The July 2026 MCP update introduces a stateless core

Agent tool servers just lost their excuse for sticky sessions. The Model Context Protocol’s 2026-07-28 spec turns MCP from a bidirectional stateful protocol into a request/response stateless one — so ordinary load-balanced HTTP finally works.
The official MCP blog post calls the stateless core the headline. Tier-1 SDKs (TypeScript, Python, Go, C#) shipped the same day, with Rust in beta. For teams hosting MCP at scale — the ones duct-taping session affinity and shared storage — this is the infrastructure release, not a feature parade.
What died with the initialize handshake
The initialize / initialized exchange and the Mcp-Session-Id header are retired (SEP-2575, SEP-2567). Every request carries its own protocol version, client identity, and capabilities in _meta. Clients that want capabilities up front get an optional server/discover RPC; it is not required.
Any request can land on any instance behind a plain round-robin load balancer without shared session storage. Application state is not banned — if you need continuity, mint an explicit handle from a tool and pass it back as an argument. Visible to the model beats hidden transport session goo. That is the right default for agent systems.
New routing headers, cacheable lists, and MRTR
Streamable HTTP requests must now include Mcp-Method and Mcp-Name headers (SEP-2243). Gateways, rate limiters, and WAFs can route and meter without parsing JSON bodies.
List responses from tools/list, prompts/list, resources/list, and resources/read carry ttlMs and cacheScope (SEP-2549), with deterministic ordering so clients can cache catalogs and keep upstream prompt caches stable across reconnects.
Multi Round-Trip Requests (MRTR) replace server-initiated elicitation/create, sampling/createMessage, and roots/list calls that previously needed a held-open stream (SEP-2322). Mid-call, a server can return resultType: "input_required" with the questions it needs answered; the client retries the original call with inputResponses. Approvals and missing parameters no longer demand a permanent bidirectional pipe.
Auth, extensions, and the twelve-month clock
Authorization keeps getting teeth. Authorization servers should return the iss parameter per RFC 9207, and clients must validate it before redeeming a code (SEP-2468). Client credentials bind to the issuer that minted them (SEP-2352). Dynamic Client Registration (DCR) is formally deprecated in favor of Client ID Metadata Documents (CIMD); DCR still works for compatibility but is on a removal path. Desktop and CLI apps also get cleaner application_type handling for localhost redirects during DCR (SEP-837).
Tasks leave the experimental core for the io.modelcontextprotocol/tasks extension, with poll-based tasks/get and tasks/update (SEP-2663). The extensions framework also covers MCP Apps and Enterprise Managed Authorization (EMA). Roots, Sampling, and Logging are deprecated (SEP-2577), as is legacy HTTP+SSE transport — still functional for at least twelve months under a formal deprecation policy. Plan upgrades; stop adopting dead ends.
Who needs the Tier-1 SDK bump this week
If you run production MCP servers, treat same-day SDK updates as the migration start gun. TypeScript, Python, Go, and C# speak 2026-07-28 now. Anyone clinging to session IDs will feel the break; the blog says early testing feedback softened that landing.
Ecosystem quotes on the post come from AWS (Bedrock AgentCore), Cloudflare, Microsoft Foundry, Google Cloud, and a long list of hosts already betting on MCP as default agent plumbing. Analysis: the community chose breaking changes over papering over scale limits. That is how protocols grow up.
Watch whether enterprise hosts finish MRTR, Tasks, and CIMD support on the twelve-month clock — and whether sticky-session workarounds finally leave your architecture diagrams. MCP 2026-07-28 does not invent agents. It makes the tool layer look like the rest of the web: stateless, cacheable, routable, and operable at load-balancer scale.




[…] and callback verification. Polling and streaming delivery are unsupported by this integration. Our July MCP update report covers the underlying protocol […]