Menu

Release: lastfm-mcp v2.6.0 — Sign-in without client registration

Project
lastfm-mcp
Summary
Last.fm MCP server.
URL
lastfm-mcp.com

MCP clients can now sign in by pointing at a web address that describes them, with no registration step first. This is the method the current MCP spec prefers, and existing connections keep working as before. All five changes behind it came from Jonathan Hitchcock, the project’s first outside contributor.

What’s new

  • Sign-in with Client ID Metadata Documents. A client can use an HTTPS URL as its ID, and the server reads the client’s name and allowed redirect addresses from the document at that URL. Some clients support nothing else. The documents Claude Code and VS Code publish are accepted as they are.
  • If a client’s document can’t be fetched or doesn’t validate, sign-in stops with a plain Invalid client_id error.
  • Dynamic client registration is still on, so clients that rely on it are unaffected and nobody needs to sign in again.
  • The landing page at lastfm-mcp.com has current setup steps for Claude, two more example questions, and a link to the privacy policy.

Fixes

  • server_info, the discovery card, and /health report the real server version. They said 1.0.0 before.

Under the hood

  • Four indirect dependencies (fast-uri, hono, ip-address, qs) moved to patched versions after new security advisories. None of them ship in the deployed Worker, and npm audit on production dependencies is back to zero.
  • Wrangler is pinned to 4.124.0, the version the test runner uses, so local dev, deploys, and tests share one runtime. Dev and deploys had been on a Wrangler more than a year older.
  • CI fails on unformatted code, after a one-time cleanup of files that had drifted.
  • The suite is at 183 tests, up from 174. The new ones include full sign-in round trips using the document shapes Claude Code and VS Code publish.