Roadmap
Shipped in v3
The v3 release is available now. It includes named meshes with tools, prompts, and resources; local tools; request/result metadata stripping; catalog sanitization; and dispatcher-aware hiding. Policy, consent, OpenTelemetry, Redis, and Postgres are released companion packages. Audit format v2 supports tool/prompt evidence, keyed verification, subject erasure, and awaited session sealing. HTTP sessions can resume through persistent session and event adapters.
Remaining boundaries
- Full session re-execution is not SSE reconnect replay and is not implemented in v3.
- Mesh resource templates and subscriptions remain unavailable.
- Prompt catalog middleware, prompt hiding, and prompt pass-through options remain deferred.
- Delegation is unsigned attribution; interoperable signed hops require a trust and key-distribution design.
- Persistent adapters do not make policy counters or audit chains distributed.
- Compliance reports and managed audit storage are outside the current library contract.
There is no released @mcpose/fintech-identity package; the host resolves its own identity profile (ADR-0020).
No additional audit label rotation ships merely because the core version is v3 (ADR-0019).
These boundaries are not dated delivery promises.
Track active work in the library issues and architecture records.