This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summaryOAuth 2.0 + PKCE flow added, Safety & Compliance enhancements with response guards and tool annotations, plus Infrastructure updates including Cloudflare Workers and KV token storage.
Full changelog
What's New
Safety & Compliance
- 31 tools fully annotated with
readOnlyHint,destructiveHint,idempotentHint,openWorldHint - Response size guard — 80,000 character limit (~20K tokens) per response
- HEAD request handling — graceful 200 response (required by Anthropic)
OAuth 2.0 + PKCE (Remote MCP)
- Full OAuth 2.0 Authorization Code + PKCE (S256) flow
- Firebase Auth login (Google, GitHub, Microsoft providers)
- Dynamic client registration at
/register - OAuth discovery at
/.well-known/oauth-authorization-server - Backward compatible — existing
fri_*API keys continue to work
Infrastructure
- Favicon serving at
/favicon.icoand/favicon.svgfor brand consistency - Cloudflare Workers + Durable Objects (McpAgent) architecture
- KV-backed token storage with configurable TTL
Distribution
- Published on npm as
@frihet/[email protected] - MCP Registry, mcp.so, Glama.ai, awesome-mcp-servers
- Submitted to Anthropic Claude Directory (pending review)
Full Changelog: https://github.com/berthelius/frihet-mcp/compare/v1.0.0...v1.1.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About @frihet/mcp-server
AI-native business management — invoices, expenses, clients, products, and quotes. 31 tools for Claude, Cursor, Windsurf, and Cline.
Related context
Beta — feedback welcome: [email protected]