Updated
Updated · O'Reilly Media · Sep 23
MCP Spec Gets Biggest Overhaul Since 2024 Launch, Adding Stateless Core and 12-Month SSE Offramp
Updated
Updated · O'Reilly Media · Sep 23

MCP Spec Gets Biggest Overhaul Since 2024 Launch, Adding Stateless Core and 12-Month SSE Offramp

3 articles · Updated · O'Reilly Media · Sep 23

Summary

  • July 28, 2026 brought MCP’s largest revision since its November 2024 debut, recasting the protocol core as stateless and adding formal support for long-running tasks, interactive apps and tighter authorization.
  • Those changes target production failures seen at scale: session-based design clashed with horizontally scaled fleets, while teams had been hand-rolling polling, callbacks and approval flows outside the spec.
  • The update also aligns authorization with OAuth 2.1 and OpenID Connect and starts a 12-month deprecation path for the legacy HTTP+SSE transport, signaling a more mature governance model.
  • Adoption has surged alongside the rewrite, with nearly 10,000 registered servers, Tier 1 SDK downloads in the tens of millions monthly, and both TypeScript and Python SDKs topping 1 billion total downloads.
  • The article argues MCP’s real challenge now is governance: 2026 security research found widespread path-traversal patterns, plus command-injection, SSRF and tool-description poisoning risks across public servers.

Insights

Could the 2026 stateless update meant to secure AI workflows actually create untraceable ghost interactions within your enterprise systems?
If AI agents now decide which enterprise tools to run, who is responsible when poisoned metadata triggers a catastrophic system breach?
With a massive attack success rate on live servers, are developers unknowingly handing hackers the keys to their local machines?