MCP 2026-07-28 Specification Ships with a Stateless Core, Header-Based Routing, and Authorization Hardening
MCP's largest revision since launch removes the initialize handshake and sessions, replaces server-initiated requests with Multi Round-Trip Requests, requires Mcp-Method/Mcp-Name headers, and deprecates DCR in favor of CIMD.
MCP 2026-07-28 is the Model Context Protocol specification released on July 28, 2026. It turns MCP from a bidirectional stateful protocol into a stateless request/response protocol, so MCP servers can scale horizontally behind ordinary load balancers like any HTTP service, and hardens authorization with RFC 9207 issuer validation and Client ID Metadata Documents (CIMD).
On July 28, 2026, MCP lead maintainers David Soria Parra and Den Delimarsky released the Model Context Protocol 2026-07-28 specification. They also reported adoption figures: close to half a billion monthly downloads across Tier 1 SDKs, with the TypeScript and Python SDKs each past one billion total downloads.
The core change is statelessness. The initialize/initialized handshake and the Mcp-Session-Id header are gone; each request carries its protocol version, client identity, and capabilities in _meta, with an optional server/discover call. Any request can land on any instance behind a round-robin load balancer without shared storage, and servers that need state across calls are advised to mint explicit handles that the model passes back. Multi Round-Trip Requests (MRTR) replace server-initiated elicitation, sampling, and roots requests that needed held-open streams. Streamable HTTP requests must carry Mcp-Method and Mcp-Name headers so gateways, rate limiters, and WAFs can route and meter without parsing JSON bodies, and list responses carry ttlMs and cacheScope hints.
On authorization, servers should return the iss parameter per RFC 9207 and clients must validate it before redeeming a code; client credentials are bound to the issuing authorization server; and Dynamic Client Registration (DCR) is formally deprecated in favor of Client ID Metadata Documents (CIMD). The release also formalizes an extensions framework, moving Tasks into the io.modelcontextprotocol/tasks extension alongside MCP Apps and Enterprise Managed Authorization (EMA).
There are breaking changes. Roots, Sampling, and Logging are deprecated, and the legacy HTTP+SSE transport is officially deprecated, each with at least a twelve-month window; implementations that relied on session IDs need to migrate. The TypeScript, Python, Go, and C# Tier 1 SDKs support the new version, and the Rust SDK supports it in beta.
The announcement also lists day-one support from several vendors. AWS says the new specification and stateless core are available in Amazon Bedrock AgentCore, and that the Tasks extension was contributed by AWS; Cloudflare's Agents SDK supports it from day zero, running MCP servers directly in Workers; Microsoft describes a unified Foundry toolbox MCP endpoint that centralizes governance, identity, and observability. Supabase notes that running statelessly had made elicitation hard to support, and that MRTR now lets tools confirm with the user before acting, such as the cost of a new project or a query that would delete data.
What to watch is how quickly MCP clients and gateways adopt the new version and what compatibility issues appear while old and new versions coexist. The maintainers' follow-up roadmap on August 22 made agent identity a priority for the next cycle.
Enterprises running MCP servers on a private AI platform can now deploy and scale them as ordinary stateless HTTP services and enforce permissions, rate limits, and audit at the gateway using Mcp-Method/Mcp-Name headers without inspecting payloads. They should also inventory internal servers still using DCR, HTTP+SSE, Sampling, or session IDs and schedule migration within the twelve-month deprecation window.


