- Sources: Model Context Protocol blog, release candidate post, HN 49088058
- Summary: The maintainers published the final 2026-07-28 specification at 09:00 UTC. David Soria Parra, named in the post, calls it MCP's most important release since remote MCP first launched over a year ago. TypeScript, Python, Go, and C# SDKs shipped the same day, with the Rust SDK in beta. The release is breaking. The initialize and initialized handshake is removed under SEP-2575, and the
Mcp-Session-Id header and the protocol-level session are removed under SEP-2567, so protocol version, client identity, and client capabilities now travel in _meta on every request and any request can land on any instance behind a round-robin load balancer. A client that still wants server capabilities up front uses a new optional server/discover RPC. Streamable HTTP requires Mcp-Method and Mcp-Name headers under SEP-2243 so gateways route without parsing bodies. Server-initiated elicitation, sampling, and roots/list are replaced by Multi Round-Trip Requests under SEP-2322, which return resultType of input_required for the client to retry with inputResponses. List and resource-read results carry ttlMs and cacheScope under SEP-2549. Tasks moves out of the experimental core into an extension under SEP-2663, with poll-based tasks/get and a new tasks/update. Roots, Sampling, Logging, and the legacy HTTP plus SSE transport are deprecated under a policy guaranteeing at least twelve months before removal. Dynamic Client Registration is deprecated in favour of Client ID Metadata Documents, and clients must validate the RFC 9207 iss parameter under SEP-2468. The adoption figure in the post, close to half a billion Tier 1 SDK downloads a month with the TypeScript and Python SDKs each past one billion total, is the maintainers' own and is not independently checked. The post carries 15 attributed quote blocks, 13 of them from outside the two MCP maintainers, naming AWS, Cloudflare, Microsoft, Google Cloud, Figma, Netlify, Supabase, and Honeycomb among others, which are statements of intent rather than shipped support. - Comments: The Hacker News submission points at the release candidate post rather than the release post. That candidate post carries a published date of 2026-05-21 and a modified date of 2026-07-24, so the discussion thread does not date today's event.
- Why it matters: Every team operating a remote MCP server now has dated migration work against a stated twelve-month deprecation clock, and the removed session means a server no longer needs sticky routing.
- Follow-up: Watch for the removal dates attached to Roots, Sampling, Logging, and the HTTP plus SSE transport, and for the Rust SDK leaving beta.
send feedback on this story