MCP 2026-07-28 explained
The 2026-07-28 revision is the largest since MCP launched. These pages explain each change in plain language, with the verbatim specification sentence behind every normative claim — the same sentences our 79-rule validator checks against.
What changed in 2026-07-28
The complete change list for the largest revision since MCP launched.
Statelessness and Mcp-Session-Id
Sessions and the initialize handshake are gone. What replaced them.
The Mcp-Method header
The required routing header, and the -32020 HeaderMismatch error.
ttlMs and cacheScope
Required caching fields on five result types, and the public/private trap.
RFC 9207 iss validation
The OAuth mix-up defence — and why your server can't implement it.
MRTR — Multi Round-Trip Requests
Server-initiated requests are gone. How a server asks for input now.
Error codes
The partitioned range, three new codes, and two that must not be emitted.
server/discover
The required method that replaced the initialize handshake.
Moving a working server across? The migration guide covers the same changes as an ordered procedure with before/after code. Something already broken? Start from the symptom. Or read all 79 rules directly.