
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@modelcontextprotocol/core
Advanced tools
Model Context Protocol for TypeScript — public Zod schemas (spec + OAuth/OpenID)
Canonical public home for the Model Context Protocol specification and OAuth/OpenID Zod schemas.
These are the exact schema constants the SDK validates protocol and OAuth/OpenID payloads against internally. The @modelcontextprotocol/server and @modelcontextprotocol/client packages keep a Zod-free public surface, so this package exists as the supported place to import the
raw schemas when you need to validate or parse MCP messages yourself.
npm install @modelcontextprotocol/core
import { CallToolResultSchema } from '@modelcontextprotocol/core';
// Throws on invalid input; returns the typed result on success.
const result = CallToolResultSchema.parse(payload);
// Or non-throwing:
const parsed = CallToolResultSchema.safeParse(payload);
if (parsed.success) {
// parsed.data is a fully typed CallToolResult
}
This package exports only Zod schema constants (*Schema), in two groups:
CallToolResultSchema, ListToolsResultSchema, …; andOAuthTokensSchema, OAuthMetadataSchema, IdJagTokenExchangeResponseSchema, … (the schemas v1 exposed from @modelcontextprotocol/sdk/shared/auth.js).The corresponding TypeScript types, error classes, enums, and type guards are part of the public API of @modelcontextprotocol/server and
@modelcontextprotocol/client.
Migrating from v1? In v1 these schemas were imported from
@modelcontextprotocol/sdk/types.js(spec schemas) and@modelcontextprotocol/sdk/shared/auth.js(OAuth/OpenID schemas). Point those*Schemaimports at@modelcontextprotocol/coreand your existing.parse()/.safeParse()calls keep working unchanged.
FAQs
Model Context Protocol for TypeScript — public Zod schemas (spec + OAuth/OpenID)
The npm package @modelcontextprotocol/core receives a total of 7,582,449 weekly downloads. As such, @modelcontextprotocol/core popularity was classified as popular.
We found that @modelcontextprotocol/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.