The Model Context Protocol's 2026-07-28 specification went final on July 28 and is described by its maintainers, David Soria Parra and Den Delimarsky, as the largest revision since the protocol launched. Three weeks in, the consequences are showing up in ecosystem work — the official C# SDK shipped a v2.0, Microsoft's App Service team published migration guidance, and security firms have started picking apart the new attack surface. If you expose an internal knowledge base, a vector index, or an enterprise search layer over MCP, this is the change that touches your infrastructure, not your prompts.
The headline is a stateless protocol core, delivered through six Specification Enhancement Proposals. The initialization handshake and protocol-level sessions are gone; every request is self-contained, so any available server instance can serve it. The previous stable spec, 2025-11-25, pinned a client to one server through a session ID. Removing that eliminates session affinity and shared session storage as deployment requirements — which is why the pitch is serverless and edge deployment, horizontal scaling, and a lower cost floor for running a remote MCP server. Flavio Copes' write-up makes the necessary caveat: your database, auth system, rate limits and tool implementations still have to scale. One source of infrastructure complexity is removed, not the hard ones.
Two additions matter specifically for retrieval workloads. Requests now carry `Mcp-Method` and `Mcp-Name` headers, so a load balancer can route without parsing the request body — meaning you can send a heavy hybrid-search or rerank call to instances with warm index caches and keep cheap metadata lookups on commodity nodes, at the proxy layer rather than in application code. And list results are now cacheable, which is the difference between re-serializing a large tool or resource catalog on every cold request and serving it from a CDN. Teams with hundreds of connector-derived tools should feel that first.
The other addition is Multi Round-Trip Requests, which is how mid-call interaction survives statelessness: a tool can pause to ask the user to approve a destructive action — deleting data, provisioning a paid resource — before it executes. Worth designing around if your knowledge tools do writes, not just reads.
The migration is not free
Per Microsoft's guidance, the breaking bits are concrete: `tasks/list` is removed, Roots, Sampling and Logging are deprecated, and the "resource not found" error code moves from `-32002` to the standard `-32602`. Sampling's deprecation is the one to check first if your server design assumed it could call back into the client's model — for example, to rewrite a query or summarize a retrieved chunk before returning it. That inference now has to live on your side of the boundary, with your own model budget and latency.
Equixly's read is the right frame for security review: each of these solves a real operational problem, and each changes the attack surface. Self-contained requests mean authorization and tenant scoping get re-established per call, with nothing sticky to lean on. The spec hardens authorization, but the burden of getting per-request scoping right lands on you.

