cloudflare / cloudflare/agents

Avoid installing the legacy MCP SDK when legacy APIs are unused

Open
#2,209 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
5.6k
Forks
711
Avg merge
1d 20h
Merged PRs (30d)
53

Description

Hey, thanks for maintaining the Agents SDK!

After updating to `agents@0.22.0`, I noticed that `@modelcontextprotocol/sdk@1.30.0` is still a required peer dependency. npm and pnpm therefore install it for every consumer.

The v1 SDK brings several server dependencies with it, including `express`, `express-rate-limit`, `cors`, `raw-body`, and `@hono/node-server`.

As described in #1557, the package is retained for legacy compatibility paths such as `McpAgent`, `WorkerTransport`, and `createLegacyMcpHandler`. That makes sense for existing users of those APIs, but we do not use any of the legacy MCP functionality and still get the complete SDK v1 dependency tree.

Besides the additional install size, avoiding unused server dependencies also reduces the supply-chain surface for consumers that only use the regular Agents or MCP v2 APIs.

Would highly appreciate if the legacy MCP path could be isolated and `@modelcontextprotocol/sdk` made optional, so only consumers using the legacy APIs need to install it.

Contributor guide

Open the contributing guide

Research direction

Start by inspecting the package metadata that declares @modelcontextprotocol/sdk and the legacy entry points named in the issue: McpAgent, WorkerTransport, and createLegacyMcpHandler. Compare installation behavior for regular Agents or MCP v2 consumers versus legacy API consumers; done means the legacy SDK is not required for the former while remaining available for the latter.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
tooling
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.