MCP's 2026-07-28 specification lands in three days with a stateless core and six authorization proposals
The final MCP spec dated 2026-07-28 closes a ten-week validation window that opened May 21. It removes session management and handshakes entirely — a remote server that previously needed sticky sessions, a shared session store, and gateway deep packet inspection can now sit behind plain round-robin load balancing — and adds Mcp-Method and Mcp-Name headers so gateways route without inspecting message bodies. Six proposals align authorization with OAuth 2.0 and OpenID Connect including issuer validation and refresh token handling; Tasks and MCP Apps graduate to versioned extensions; and Roots, Sampling, and Logging are formally deprecated under a new policy guaranteeing minimum 12-month removal windows. Anyone running a remote MCP server should read the migration notes this week.
↳ Follow the thread