跳到主要内容
Supermarket
返回能力市场
MCP Server
programming
NOASSERTION

typescript-sdk

The official TypeScript SDK for Model Context Protocol servers and clients

modelcontextprotocolmodelcontextprotocol
93/ 100

公开评测 · 综合采用结论

证据充分,整体质量与安全表现优秀

查看评测依据 评测我的项目基于公开项目证据,非安全认证或安装推荐
13.4kstars
2.2kforks
最近更新 19天前
评测生成时间(北京时间)
本报告引擎
v3.10.0
当前引擎
v3.16.0

本报告与当前引擎使用不同规则;原分数不会自动更新,不同版本的分数不宜直接对比。

重新评测此项目

进入后确认来源与额度,提交才会创建任务。

Evaluation report

综合采用结论

93
A+
满分 100
值得推荐低风险
决策摘要

证据充分,整体质量与安全表现优秀

91%
高置信度
100
文档
100
安全
85
质量
100
活跃
70
采用
  • 基础评测完成+25/25确定性评分与静态安全扫描已完成
  • README 有效证据+20/257,842 个去重后的有效字符
  • 独立证据来源+16/204 类非重复证据,重复文件不叠加
  • 仓库元数据+10/10已取得仓库状态与采用数据
  • 活跃记录+5/5已取得最近提交时间
  • AI 复核+15/15已完成结构化 AI 证据复核
How it works · 时序图

MCP服务器工具调用流程

README示例展示了服务器注册工具并通过stdio传输连接,涉及客户端调用和服务器响应,存在请求-响应关系。

AI 提取 · 证据约束

左右滑动查看完整图示

MCP服务器工具调用流程README示例展示了服务器注册工具并通过stdio传输连接,涉及客户端调用和服务器响应,存在请求-响应关系。客户端发起调用stdio传输通信通道服务器处理请求greet工具执行逻辑发送调用请求传递请求调用工具返回结果发送响应返回结果
图示依据
  • • Getting Started: 示例创建McpServer并注册greet工具
  • • Getting Started: 使用StdioServerTransport连接服务器
  • • Overview: 描述MCP提供标准化上下文
五维表现
官方TypeScript SDK,解决MCP服务器/客户端构建的明确需求,示例清晰,安装步骤完整,文档丰富。最大缺口是设计细节(如错误处理、安全边界)在README中未充分展示。
质量证据
  • Overview: 描述MCP用途和SDK包含的服务器/客户端库
  • Installation: 提供npm、bun、deno安装命令
  • Getting Started: 展示最小服务器示例,注册greet工具
  • Documentation: 列出教程、排障、API参考链接
  • License: 声明Apache 2.0和MIT
采用建议
优势
  • 问题与用途描述
  • 有效 README
  • 安装或接入步骤
  • 可执行示例
  • 未发现已知高风险模式
关注点
  • README未详细说明错误处理机制
  • 安全默认值(如Host头验证)仅在中间件提及
  • 权限和数据边界未在README中明确
  • 设计细节需查阅API参考文档
适合

构建MCP服务器或客户端的TypeScript开发者、需要stdio或Streamable HTTP传输的场景、希望集成Express、Fastify等框架的开发者、需要官方支持且遵循最新MCP规范的项目

不建议直接用于

非TypeScript项目、需要图形化界面或低代码开发的场景、对MCP规范不熟悉且需要完整设计文档的初学者

也有自己的公开项目?先看完证据,再用当前规则生成独立报告。

评测我的项目 →
文档证据
100/100
问题与用途描述10 分
有效 README12 分
安装或接入步骤14 分
可执行示例16 分
输入、参数或工具说明11 分
输出或结果说明9 分
限制、权限或边界12 分
错误处理或排障8 分
许可证信息5 分
结构化章节3 分
安全证据
低风险
未发现已知高风险模式

静态扫描不是安全保证,生产接入前仍应人工复核权限和数据边界。

方法、证据与局限展开
数据来源

GitHub Repository API

扫描范围

25 个文件 · 33,949 字符

评测引擎

v3.10.0 · AI 复核已启用(deepseek-chat)

局限
  • 静态评测不会安装或执行项目代码
  • 安全扫描基于高信号文件与已知模式,不能替代人工审计
  • 流行度只反映采用程度,不代表安全或工程质量

30 天热度趋势

README

MCP TypeScript SDK

[!IMPORTANT] This is the main branch — v2 of the SDK (@modelcontextprotocol/server, @modelcontextprotocol/client), implementing the 2026-07-28 MCP spec.

Have feedback? Please open a v2 issue — it is the most useful thing you can do for the SDK right now. The v2 documentation starts with a ten-minute server tutorial.

v2 is the stable release line, released alongside the 2026-07-28 spec. v1.x continues to receive bug fixes and security updates for at least 6 months after v2's release. v1 documentation: ts.sdk.modelcontextprotocol.io · v2: /v2/.

