The most consequential thing in our space right now isn't a model — it's a transport change. The Model Context Protocol published its 2026-07-28 specification, the largest revision since launch: MCP is now stateless, with a governed extensions system and hardened authorization . Google's engineering writeup on the migration landed in the past week, and it's the clearest explanation yet of why this matters to anyone running knowledge connectors in production.
The bottleneck was session pinning
If you've deployed remote MCP servers fronting a vector index, a Confluence corpus, or a warehouse, you've already hit this. The headline change is the removal of the initialize/initialized handshake and the Mcp-Session-Id header. Previously, an MCP session was pinned to whichever server instance handled the initial handshake, which meant deployments needed sticky sessions or shared state. Google describes hitting a hard wall deploying MCP across cloud-native infrastructure: the original protocol-level session model required persistent state, handshakes, and session pinning — stateful transports that broke the core tenets of modern cloud-native scalability.
For retrieval workloads this was always the wrong shape. Search is naturally stateless and embarrassingly parallel; the protocol was forcing affinity onto a layer that didn't need it. The stateless core unlocks horizontal scaling and standard HTTP routing. Concretely: no more shared session store between replicas, no sticky-session config in your load balancer, and a replica can die mid-conversation without killing the client's context.
What you actually have to change
The migration list is real work, not a version bump. Tasks move out of the experimental core into the io.modelcontextprotocol/tasks extension, with a poll-based tasks/get and a new tasks/update. Change notifications move from the old HTTP GET endpoint to a single subscriptions/listen stream that clients opt into per notification type. Roots, Sampling, and Logging are deprecated — they'll keep working for at least twelve months, but new implementations shouldn't adopt them. The legacy HTTP+SSE transport is also officially deprecated, with a year-long offramp. On auth, Dynamic Client Registration is formally deprecated in favor of CIMD , and six SEPs bring MCP's authorization closer to production OAuth 2.0 and OpenID Connect deployments .
The subscriptions change is the one to think about if you push index-freshness notifications to clients. Opt-in-per-type is better hygiene, but it means clients that silently relied on the old GET stream stop hearing about updates.
Timelines were deliberately unhurried: the release candidate locked May 21, the final spec published July 28, and the ten-week window existed for SDK maintainers to validate against real workloads . All four Tier 1 SDKs speak 2026-07-28 as of launch day; the Rust SDK supports it in beta. Google's Go SDK shipped v1.7.0 on July 28 and powers integrations including the GitHub MCP Server.
Who should care: platform teams operating server fleets, not application teams calling them. Upgrading is opt-in — nothing changes until both you and your clients act , and on Bedrock AgentCore Gateway the gateway advertises which versions it speaks through a single configuration field, with clients selecting a version per request . Dual-advertise, migrate clients, then drop the old version.

