The thread worth tracking this month isn't a model release. It's the Model Context Protocol shedding the parts that made it awkward to operate, and the maintainers' updated roadmap (published August 22 by lead maintainers David Soria Parra and Den Delimarsky) signalling that the next round of work is retrieval-shaped.
Start with the July 28 spec, the largest revision since launch. The headline is a stateless protocol core: the initialize handshake and the session header are gone, and negotiation data — protocol version, client name, capabilities — rides along with each request. The practical consequence is boring in the best way. A remote MCP server that previously needed sticky sessions and a shared session store can now sit behind an ordinary load balancer and have any instance answer any request. The spec also adds required method and tool-name headers, so gateways can route agent traffic without parsing JSON bodies, plus cacheable list responses. Tasks graduated from experimental to an official extension (contributed by AWS): `tools/call` returns a handle and the client drives progress via `tasks/get`, `tasks/update`, `tasks/cancel`. `tasks/list` was cut — without sessions, enumerating all tasks isn't safe. Cloudflare's Agents SDK supported the spec from day zero; Bedrock AgentCore takes the stateless core too.
InfoQ captured the obvious objection: a chunk of developers read this as MCP rediscovering REST. Fair, and mostly beside the point. The value was never novelty in the transport; it was one envelope that every client already speaks. Nango's take is the useful corrective for anyone building connectors — removing protocol sessions removes none of the provider-specific work. You still authorize each user, store and refresh credentials, handle rate limits, and trace failures across a dozen SaaS APIs.
Where this lands for knowledge systems
The August roadmap names five priorities: agentic messaging primitives, HTTP-native transport unification, agent identity and enterprise-ready security, improved primitives, and SDK developer experience. Two matter directly if you build retrieval.
Progressive discovery. Once an agent can reach hundreds of servers over cheap stateless HTTP, the tool catalog itself becomes too large to stuff into context. Selecting the right tools for a query is the same problem as selecting the right chunks — ranking, filtering, and staged disclosure over a corpus that no longer fits. If you already run a hybrid retriever over documents, expect to run something like it over tool descriptions.
Agent identity. The July release already moved authorization toward production OAuth and OIDC practice: issuer validation, credentials bound to their authorization server, a shift from Dynamic Client Registration toward Client ID Metadata Documents, and an Enterprise-Managed Authorization extension that lets admins govern MCP access through Okta or Entra ID.
That last piece is the one to watch. Permission-aware retrieval has been the unglamorous blocker on every internal knowledge deployment. Standardizing who the agent *is* — separately from who the user is — is a precondition for solving it, and it isn't solved yet.

