Skip to content

basalt / mcp-core/src / McpSessions

Class: McpSessions ​

Defined in: mcp-core/src/sessions.ts:53

The session table of the Streamable HTTP transport: ids issued on initialize, required on every later request, each bound to the principal that opened it, expiring when idle and capped in number.

Binding is what makes the id safe to accept: a request whose principal differs from the session's is treated exactly like one naming an unknown session (so the id of someone else's session reveals nothing and cancels nothing). In-memory and per process — behind several replicas, route a session's requests to one replica (sticky sessions) or run stateless.

Constructors ​

Constructor ​

> new McpSessions(options?, now?): McpSessions

Defined in: mcp-core/src/sessions.ts:58

Parameters ​

options? ​

McpSessionOptions = {}

now? ​

() => number

Returns ​

McpSessions

Accessors ​

size ​

Get Signature ​

> get size(): number

Defined in: mcp-core/src/sessions.ts:64

Live sessions (expired ones may still be counted until the next purge).

Returns ​

number

Methods ​

create() ​

> create(principal): McpSession

Defined in: mcp-core/src/sessions.ts:69

Open a session for principal and return it (its id goes in the response header).

Parameters ​

principal ​

string

Returns ​

McpSession


delete() ​

> delete(id, principal): boolean

Defined in: mcp-core/src/sessions.ts:103

End a session (HTTP DELETE). False when principal has no such live session.

Parameters ​

id ​

string | undefined

principal ​

string

Returns ​

boolean


resolve() ​

> resolve(id, principal): McpSession | undefined

Defined in: mcp-core/src/sessions.ts:86

The live session id names, provided principal opened it — refreshing its idle timer. undefined for an unknown, expired or foreign session.

Parameters ​

id ​

string | undefined

principal ​

string

Returns ​

McpSession | undefined

Released under the MIT License.