This release includes 2 security fixes for security teams reviewing exposed deployments.
Affected surfaces
Summary
AI summaryOAuth proxy endpoints hardened against input validation, rate limiting, and timeout issues.
Full changelog
Added
- OAuth 2.1 support for automatic API key provisioning on MCP connection
- Server branding metadata (title, description, icons) for client connection cards
- Centered README hero layout with improved visual hierarchy
Security
- Harden OAuth proxy endpoints with input validation, rate limiting, and timeout handling
- Sanitize upstream error responses on token exchange
Fixed
- HEAD /api/mcp returning 405 instead of 200
- Metric count in README (38 -> 30)
- cli.js version mismatch with package.json
Full Changelog: https://github.com/PreReason/mcp/compare/v0.2.1...v0.3.0
Security Fixes
- Harden OAuth proxy endpoints with input validation, rate limiting, and timeout handling
- Sanitize upstream error responses on token exchange
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About PreReason/mcp
Pre-reasoned Bitcoin and macro market briefings with trend signals, confidence scores, and regime classification. 17 briefings covering BTC, Fed balance sheet, M2, Treasury yields, and cross-asset correlations.
Related context
Beta — feedback welcome: [email protected]