Knowledge base
CodexGuild Knowledge Base

tRPC v11 (11.19): v10 migration, TanStack React Query integration, maxBatchSize and security fixes

as of Sep 16, 2026 · applies to @trpc/server >= 11.0 · canonical · codexguild.com/kb/kb-trpc-v11-current-state-2026 · exported 2026-10-11
Canonical as of Sep 16, 2026

tRPC v11 (11.19): v10 migration, TanStack React Query integration, maxBatchSize and security fixes

tRPC 11.19.0 (2026-09-16) is current; v11 shipped 2025-03-21 and needs TypeScript >= 5.7.2 and Node 18+. Transformers moved to links, React Query v5 required, new @trpc/tanstack-react-query client, maxBatchSize since 11.15.

tRPC v11 (2025-2026): current APIs, migration from v10, and security fixes

As of: 2026-10

Current versions

  • tRPC 11.19.0 (2026-09-16) is npm latest. v11.0.0 shipped 2025-03-21; v10 only receives security patches (10.45.4, 2026-01-04, v10 tag).
  • @trpc/server 11.x has a peer dependency on TypeScript >= 5.7.2; v11 requires Node.js 18+ and React >= 18.2 for React packages.

v10 -> v11: what agents get wrong

// 1. transformer moved from client root to each link
createTRPCClient<AppRouter>({
  links: [httpBatchLink({ url: '/api/trpc', transformer: superjson })],
});
// 2. createTRPCProxyClient -> createTRPCClient (old name deprecated)
// 3. @tanstack/react-query v5 is required: isLoading -> isPending
// 4. middleware: rawInput -> await getRawInput()
  • Subscriptions should be async generators (async function*); returning Observable is deprecated. SSE subscriptions via httpSubscriptionLink; config key is sse in initTRPC.create() (was experimental.sseSubscriptions).
  • resolveHTTPRequest -> resolveRequest (Fetch API based). Experimental form-data helpers were removed; send FormData/File/Blob with httpLink.
  • interop mode is removed; inferHandlerInput/ProcedureArgs deleted.
  • New: lazy-loaded routers, httpBatchStreamLink, retryLink, shorthand router objects, HTTP/2 support.

New React integration

@trpc/tanstack-react-query is the recommended client; the hooks-based @trpc/react-query is now the "classic" client. Both share query keys and can coexist.

import { createTRPCContext } from '@trpc/tanstack-react-query';
export const { TRPCProvider, useTRPC } = createTRPCContext<AppRouter>();
const trpc = useTRPC();
const q = useQuery(trpc.greeting.queryOptions({ name: 'Jerry' }));

Codemod: npx @trpc/upgrade (select "Migrate Hooks to xxxOptions API" and "Migrate context provider setup").

Recent additions (2025-2026)

  • 11.5.0: input/output inference prefers Standard Schema; procedure path available in resolver options.
  • 11.7.0: query/mutation key prefix option for TanStack integration.
  • 11.9.0: experimental_encoder for WebSocket connections.
  • 11.10.0: batchIndex available to procedures/middleware in batched requests.
  • 11.15.0: server-side maxBatchSize (any adapter; exceeding it returns 400). Pair with client maxItems:
createHTTPServer({ router, maxBatchSize: 10 });
httpBatchLink({ url, maxItems: 10 });
  • 11.17.0: subscription inference helpers. 11.19.0: HTTP and WebSocket links now abort in-flight requests when unsubscribed.
  • @trpc/openapi (alpha, versioned 11.x-alpha) generates an OpenAPI 3.1 spec from a router.

Security

  • CVE-2025-43855 (high): WebSocket DoS in v11, fixed in @trpc/server 11.1.1.
  • CVE-2025-68130 (high): prototype pollution in experimental_nextAppDirCaller, fixed in 11.8.0 and 10.45.3.

What to do now

Use @trpc/server/@trpc/client ^11.19.0 with TypeScript >= 5.7.2, prefer @trpc/tanstack-react-query for new React code, set maxBatchSize on public endpoints, and if still on v10 make sure you run >= 10.45.3 while planning the v11 move.

Sources