Official releaseAgent Protocols / Standards

New MCP Roadmap Makes Agent Identity and Enterprise Security One of Five Priority Areas

Following the 2026-07-28 specification, MCP maintainers published a new roadmap with five priorities: agentic messaging, HTTP transport unification, agent identity and enterprise security, improved primitives with progressive discovery, and SDK experience.

Key answer

The new MCP roadmap, published by the Model Context Protocol core maintainers on August 22, 2026, sets the direction for the next specification release. Its most enterprise-relevant goal is giving unattended cloud agents verifiable identities through DPoP, Workload Identity Federation, and standard token exchange instead of pasted API keys and long-lived tokens.

On August 22, 2026, Model Context Protocol (MCP) lead maintainers David Soria Parra and Den Delimarsky published an updated roadmap setting the direction for the specification release after 2026-07-28. It is organized into five priority areas, each with responsible Core Maintainers and one or more Working Groups.

The five areas are: agentic messaging primitives (server-initiated events such as webhooks and channels, plus maturing the Tasks extension); HTTP-native transport unification, extending the HTTP approach to other deployment modes including local servers; agent identity and enterprise security; improved primitives, standardizing a single tool-result contract and starting progressive tool discovery so that connecting to a server with a hundred tools no longer means paying for the whole catalog up front; and SDK developer experience and conformance testing.

Identity is the item that matters most for enterprises. The roadmap notes that MCP authorization today assumes a person approving access in a browser, while more callers are cloud workloads with their own identity, agents acting for an absent user, or agents delegating narrower authority to sub-agents. Maintainers plan to drive adoption of DPoP (Demonstrating Proof of Possession), define a path through Workload Identity Federation and standard token exchange, and keep working with the IETF OAuth and related working groups.

This is a roadmap, not a ratified specification: it gives no release date for the next version, and proposals still go through the SEP process. Governance changes accompany it: a formal Contributor Ladder, Working Groups triaging SEPs in their own areas, and a feature lifecycle and deprecation policy, with SEPs inside the priority areas getting expedited review.

The roadmap also recaps what the previous cycle delivered, which explains where these priorities start from: protocol-level sessions and the initialization handshake are gone so servers can scale horizontally without holding state; server/discover lets clients learn supported versions and capabilities up front; list results are cacheable; and authorization gained issuer validation, issuer-bound client credentials, and Client ID Metadata Documents (CIMD) as the preferred client registration path. On tool results, it names a concrete pain point: a single tool response can carry the same output in more than one form, and server developers cannot know which form a client will put in front of the model, so the goal is one clear contract.

What to watch is the concrete content and timing of the agent-identity SEPs, and when major MCP clients, gateways, and identity providers support DPoP and token exchange.

X Cube view

Enterprises running their own MCP servers or gateways should stop putting long-lived API keys into agent configurations and move toward short-lived, revocable credentials bound to workload identity. They should also manage tool-catalog size as a cost and accuracy issue: until progressive discovery is standardized, every additional tool adds context overhead to every conversation.