com/samanhappy/mcphub/pull/985
v1.0.23Jul 5, 2026

v1.0.23

This release adds local development convenience with a default admin user and dynamic base URL configuration, fixes several layout and i18n issues, and improves documentation.

View release
FeatureFix
  • •feat: add default admin user for local development and update documentation by @samanhappy in https://github.com/samanhappy/mcphub/pull/973
  • •feat: add INSTALLBASEURL support for dynamic configuration and improve related utilities by @samanhappy in https://github.com/samanhappy/mcphub/pull/976
  • •docs: update README files with Docker image variants and configuration details by @samanhappy in https://github.com/samanhappy/mcphub/pull/968
v1.0.22Jul 3, 2026

v1.0.22

This release surfaces the OAuth auth method in the activity log's API key field, fixes remote keep-alive status updates and OpenAPI server editing with recursive schemas, and ships routine dependency bumps for pg, @types/pg, openai, typescript, and i18next-browser-languagedetector.

View release
FeatureFix
  • •Surface OAuth auth method in activity log API key field by @samanhappy in https://github.com/samanhappy/mcphub/pull/958
v1.0.21Jun 30, 2026

v1.0.21

This release broadens OpenAPI integration — servers can now be defined as YAML endpoints, and OAuth2-secured OpenAPI servers correctly refresh their access token after a 401. It also ships a packaging fix that adds Cargo to the Docker image, corrects the Discord community link, and bumps typeorm and i18next-fs-backend.

View release
FeatureFix
  • •Support OpenAPI YAML endpoints by @samanhappy in https://github.com/samanhappy/mcphub/pull/950
v1.0.20Jun 28, 2026

v1.0.20

This release fixes smart call_tool routing.

View release
Fix
v1.0.19Jun 28, 2026

v1.0.19

This release hardens server management reliability with fixes across pagination, state broadcasts, process lifecycle, and serialization, and introduces config-gated verbatim tool call payload storage.

View release
FeatureFix
  • •Store tool call payloads verbatim, gated by a config switch by @samanhappy in https://github.com/samanhappy/mcphub/pull/944
v1.0.18Jun 22, 2026

v1.0.18

Adds per-tenant server isolation via group server aliases, a release-notes skill, and pnpm audit fixes.

View release
FeatureFix
  • •Group server alias: optional alias on group servers lets the same name be reused across groups, with tools prefixed by the alias instead of the owner; default unchanged when unset (#932)
  • •release-notes skill that rewrites a release body into the bilingual template, and relaxed validation that omits empty optional sections (#929)