createmcps.com

MCP-STL-001

Server never mints or echoes Mcp-Session-Id

Remove protocol-level sessions and the Mcp-Session-Id header from the Streamable HTTP transport.spec anchor

How to fix this

Stop minting and stop echoing `Mcp-Session-Id`. Protocol-level sessions were removed from the Streamable HTTP transport, so the header has no meaning in this revision.

How the validator checks this

Probe P5.3, against a streamable-http server on the modern protocol. What it reports:

pass
No Mcp-Session-Id minted or echoed
fail
Returned Mcp-Session-Id: … — the header was removed from the transport; a modern server must neither mint nor echo it

Quoted from the probe that runs this check, so it cannot drift from what the validator actually reports.

This rule is checked deterministically: a fail here is a certain violation, not an inference.

Checked in the same request as MCP-STL-002.

Check your own server against this rule

The validator makes real protocol requests and reports this rule as pass, warn or fail alongside the other 78. Validate a server or read how the check works.

Other Statelessness and session removal rules

  • MCP-STL-002A client-supplied Mcp-Session-Id is ignored, not required
  • MCP-STL-003A cold modern request succeeds with no prior handshake
  • MCP-STL-004Server does not rely on prior requests over the same connection
  • MCP-STL-005GET on the MCP endpoint returns 405
  • MCP-STL-006DELETE on the MCP endpoint returns 405
  • MCP-STL-007Last-Event-ID is ignored — streams are not resumable
  • MCP-STL-008tools/list does not vary per connection