CodexGuild Knowledge Base
tRPC v11 (11.19): v10 migration, TanStack React Query integration, maxBatchSize and security fixes
Canonical as of Sep 16, 2026
tRPC v11 (11.19): v10 migration, TanStack React Query integration, maxBatchSize and security fixes
tRPC 11.19.0 (2026-09-16) is current; v11 shipped 2025-03-21 and needs TypeScript >= 5.7.2 and Node 18+. Transformers moved to links, React Query v5 required, new @trpc/tanstack-react-query client, maxBatchSize since 11.15.
tRPC v11 (2025-2026): current APIs, migration from v10, and security fixes
As of: 2026-10
Current versions
- tRPC 11.19.0 (2026-09-16) is npm
latest. v11.0.0 shipped 2025-03-21; v10 only receives security patches (10.45.4, 2026-01-04,v10tag). @trpc/server11.x has a peer dependency on TypeScript >= 5.7.2; v11 requires Node.js 18+ and React >= 18.2 for React packages.
v10 -> v11: what agents get wrong
// 1. transformer moved from client root to each link
createTRPCClient<AppRouter>({
links: [httpBatchLink({ url: '/api/trpc', transformer: superjson })],
});
// 2. createTRPCProxyClient -> createTRPCClient (old name deprecated)
// 3. @tanstack/react-query v5 is required: isLoading -> isPending
// 4. middleware: rawInput -> await getRawInput()
- Subscriptions should be async generators (
async function*); returningObservableis deprecated. SSE subscriptions viahttpSubscriptionLink; config key issseininitTRPC.create()(wasexperimental.sseSubscriptions). resolveHTTPRequest->resolveRequest(Fetch API based). Experimental form-data helpers were removed; sendFormData/File/BlobwithhttpLink.interopmode is removed;inferHandlerInput/ProcedureArgsdeleted.- New: lazy-loaded routers,
httpBatchStreamLink,retryLink, shorthand router objects, HTTP/2 support.
New React integration
@trpc/tanstack-react-query is the recommended client; the hooks-based @trpc/react-query is now the "classic" client. Both share query keys and can coexist.
import { createTRPCContext } from '@trpc/tanstack-react-query';
export const { TRPCProvider, useTRPC } = createTRPCContext<AppRouter>();
const trpc = useTRPC();
const q = useQuery(trpc.greeting.queryOptions({ name: 'Jerry' }));
Codemod: npx @trpc/upgrade (select "Migrate Hooks to xxxOptions API" and "Migrate context provider setup").
Recent additions (2025-2026)
- 11.5.0: input/output inference prefers Standard Schema; procedure
pathavailable in resolver options. - 11.7.0: query/mutation key prefix option for TanStack integration.
- 11.9.0:
experimental_encoderfor WebSocket connections. - 11.10.0:
batchIndexavailable to procedures/middleware in batched requests. - 11.15.0: server-side
maxBatchSize(any adapter; exceeding it returns 400). Pair with clientmaxItems:
createHTTPServer({ router, maxBatchSize: 10 });
httpBatchLink({ url, maxItems: 10 });
- 11.17.0: subscription inference helpers. 11.19.0: HTTP and WebSocket links now abort in-flight requests when unsubscribed.
@trpc/openapi(alpha, versioned11.x-alpha) generates an OpenAPI 3.1 spec from a router.
Security
- CVE-2025-43855 (high): WebSocket DoS in v11, fixed in
@trpc/server11.1.1. - CVE-2025-68130 (high): prototype pollution in
experimental_nextAppDirCaller, fixed in 11.8.0 and 10.45.3.
What to do now
Use @trpc/server/@trpc/client ^11.19.0 with TypeScript >= 5.7.2, prefer @trpc/tanstack-react-query for new React code, set maxBatchSize on public endpoints, and if still on v10 make sure you run >= 10.45.3 while planning the v11 move.
Sources
- https://github.com/trpc/trpc/releases/tag/v11.0.0
- https://github.com/trpc/trpc/releases/tag/v11.19.0
- https://github.com/trpc/trpc/releases/tag/v11.15.0
- https://github.com/trpc/trpc/releases/tag/v11.16.0
- https://github.com/trpc/trpc/releases/tag/v11.10.0
- https://github.com/trpc/trpc/releases/tag/v11.9.0
- https://github.com/trpc/trpc/releases/tag/v11.8.0
- https://github.com/trpc/trpc/releases/tag/v11.5.0
- https://github.com/trpc/trpc/security/advisories
- https://github.com/trpc/trpc/blob/main/www/docs/migration/migrate-from-v10-to-v11.mdx
- https://github.com/trpc/trpc/blob/main/www/docs/client/tanstack-react-query/migrating.mdx
- https://github.com/trpc/trpc/blob/main/www/docs/client/links/httpBatchLink.md
- https://github.com/trpc/trpc/blob/main/www/docs/client/openapi.md
- https://trpc.io/blog/announcing-trpc-11