MCP Spec Evolution

July 28, 2026: MCP's biggest revision ever — the protocol went stateless. Sessions, the handshake, and server-initiated callbacks are gone. Here's what changed and why it matters.

▶ Watch this reel

What you'll learn

  1. Versioned specs
  2. The stateless core
  3. What replaced the old features
  4. Extensions, auth & lifecycle

Remember this

Versioning

Stateless core

MRTR replaces server-initiated callbacks

Deprecated (12-month floor)

New structure

Code: The migration checklist for a 2025-era server

# From 2025-11-25 → 2026-07-28 — check your servers against this:

# REMOVED (no grace period):
#  □ Mcp-Session-Id header + any server-side session store
#  □ initialize/initialized handshake → send version/caps per-request in _meta
#  □ notifications/initialized, ping, logging/setLevel
#  □ HTTP GET endpoint + resources/subscribe → subscriptions/listen

# DEPRECATED (≥12 months, do NOT adopt in new code):
#  □ roots/list            → explicit path arguments
#  □ sampling/createMessage → MRTR input_required
#  □ elicitation           → MRTR input_required
#  □ logging               → server-side observability (AG-08)
#  □ HTTP+SSE transport    → Streamable HTTP
#  □ OAuth Dynamic Client Registration → Client ID Metadata Documents

# NEW (adopt):
#  □ Mcp-Method / Mcp-Name headers for gateway routing
#  □ ttlMs/cacheScope on capability catalogs
#  □ Long-running work → io.modelcontextprotocol/tasks (poll tasks/get)
#  □ Rich UI results → MCP Apps extension (sandboxed iframe)