MCP Spec Evolution
July 28, 2026: MCP's biggest revision ever — the protocol went stateless. Sessions, the handshake, and server-initiated callbacks are gone. Here's what changed and why it matters.
▶ Watch this reelWhat you'll learn
- Versioned specs
- The stateless core
- What replaced the old features
- Extensions, auth & lifecycle
Remember this
- 2026-07-28: stateless core — handshake and sessions removed; every request self-contained with its own metadata; round-robin scaling
- MRTR replaces all server-initiated callbacks: interim input_required result → client gathers answers → original call re-issued with responses
- Roots, Sampling, Logging + HTTP+SSE deprecated (12-month floor); Tasks and MCP Apps graduated into a reverse-DNS extensions framework; OAuth hardened
Versioning
- Date-stamped revisions (2025-03-26 … 2025-11-25 → 2026-07-28), negotiated per connection.
- Fifth revision; largest since auth; Linux Foundation (Agentic AI Foundation) governance.
Stateless core
- REMOVED: sessions,
Mcp-Session-Id, initialize/initialized handshake, ping, SSE resumability. - Every request self-contained: version + identity + capabilities in
_meta. - Round-robin scaling; state → explicit handles in tool args (visible to the model).
MRTR replaces server-initiated callbacks
- elicitation / sampling / roots → one pattern:
resultType: input_required→ client gathers → retry withinputResponses.
Deprecated (12-month floor)
- Roots, Sampling, Logging, HTTP+SSE transport, OAuth DCR (→ Client ID Metadata Documents).
New structure
- Extensions framework (reverse-DNS, versioned): Tasks (poll
tasks/get), MCP Apps (sandboxed UI), Enterprise Managed Auth. - Hardened OAuth (RFC 9207 issuer binding) · cacheable catalogs (ttlMs/cacheScope) · Mcp-Method/Name header routing.
- Tier 1 SDKs: TypeScript, Python, Go, C# (Rust beta).
Code: The migration checklist for a 2025-era server
# From 2025-11-25 → 2026-07-28 — check your servers against this:
# REMOVED (no grace period):
# □ Mcp-Session-Id header + any server-side session store
# □ initialize/initialized handshake → send version/caps per-request in _meta
# □ notifications/initialized, ping, logging/setLevel
# □ HTTP GET endpoint + resources/subscribe → subscriptions/listen
# DEPRECATED (≥12 months, do NOT adopt in new code):
# □ roots/list → explicit path arguments
# □ sampling/createMessage → MRTR input_required
# □ elicitation → MRTR input_required
# □ logging → server-side observability (AG-08)
# □ HTTP+SSE transport → Streamable HTTP
# □ OAuth Dynamic Client Registration → Client ID Metadata Documents
# NEW (adopt):
# □ Mcp-Method / Mcp-Name headers for gateway routing
# □ ttlMs/cacheScope on capability catalogs
# □ Long-running work → io.modelcontextprotocol/tasks (poll tasks/get)
# □ Rich UI results → MCP Apps extension (sandboxed iframe)