Six weeks ago I argued that MCP configs were a fresh attack surface and that the protocol's auth story was an implementation detail every enterprise was rebuilding from scratch. The 2026-07-28 release candidate, locked May 21, addresses the protocol half of that problem.

The most visible change is that MCP is now stateless at the protocol layer. The initialize/initialized handshake is gone (SEP-2575). The Mcp-Session-Id header is gone (SEP-2567). Protocol version and client capabilities now travel in _meta on every request. A stateless MCP server can sit behind a plain round-robin load balancer with no sticky sessions and no shared session store. This is the change ops teams wanted.

The deeper change is the authorization hardening. A series of authorization-focused SEPs align MCP with OAuth 2.0 and OpenID Connect. Clients must validate the iss parameter per RFC 9207 [3] (SEP-2468). Clients now declare their OIDC application_type during Dynamic Client Registration (SEP-837), avoiding the common failure mode where CLI clients are treated as web apps and localhost redirect URIs are rejected. Registered credentials are bound to the issuing authorization server (SEP-2352). This standardizes the enterprise deployment model many teams had already built around MCP, including the registry-layer assumptions from B2.

Tasks moved out of the core to an extension. MCP Apps (SEP-1865) lets servers ship sandboxed HTML UIs that can route actions through the same audit and consent flow as direct tool calls. A formal feature lifecycle (SEP-2577) requires twelve months between deprecation and removal.

What didn't change: the config files on disk. The protocol hardens transport and authorization. It doesn't touch ~/.claude, ~/.cursor, ~/.codex, or the project-scoped .cursor/mcp.json and .vscode/mcp.json files that often hold long-lived tokens for every system an agent touches. The Bitwarden CLI harvester from April still works in the new world. The protocol grew up. The local credential surface still hasn't.

If you build on MCP, the migration window was the ten weeks between this piece and final publication on July 28. (Update, 2026-09-23: that window has closed; what follows is preserved as a dated read of the candidate spec.) The wire format changes are substantial enough that compatibility testing should start now. For production operators, the stateless transport and OAuth alignment are worth the effort. For security teams, the trust boundary thesis still holds: most of securing an agent is everything around the agent, and the configs on disk remain the part nobody has fixed.