The Model Context Protocol changed on 28 July 2026. The revision removed the handshake and protocol sessions, added server/discover and "input required" results, and deprecated Roots, Sampling, Logging and HTTP+SSE. Most material online still describes the old model. This is a 191-page manual for the current specification and the TypeScript SDK v2, not a blog post. You build four complete servers and run them: tasklog (tools, a resource, a prompt, a delete confirmation through elicitation, stdio and Streamable HTTP), notes (a sandboxed folder whose path confinement survives symbolic links), sql (a read-only analyst, where the database and not your string checks is the boundary), and bookmarks (a multi-user remote server with OAuth resource-server checks, scope step-up and signed request state). All four ship in the download with thirteen tests that pass on Node 24. A chapter of real captured wire traffic shows what the protocol actually sends. Every guard in the book has a test that fails when the guard is removed, and we show that failing.
What's included
191-page PDF (6 x 9 in, page-numbered, cover page, contents, index)
EPUB 3 of the same book for phones and e-readers (epubcheck: 0 errors, 0 warnings)
Offline HTML flipbook: page-turn by tap, swipe or arrow keys, page counter, contents that jump to any chapter, works on a phone with no internet
64 original diagrams and charts, drawn in code: protocol sequence diagrams, threat-model maps, a token-bucket chart, measured latency and tool-definition sizes
The code folder: four servers, shared guards, a test kit, thirteen tests, a trace recorder and a measurement script. npm install, npm test
20 chapters in four parts: Understand, Build, Secure, Ship
What changed in 2026-07-28: stateless requests, _meta, server/discover, multi round-trip requests, subscriptions/listen, the deprecation window
A real captured trace: seven HTTP exchanges between the official v2 client and our server, headers and bodies
Tool design: names, descriptions, tight zod schemas, paging, annotations and why they are untrusted
Authorization: Protected Resource Metadata, 401 and 403 challenges, audience-bound tokens, scope step-up, why token passthrough is forbidden
Guards in code: path confinement that survives links, a token bucket, an SSRF check, signed request state, output scrubbing
Testing: the Inspector, end-to-end tests with the official client, and the four-step check that proves a security test is real
Deployment, host configuration (Claude Code, Claude Desktop, Cursor), a migration guide from 2025 code and SDK v1, and a troubleshooting field guide by layer
Glossary, quick reference card, index
File formats
PDF, for reading on a laptop or tablet and for printing
EPUB 3, for e-readers and phone reading apps
An offline HTML flipbook that turns pages by tap, swipe or arrow key, in any browser
Delivered as one ZIP (25 files)
Works with
Node.js 22 or newer (tested on 24.18.1) and basic JavaScript or TypeScript
The MCP Inspector needs Node 22.19 or newer
Optional: an MCP host such as Claude Code, Claude Desktop or Cursor
A PDF reader, any EPUB reader, and a browser for the flipbook.
Licence
Personal use by one person; no redistribution of the book. The code in the code folder may be used in your own projects, commercial or not. Seller: CodeUpVik.
Questions
How do I get my file?
Right after payment you see a Download button on the payment page. Each link works for 10 minutes, so save the file straight away. If a link expires, write to us with your order ID for a new one.
Can I get a refund?
Digital products are final sale. If a download does not work, email us within 7 days of purchase with your order ID and a short screen recording. We send a working file within 2 working days, or refund you in full if we cannot. Read the refund policy
Is anything shipped?
No. Every product is a digital download. Nothing physical is shipped.
Is the payment secure?
Yes. Payments in India are processed by Cashfree, and payments from outside India by PayPal, each on its own secure checkout. We never see or store your card or bank details.
Paid, but no download?
Write to us with the order ID shown on the payment page and we will sort it out. [email protected]