DISPATCH · 29 SEP 2026
The MCP 2026-07-28 specification explained for web teams
What the stateless release changes for a company that exposes its product or site through an MCP server.
Agent Readiness Compare editors · Spec status checked September 2026
Agent Readiness Compare editors · · 6 min read
Answer
The Model Context Protocol specification dated 2026-07-28 turns MCP into a stateless request and response protocol: no initialize handshake, no session IDs, method and tool names in HTTP headers, cacheable list results, stricter authorization and a twelve-month deprecation window. For a web team, an MCP server can now run on ordinary HTTP infrastructure, including serverless platforms, and gateways can route and authorise requests without reading the JSON body.
On this page
1.What is MCP, briefly?
MCP is an open protocol that connects LLM applications (hosts and their clients) to servers that offer tools, resources and prompts, using JSON-RPC 2.0 messages. For a website or SaaS product, an MCP server is the usual way to let an agent perform API-backed tasks such as looking up an order, creating a record or checking availability. See our MCP standard page.
2.What changed on 28 July 2026?
The release post by lead maintainers David Soria Parra and Den Delimarsky lists these changes.
- Stateless core. MCP moved "from a bidirectional stateful protocol into a request/response stateless protocol". The initialize and initialized exchange and session IDs are gone.
- Multi round-trip requests (MRTR). Instead of holding a stream open so a server can ask the client a question mid-call, the server returns a result saying input is required, and the client retries with the extra information.
- Header-based routing. Method and tool names travel in HTTP headers (
Mcp-MethodandMcp-Name, per Cloudflare's summary), so gateways can route and authorise on headers. - Cacheable list results. Responses carry
ttlMsandcacheScopeso clients can cache tool and resource lists. - Authorization hardening. RFC 9207 issuer validation is added, and Dynamic Client Registration is deprecated in favour of Client ID Metadata Documents.
- Tasks as an extension. Long-running Tasks move from the experimental core into the official extensions framework, with poll-based operations.
- Deprecation policy. Deprecated features get a minimum twelve-month window before removal.
3.Why does statelessness matter to a web team?
A stateful protocol needs a server that remembers each client session. That fits poorly with load balancers, CDNs and serverless functions, which may send each request to a different instance. With the handshake and session IDs removed, each request carries what it needs. Cloudflare's post of 6 August 2026 makes this point for Workers, and Vercel documents deploying MCP servers with its mcp-handler package. In practice, an MCP endpoint can now be operated much like any other HTTP API.
It also changes monitoring. With no session to follow, logs and metrics are per request, and the method and tool name headers give each request a label you can count, alert on and rate-limit.
4.What should you change in an existing MCP server?
- Upgrade the SDK first. Cloudflare's summary notes that the specification shipped with updated TypeScript, Python, Go and C# SDKs.
- Remove session assumptions. State stored against a session ID needs another home, such as your own store keyed by user or task.
- Replace held-open elicitation with MRTR. If a tool asks the user for input mid-call, adopt the input-required pattern.
- Review authorization. If you rely on Dynamic Client Registration, plan a move to Client ID Metadata Documents or pre-registered clients, and validate the issuer.
- Set cache hints on list results where your tool list changes rarely.
- Use the headers at the edge. With method and tool names in headers, a gateway or WAF rule can rate-limit or block specific tools.
5.What comes next for MCP?
The MCP roadmap published on 22 August 2026 lists five priorities: agentic messaging primitives, HTTP-native transport unification and hardening, agent identity and enterprise-ready security (naming DPoP and Workload Identity Federation), improved primitives including progressive discovery, and SDK developer experience. Separately, A2A, the protocol for agent-to-agent tasks, joined the Linux Foundation-directed Agentic AI Foundation on 27 August 2026, and its announcement names MCP as a sibling project there.
6.Does this affect WebMCP?
Not directly. WebMCP is a W3C Community Group proposal for tools that a web page registers inside the browser, using the user's existing session. It shares MCP's idea of a tool but not its transport. Cloudflare opened a developer preview on 6 August 2026 that injects WebMCP tools at the edge. See MCP and WebMCP for how the two divide the work.
7.Sources
- MCP blog, The 2026-07-28 Specification
- MCP blog, The New MCP Roadmap
- MCP specification
- Cloudflare, The next generation of MCP
- Vercel, Deploy MCP servers to Vercel
- Cloudflare, Give any website a WebMCP interface
- A2A project blog
- WebMCP repository
Reviewed Sep 2026