Back to all releases

v1.7.0

Platform

// August 10, 2026

Search and filter every client and session connected to an MCP server

The Clients and Sessions tab on MCP server pages now leads with live counts and renders both listings as searchable, sortable tables, so answering "who is connected to this server right now" takes one click instead of a scroll. MCP OAuth responses also meet the newest authorization spec, protecting clients that hold flows against several servers at once.

Features

  • Searchable client and session tables #5077 - Both listings are searchable, filterable, and sortable, with member avatars and creation dates on sessions. Each client row reports how many active sessions it holds, and clicking that count narrows both listings to that client. (Author: @bflad)
  • OAuth responses defend against mix-up attacks #4956 - The authorization server now emits the RFC 9207 issuer parameter on every response and advertises it in metadata, satisfying the MCP 2026-07-28 authorization response validation requirement. (Author: @bflad)

Bug fixes

  • Shadow MCP finding descriptions stay generic #5056 - Risk finding descriptions no longer name the specific tool that was called. (Author: @disintegrator)
  • Onboarding covers Claude Cowork and shows conversations #5057 - Choosing Device Agent during onboarding now notes that Claude Cowork's cloud sandbox needs its own manual setup step and links to it. Conversation events also reach the confirm-traffic feed, so it shows prompts and replies rather than only tool calls, and MDM vendor wording follows the Iru rebrand. (Author: @mfbx9da4)
Sagar Batchu
Sagar Batchu
View on GitHub