July 28, 2026
The protocol
goes stateless.
The specification published on 2025-11-25 has been replaced. The release candidate locked on May 21. The final published on July 28. The spec calls it a breaking change in those words, and every line below links to the pull request that made it.
the spec being replaced retired jul 28
-> initialize a handshake before anything else
<- Mcp-Session-Id your state lives on their server
<- sampling, roots/list the server calls the client back
-> Last-Event-ID resume a broken stream
from July 28 the stateless shape
-> any request _meta carries protocol version and capabilities
<- resultType complete, or input_required
-> follow-up request multi round-trip: the client always initiates
-> server/discover capabilities on demand; servers MUST implement it
Same tools, same servers; what changes is who is allowed to start a sentence. Every method above has its row and its pull request in the list below.
- removed SEP-2575
initialize, notifications/initialized Every request now carries its own protocol version and client capabilities in _meta.
- removed SEP-2567
Mcp-Session-Id, protocol level sessionsCross call state becomes server minted handles, passed back as ordinary tool arguments.
- removed SEP-2575
Last-Event-ID, SSE resumabilityA broken response stream loses the in flight request. Clients re-issue it as a new one.
- removed SEP-2575
The HTTP GET endpoint, resources/subscribe, resources/ unsubscribe Replaced by subscriptions/
listen: one long lived POST response stream carrying the change notifications a client opted into. A server still exposing GET for notifications, or answering resources/ subscribe, is talking to nobody. - removed SEP-2575
ping, logging/setLevel, notifications/ roots/ list_changed Log level moves per request into _meta.
- added SEP-2575
server/discover Servers MUST implement it, to advertise supported versions, capabilities and identity.
- added SEP-2322
resultType on every resultEither complete, or input_required for a multi round trip interim result.
- added SEP-2322
Multi Round-Trip RequestsReplaces every server initiated request: roots/
list, sampling/ createMessage, elicitation/ create. - added SEP-2243
Mcp-Method, Mcp-NameHeaders on Streamable HTTP POST. Mcp-Method on every request, Mcp-Name only on tools/
call, resources/ read and prompts/ get. A header that disagrees with the body is rejected. - added SEP-2549
ttlMs, cacheScopeNow required on every list and resource read result, so clients can cache and stop polling.
- deprecated SEP-2577
Roots, Sampling, LoggingStill fully functional, but new implementations should not adopt them.
- deprecated PR #2858
Dynamic Client RegistrationIn favor of Client ID Metadata Documents. Kept for servers that do not support CIMD yet.
- moved SEP-2663
TasksOut of the core protocol and into an official extension, io.modelcontextprotocol/
tasks.
The previous pattern of server-initiated requests is no longer supported. This is a breaking change.
And yet nothing breaks that day.
The same release adopts a feature lifecycle policy with a minimum twelve-month deprecation window, so a server written against the old spec keeps working for a year while you move. This is not an emergency, and a tool that measures things for a living should be the last one to tell you it is.
It is simply the date on which does mine still comply stops
being a matter of opinion. That is what efaimo check --mcp
is for, and the commands page shows it run against the official
reference server.
One delta this page does not show. Everything above is what changed
from the 2025-11-25 specification, but the
release candidate that locked on 2026-05-21
is also not the document that published: server identity moved out
of DiscoverResult into _meta, and three
error codes were renumbered. efaimo had read the candidate, so for
four days after publication its own rules reported identity as
unknown for precisely the servers that had finished migrating. The
delta, and the commands to reproduce it, are
an Agent Skill.