Observed Signal · Jul 30, 2026 · Technical Release · Source: DEV Community · Impact: 3/5 · Sentiment: Positive

MCP Moves to Stateless 2026-07-28 Spec

Executive Signal Summary

The Model Context Protocol (MCP) 2026-07-28 specification shipped final on July 28, 2026, introducing a major era shift from stateful (handshake/session) communication to a stateless model where every request is self-contained via a fully-qualified _meta envelope. The release requires servers to implement server/discover, changes error codes, deprecates Roots, Sampling, Logging and HTTP+SSE on a 12-month clock, and ships new v2 TypeScript packages (@modelcontextprotocol/client@2 and @modelcontextprotocol/server@2) alongside the legacy SDK. The stateless workflow enables simple round-robin scaling but introduces a critical security risk: an unsigned requestState blob that must be integrity-protected. The article provides a concrete server migration checklist, gotchas, testing advice, and mitigation recommendations (sign requestState, audit error codes, run both eras in parallel).

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Protocol-level change that affects server/client interoperability, scaling, and security; relevant to teams integrating LLM/tooling or building MCP-compatible services, but not a major platform-wide shift.

SIGNAL RADAR

Track Real-Time Protocol Migration / Infrastructure Signals & Market Shifts

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • The 2026-07-28 MCP spec shipped final on July 28, 2026 (RC locked May 21, 2026).
  • The new spec is stateless: sessions/initialize and Mcp-Session-Id are removed; all protocol metadata must appear in _meta on every request and Mcp-Method / Mcp-Name are required headers.
  • TypeScript support now ships as two packages: @modelcontextprotocol/client@2 and @modelcontextprotocol/server@2 while @modelcontextprotocol/sdk remains at 1.x for legacy servers.
  • server/discover is mandatory in the new era; Roots, Sampling, Logging, and HTTP+SSE are deprecated with a 12-month removal window (no earlier than July 2027).
  • A new security risk exists: an unsigned requestState blob can be tampered with by clients; the spec mandates integrity protection and the SDK does not automatically sign it.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jul 30, 2026
Original Coverage Title: “MCP Went Stateless: Migrating to the 2026-07-28 Spec (and Proving It Works)”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Technical Release / Protocol InfrastructureJul 2, 2026

MCP 2026-07-28 Release Candidate: Key Migration Guide

The Model Context Protocol (MCP) 2026-07-28 release candidate is a major specification revision and a compatibility test for clients, servers, SDKs, gateways, and developer tools. The candidate was locked on 2026-05-21 and the final spec is scheduled for 2026-07-28; the intervening period is intended for real-world testing and migration. Major changes include a stateless protocol layer (per-request _meta), new transport headers (e.g., MCP-Protocol-Version and Mcp-Method), a server/discover method, support for server-rendered MCP Apps in sandboxed iframes, tightened OAuth2/OpenID Connect requirements (iss validation and Dynamic Client Registration changes), deprecation annotations for Roots/Sampling/Logging, and full JSON Schema 2020-12 for tool schemas. The release also standardizes a missing-resource error to JSON-RPC -32602. The article provides migration checklists and testing guidance for implementers.

Read assessment
InfrastructureJul 20, 2026

Model Context Protocol adds stateless session support

The Model Context Protocol (MCP), an interoperability standard that lets AI models access external data and services, is being updated to adopt a more stateless approach to server-side session handling. The official specification has been public since May, and Arcade published a clear explanation of the change, which alters how session IDs are managed so servers can scale more easily behind load balancers. The update aims to reduce the operational complexity and cost of running MCP servers at large scale, potentially lowering barriers for first-party integrations that let chatbots access calendars, databases, and internal tools. The change is a technical infrastructure refinement rather than a user-facing feature, but it may materially affect how the ecosystem develops.

Read assessment
Large Language Models (LLM) & AIJun 15, 2026

Model Context Protocol (MCP) — what it is and how to build a server

The article explains the Model Context Protocol (MCP), an open standard (originally created at Anthropic, MIT licensed) that standardizes how LLM-powered applications access context and tools from external data sources. MCP uses JSON-RPC 2.0 and supports three transports (stdio, Server-Sent Events, and Streamable HTTP). The protocol defines server primitives (Resources, Tools, Prompts) and client primitives (Sampling, Roots, Elicitation), and begins each session with a capability-negotiation handshake. The Python SDK (mcp on PyPI) includes FastMCP for building servers; the SDK was at v1.27.2 in May 2026 and a 2.0.0 alpha with an updated transport layer was published in June 2026. The article includes a Python server example, notes common pitfalls, and points readers to the MCP Inspector (npx @modelcontextprotocol/inspector) for testing.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.