Fetching from the wire…
Infra2026-09-01 · source-backed
PR #2629 merged August 31, implementing the client half of RFC 9449 per draft SEP-1932 across 18 files and 1,753 added lines (GitHub). A DpopSession generates a non-extractable keypair and builds proofs with a fresh jti, a query/fragment-stripped htu, and an ath binding when presenting a token, plus per-origin nonce tracking for both authorization and resource servers. It applies at the fetch layer, so StreamableHTTPClientTransport, SSEClientTransport and withOAuth all inherit it through one integration path, and hosts that do not implement provider.dpop() keep Bearer-only behavior.
Each link below shares sources, entities, or timing with this story.
If you wrote an MCP server before July, it's on a protocol shape the maintainers have already removed. Not deprecated-with-a-migration-window. Removed from the spec. MCP lead maintainers David Soria Parra and Den Delimarsky published an updated roadmap on August 22, and the re...
Ryan Dahl announced celld on August 5. It's a daemon built from V8, S3, SQLite, LTX and Tokio that runs the exact Cloudflare Workers and Durable Objects JavaScript APIs and configuration on hardware you own. The architecture is the interesting part, not the API compatibility....
v1.0.81 (August 27) lists MCP 2026-07-28 support across CLI, SDK, IDE and in-memory clients, and hooks now receive the current OTel trace context: inputs gain traceparent plus tracestate when the span carries vendor state, and command hooks get matching env vars, so hook work...
PR #29081, merged August 26 and in nightly v0.59.0-nightly.20260827, enforces RFC 9728 §7.7 and RFC 8414 constraints across MCP OAuth metadata discovery, dynamic client registration, and token exchange. It requires HTTPS for remote endpoints with HTTP allowed only for loopback...
3,364 stars since its August 17 creation. Every action against a computer, file, MCP server or UI component routes through a single gateway that resolves the target, decides it against policy, writes an audit row, then acts or refuses while naming the rule. Each bot gets its o...
gemini-cli's August 27 nightly prevents SSRF in MCP OAuth metadata discovery and authentication (PR #29081), google/adk-python v1.39.1 added a Host header check on its CLI server plus artifact reference scoping, and pydantic-ai v2.35.3 scopes safe_download cookies to their ori...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.