[!WARNING] We're limiting pull requests to 1 per new contributor while v2 settles after the 2026-07-28 spec release.

Issues are the most useful feedback right now — we'll reopen PRs as v2 stabilizes.

NPM Version - Server NPM Version - Client MIT licensed

Table of Contents

Overview

The Model Context Protocol (MCP) allows applications to provide context for LLMs in a standardized way, separating the concerns of providing context from the actual LLM interaction.

This repository contains the TypeScript SDK implementation of the MCP specification. It runs on Node.js, Bun, and Deno, and ships:

  • MCP server libraries (tools/resources/prompts, Streamable HTTP, stdio, auth helpers)
  • MCP client libraries (transports, high-level helpers, OAuth helpers)
  • Optional middleware packages for specific runtimes/frameworks (Express, Fastify, Hono, Node.js HTTP)
  • Runnable examples (under examples/)

Packages

This monorepo publishes split packages:

  • @modelcontextprotocol/server: build MCP servers
  • @modelcontextprotocol/client: build MCP clients

Tool and prompt schemas use Standard Schema — bring Zod v4, Valibot, ArkType, or any compatible library.

Middleware packages (optional)

The SDK also publishes small "middleware" packages under packages/middleware/ that help you wire MCP into a specific runtime or web framework.

They are intentionally thin adapters: they should not introduce new MCP functionality or business logic. See packages/middleware/README.md for details.

  • @modelcontextprotocol/node: Node.js Streamable HTTP transport wrapper for IncomingMessage / ServerResponse
  • @modelcontextprotocol/express: Express helpers (app defaults + Host header validation)
  • @modelcontextprotocol/fastify: Fastify helpers (app defaults + Host header validation)
  • @modelcontextprotocol/hono: Hono helpers (app defaults + JSON body parsing hook + Host header validation)

Installation

Server

npm install @modelcontextprotocol/server
# or
bun add @modelcontextprotocol/server
# or
deno add npm:@modelcontextprotocol/server

Client

npm install @modelcontextprotocol/client
# or
bun add @modelcontextprotocol/client
# or
deno add npm:@modelcontextprotocol/client

Optional middleware packages

The SDK also publishes optional “middleware” packages that help you wire MCP into a specific runtime or web framework (for example Express, Fastify, Hono, or Node.js http).

These packages are intentionally thin adapters and should not introduce additional MCP features or business logic. See packages/middleware/README.md for details.

# Node.js HTTP (IncomingMessage/ServerResponse) Streamable HTTP transport:
npm install @modelcontextprotocol/node

# Express integration:
npm install @modelcontextprotocol/express express

# Fastify integration:
npm install @modelcontextprotocol/fastify fastify

# Hono integration:
npm install @modelcontextprotocol/hono hono

Getting Started

Here is what an MCP server looks like. This minimal example exposes a single greet tool over stdio:

import { McpServer } from '@modelcontextprotocol/server';
import { StdioServerTransport } from '@modelcontextprotocol/server/stdio';
import * as z from 'zod/v4';

const server = new McpServer({ name: 'greeting-server', version: '1.0.0' });

server.registerTool(
    'greet',
    {
        description: 'Greet someone by name',
        inputSchema: z.object({ name: z.string() })
    },
    async ({ name }) => ({
        content: [{ type: 'text', text: `Hello, ${name}!` }]
    })
);

async function main() {
    const transport = new StdioServerTransport();
    await server.connect(transport);
}

main();

Ready to build something real? Follow the step-by-step tutorials:

For runnable, end-to-end examples beyond the tutorials, see:

  • examples/README.md — runnable, self-verifying client/server example pairs (one story per directory)

Documentation

Building docs locally

To work on the documentation site locally:

pnpm docs:api      # Generate the API reference markdown (output: docs/api/)
pnpm docs:dev      # Start the VitePress dev server for the V2 site
pnpm docs:build    # Build the V2 site (output: docs/.vitepress/dist/)
pnpm docs:multi    # Build the combined V1 + V2 site (output: tmp/docs-combined/)

The docs:multi script builds the V2 site from the current checkout, checks out the v1.x branch via a git worktree to build the V1 site, and produces a combined site with V1 docs at the root and V2 docs under /v2/.

v1 (legacy) documentation and fixes

If you are using the v1 generation of the SDK, the v1 API documentation is available at https://ts.sdk.modelcontextprotocol.io/. The v1 source code and any v1-specific fixes live on the long-lived v1.x branch. V2 API docs are at /v2/.

Contributing

Issues and pull requests are welcome on GitHub at https://github.com/modelcontextprotocol/typescript-sdk.

License

This project is licensed under the Apache License 2.0 for new contributions, with existing code under MIT. See the LICENSE file for details.