You'll notice Notable
No documentation found
MCP server URLs with embedded credentials are now rejected, and plain-http can be explicitly allowed.
The shared URL schema used for MCP server URLs and similar fields now rejects URLs containing embedded userinfo (user:pass@host), reporting a dedicated CREDENTIALED_URL_MESSAGE error. A new allowHttp option can be set on the schema to permit plain-http URLs beyond the existing loopback-http allowance.
Names in the bundleallowHttp