1 October 2026
API
Deprecation
Enhancement
GeneralSecurity and privacy
Tool results now include structuredContent alongside the existing text content, and failed execute_tool calls return isError: true, so clients can react to errors without parsing text. In version 0.4.0 of the tools-core package (@commercetools/tools-core), every tool definition includes a title and MCP annotations (readOnlyHint, destructiveHint, and openWorldHint) derived from the tool name, which Commerce MCP 4.2.0 advertises for each tool.
Tool schemas are now compatible with stricter MCP clients. Numeric bounds use the numeric exclusiveMinimum form, so clients that validate tool schemas, such as MCP Inspector, no longer fail to connect. Recursive schemas, such as the query parameter of read_product_search, are no longer emitted as empty schemas. In version 0.4.1 of the tools-core package (@commercetools/tools-core), geoLocation.coordinates in update_channels is no longer emitted as a JSON Schema tuple, so MCP clients that validate tool schemas with an OpenAPI-based validator can load tools from the server.
The server no longer issues or accepts the Mcp-Session-Id header, and GET /mcp returns 405 instead of 401, because the GET endpoint was removed in the 2026-07-28 specification. Running the server in stateful mode with --stateless=false is deprecated. The Commerce MCP package (@commercetools/commerce-mcp) is published as an ES module only and requires Node.js 20 or later.
Commerce MCP tools now support the authenticationMode field of Managed MCP Servers. With authentication modes, you control how AI agents authenticate when they connect to an MCP Server. The create_mcp_servers tool accepts an optional authenticationMode, which can be ClientCredentials or CommercetoolsIdentity. If not set, it defaults to ClientCredentials. The update_mcp_servers tool supports the Set Authentication Mode update action. This change is part of the tools-core package.
For more information, see Self-hosted Commerce MCP.