v1.3.0

mattermost-community/focalboardv1.3.0May 21, 2026by release-please[bot]

AI Summary

This release introduces tool-level scope validation for MCP auth, adds new SQL admin tools, implements SQLCommenter for client metadata, and fixes various bugs including Looker integration issues and path traversal prevention.

Key Highlights

  • Implement MCP auth tool-level scopes validation
  • Add new cloud-sql-admin tools (execute-sql-many, sql-many)
  • Implement SQLCommenter for client metadata
  • Fix path traversal and enforce toolset boundaries

New Features

  • Implement MCP auth tool-level scopes validation
  • Add cloud-sql-admin-execute-sql-many and cloud-sql-admin-sql-many
  • Setup SQLCommenter and allow client metadata
  • Propagate client IP from incoming MCP requests

Full Release Notes

## [1.3.0](https://github.com/googleapis/mcp-toolbox/compare/v1.2.0...v1.3.0) (2026-05-21)


### Features

* **auth:** Implement MCP auth tool-level scopes validation ([#3049](https://github.com/googleapis/mcp-toolbox/issues/3049)) ([c528985](https://github.com/googleapis/mcp-toolbox/commit/c528985149060adb648f85b5486391bd72d6727e))
* **looker:** Propagate client IP from incoming MCP requests to downstream SDK calls ([#3253](https://github.com/googleapis/mcp-toolbox/issues/3253)) ([75da6c2](https://github.com/googleapis/mcp-toolbox/commit/75da6c21dd29d7e8e70eac1b747e3946097e7459))
* Setup SQLCommenter and allow client metadata  ([#3064](https://github.com/googleapis/mcp-toolbox/issues/3064)) ([9f1f9b3](https://github.com/googleapis/mcp-toolbox/commit/9f1f9b321dcd05cce55dbff1bbaebfc44a4c9907))
* **tool/cloudsqladmin:** Add `cloud-sql-admin-execute-sql-many` and `cloud-sql-admin-sql-many` ([#3083](https://github.com/googleapis/mcp-toolbox/issues/3083)) ([ef300a8](https://github.com/googleapis/mcp-toolbox/commit/ef300a8401e5d5458bc08186fe4d3529e4bab15a))


### Bug Fixes

* **auth/generic:** Fix generic auth expiration field and integration with `authRequired` ([#3251](https://github.com/googleapis/mcp-toolbox/issues/3251)) ([f4d16c0](https://github.com/googleapis/mcp-toolbox/commit/f4d16c09b12c4d3297a9aedca706c9830382a4e3))
* Enforce toolset/promptset boundary on tools/call and prompts/get ([#3036](https://github.com/googleapis/mcp-toolbox/issues/3036)) ([c739b80](https://github.com/googleapis/mcp-toolbox/commit/c739b805ba5ab0e156016fe7c8ce67bc1c138e5a))
* **tools/http:** Prevent path traversal and base path scope escape ([#3218](https://github.com/googleapis/mcp-toolbox/issues/3218)) ([80a6602](https://github.com/googleapis/mcp-toolbox/commit/80a66021205e032a424fff87b3dc6d92da58aa77))
* **tools/looker:** Return a 401 error to MCP client when Looker returns a 401 ([#3233](https://github.com/googleapis/mcp-toolbox/issues/3233)) ([4f409a3](https://github.com/googleapis/mcp-toolbox/commit/4f409a3283d533bddcf4756a1d58c228744b3931))
* **tools/looker:** Strip wrapping quotes from filter values for unquoted parameters ([#3273](https://github.com/googleapis/mcp-toolbox/issues/3273)) ([1e3de96](https://github.com/googleapis/mcp-toolbox/commit/1e3de96daa9bc06253d05b0caf63d499878fb70e))
* **tools:** Initialize query result slices to empty array ([#3250](https://github.com/googleapis/mcp-toolbox/issues/3250)) ([60ddf48](https://github.com/googleapis/mcp-toolbox/commit/60ddf487468bfd11c7f9346f16a33a8986f89f84))

| **OS/Architecture**                                                                                       | **Description**                                                                                                          | **SHA256 Hash**                                                     |
| --------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------- |
| [linux/amd64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.3.0/linux/amd64/toolbox)        | For **Linux** systems running on **Intel/AMD 64-bit processors**.                                                        | 08e00671737ff4fd6c7af25a1a0c5da43b3657c4a435fd0a381757876d694b45    |
| [darwin/arm64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.3.0/darwin/arm64/toolbox)      | For **macOS** systems running on **Apple Silicon** (M1, M2, M3, etc.) processors.                                        | b16ea9f864b0b9c711dff0b08a663e6dee5969b41033fe6d05412dc04e85cfb8    |
| [darwin/amd64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.3.0/darwin/amd64/toolbox)      | For **macOS** systems running on **Intel processors**.                                                                   | 94d6fd02a4bbc67ad9dcf69d5f36af5a584735d2fb2ebb0023e91cb701e7a98a    |
| [windows/amd64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.3.0/windows/amd64/toolbox.exe) | For **Windows** systems running on **Intel/AMD 64-bit processors**.                                                      | 4661004b9cd37ea258d82332a24b3955fd9a258a5b8b6da471584cd7cb3de35d    |