MCP-STL-001
Server never mints or echoes Mcp-Session-Id
“Remove protocol-level sessions and the Mcp-Session-Id header from the Streamable HTTP transport.” — spec anchor
How to fix this
Stop minting and stop echoing `Mcp-Session-Id`. Protocol-level sessions were removed from the Streamable HTTP transport, so the header has no meaning in this revision.
How the validator checks this
Probe P5.3, against a streamable-http server on the modern protocol. What it reports:
- pass
- No Mcp-Session-Id minted or echoed
- fail
- Returned Mcp-Session-Id: … — the header was removed from the transport; a modern server must neither mint nor echo it
Quoted from the probe that runs this check, so it cannot drift from what the validator actually reports.
This rule is checked deterministically: a fail here is a certain violation, not an inference.
Checked in the same request as MCP-STL-002.
Check your own server against this rule
The validator makes real protocol requests and reports this rule as pass, warn or fail alongside the other 78. Validate a server or read how the check works.
Other Statelessness and session removal rules
- MCP-STL-002A client-supplied Mcp-Session-Id is ignored, not required
- MCP-STL-003A cold modern request succeeds with no prior handshake
- MCP-STL-004Server does not rely on prior requests over the same connection
- MCP-STL-005GET on the MCP endpoint returns 405
- MCP-STL-006DELETE on the MCP endpoint returns 405
- MCP-STL-007Last-Event-ID is ignored — streams are not resumable
- MCP-STL-008tools/list does not vary per connection