MCP-STL-004
Server does not rely on prior requests over the same connection
“Servers MUST NOT rely on prior requests over the same connection to establish context (e.g., capabilities, protocol version, client identity). Every request supplies this metadata in its _meta field.” — spec anchor
How to fix this
Read capabilities, protocol version and client identity from each request's own `_meta`, never from an earlier request on the same connection.
How the validator checks this
Probe P1.2, against a streamable-http server on the modern protocol. What it reports:
- pass
- A second request carrying its own complete _meta was answered without relying on any earlier exchange
Quoted from the probe that runs this check, so it cannot drift from what the validator actually reports.
This rule is checked deterministically: a fail here is a certain violation, not an inference.
Checked in the same request as MCP-STL-008.
Check your own server against this rule
The validator makes real protocol requests and reports this rule as pass, warn or fail alongside the other 78. Validate a server or read how the check works.
Other Statelessness and session removal rules
- MCP-STL-001Server never mints or echoes Mcp-Session-Id
- MCP-STL-002A client-supplied Mcp-Session-Id is ignored, not required
- MCP-STL-003A cold modern request succeeds with no prior handshake
- MCP-STL-005GET on the MCP endpoint returns 405
- MCP-STL-006DELETE on the MCP endpoint returns 405
- MCP-STL-007Last-Event-ID is ignored — streams are not resumable
- MCP-STL-008tools/list does not vary per connection