Some MCP clients still speak only spec 2025. Spec 2025 can use sessions, and a session lives in one process. On a deploy with many instances, sessions need sticky routing.
By default, createMCPServer keeps no spec 2025 session, so any instance can answer any request. Set the sessions option only when you need something else:
You do not have to set anything. A new server answers each spec 2025 request, and no session is kept. A spec 2026 client sends no session id either, so any instance can serve both.
Without a session, the server cannot send a request back to a spec 2025 client. For that client:
A spec 2026 client gets requestInput and sample with no session.
To ask a spec 2025 client for input or a sample, set sessions to 'memory':
import { createMCPServer } from '@tanstack/ai-mcp/server'
const server = createMCPServer({
name: 'weather',
version: '1.0.0',
sessions: 'memory',
})serveMCPStdio uses 'memory' when you do not set sessions. A stdio process serves one client, so a session costs nothing there.
A spec 2025 session keeps a live connection object. That object stays in the process that opened the session. Another process cannot read it.
On a deploy with more than one instance, a later request can reach an instance that did not open the session. That request gets 404. Use the mcp-session-id header as the key for sticky routing on your load balancer.
A session closes in two cases:
The server checks for idle sessions when a request comes in. After a session closes, the client must open a new session.
The server has no limit on the number of open sessions. Each session stays in memory until it closes, which can take 30 minutes. On a public server, set auth, or limit new sessions at your proxy.
When the server has auth, the session belongs to the caller that opened it: the clientId of the token plus its sub claim. A request from another caller gets 404, the same as an unknown id. MCP Server Auth shows how the verifier sets them.
To serve spec 2026 only, set sessions to 'reject'. A spec 2025 request then gets the SDK rejection. A client that speaks only spec 2025 cannot use that server.
import { createMCPServer } from '@tanstack/ai-mcp/server'
const server = createMCPServer({
name: 'weather',
version: '1.0.0',
sessions: 'reject',
})Each spec 2025 client now gets the behavior that you chose.