Observed behavior
With mcp 1.6.1, MCP::Client#call_tool returns normally when the server's response omits jsonrpc or sets it to "1.0". Both variants were accepted in three independent runs over stdio and three over Streamable HTTP, using the legacy 2025-11-25 lifecycle.
The response keeps the matching request ID and valid tool result; only the jsonrpc field is changed.
Expected behavior
Reject these responses as invalid JSON-RPC 2.0 envelopes rather than return a successful tool result. JSON-RPC 2.0 section 5 requires the response's jsonrpc value to be exactly "2.0".
Reproduction
Requires Ruby, the mcp gem at 1.6.1, and Node.js/npm. Save this as repro.rb, then run ruby repro.rb:
require "json"
gem "mcp", "1.6.1"
require "mcp"
%w[missing-jsonrpc invalid-jsonrpc-version].each do |variant|
adapter = MCP::Client::Stdio.new(
command: "npx",
args: ["-y", "mcp-failure-lab@0.12.0", "serve"],
read_timeout: 5,
)
begin
client = MCP::Client.new(transport: adapter)
client.connect(
client_info: { name: "jsonrpc-repro", version: "1.0.0" },
protocol_version: "2025-11-25",
mode: :legacy,
)
response = client.call_tool(
name: "malformed_message",
arguments: { variant: variant },
)
puts "#{variant}: accepted #{JSON.generate(response)}"
ensure
adapter.close
end
end
malformed_message changes the response envelope for that call: missing-jsonrpc removes the field, and invalid-jsonrpc-version sets it to "1.0". Initialization uses valid responses.
Environment and evidence
The separate variant containing both result and error raised an error; a subsequent ping using the same client succeeded. This report is limited to the two jsonrpc variants above. Modern lifecycle behavior was not tested.
Observed behavior
With
mcp1.6.1,MCP::Client#call_toolreturns normally when the server's response omitsjsonrpcor sets it to"1.0". Both variants were accepted in three independent runs over stdio and three over Streamable HTTP, using the legacy2025-11-25lifecycle.The response keeps the matching request ID and valid tool result; only the
jsonrpcfield is changed.Expected behavior
Reject these responses as invalid JSON-RPC 2.0 envelopes rather than return a successful tool result. JSON-RPC 2.0 section 5 requires the response's
jsonrpcvalue to be exactly"2.0".Reproduction
Requires Ruby, the
mcpgem at 1.6.1, and Node.js/npm. Save this asrepro.rb, then runruby repro.rb:malformed_messagechanges the response envelope for that call:missing-jsonrpcremoves the field, andinvalid-jsonrpc-versionsets it to"1.0". Initialization uses valid responses.Environment and evidence
mcp1.6.1, Node.js 22mcp-failure-lab@0.12.02025-11-25The separate variant containing both
resultanderrorraised an error; a subsequent ping using the same client succeeded. This report is limited to the twojsonrpcvariants above. Modern lifecycle behavior was not tested.