A new specification for the Model Context Protocol (MCP), the standard that connects AI agents to external applications, went live on July 28, 2026. The centerpiece of this fifth revision is a shift to a design that no longer keeps connection state. The revision also formalizes a framework for extensions and rebuilds authorization around how enterprises actually run identity today. Anthropic says support for the new spec is rolling out across Claude products.
No More Handshake, No More Session ID
The biggest change is that the foundation of the protocol moves from bidirectional, stateful communication to a plain request/response model. There is no handshake at the start of a connection and no session ID, so any request can be handled by any server instance.
That sounds like a quiet change, but it matters a great deal to anyone operating a server. Because the old design assumed connection state was preserved, you needed an always-on server and some mechanism to route a given user's requests back to the same instance. With a stateless core, the same server can sit on serverless infrastructure that spins up per request, or on edge infrastructure that runs closer to the user.
MCP servers now span everything from small personal utilities to integrations with core enterprise systems, and whether you can simply scale horizontally as usage grows has a direct effect on operating cost. The move to a stateless core widens that door.
MCP Apps and Tasks Become Formal Extensions
The second pillar is that extensions have been reorganized into a versioned framework. MCP Apps and Tasks, both discussed for some time, now ship as official extensions under that framework.
MCP Apps lets a server render an interactive interface directly inside the conversation. Users can see what a connector is doing and keep working with it in place, which removes the need to jump to another tab or application. Tasks is an extension for handling long-running work, providing the groundwork for running time-consuming agent processes reliably.
What matters is that adding capabilities like these no longer requires rewriting the core protocol. The core stays small while features arrive as explicitly versioned extensions. That separation makes it easier for implementations to declare exactly which extensions they support, which in turn reduces the bugs that come from mismatched expectations. The revision also documents a formal policy for how deprecated features are handled.
Authorization Aligned With Production OAuth 2.0 and OIDC
The third pillar is a rebuild of authorization. Authorization now aligns with OAuth 2.0 and OIDC as they are actually deployed in production, which means connecting an MCP server to a corporate identity platform such as Microsoft Entra or Okta no longer requires custom workarounds.
Anyone trying to let an AI agent touch internal systems hits the authentication wall first. Whether existing identity management can be used as-is often decides whether a deployment moves forward or stalls. Having the spec meet production practice partway should help adoption inside companies.
For scale, MCP SDKs now exceed 400 million downloads per month, a fourfold increase this year. As a way to connect AI agents to applications, MCP has effectively settled into the position of an industry standard.
What Is Already Live on the Claude Side
Anthropic says support for the new spec is being rolled out across Claude products. Its connector directory now lists more than 950 MCP servers, used by large numbers of people every day.
The features added on the Claude side this year line up with the new spec. Alongside in-conversation interfaces via MCP Apps, there is now a way for administrators to provision connectors across an entire organization. An admin authorizes a connector once, users inherit access through their existing identity groups, and the connection is already in place at first login, with no setup work for the end user.
Developers building connectors get a dashboard showing how their published connectors perform across Claude product surfaces. It tracks adoption, surfaces errors and latency, and breaks usage down by product, which makes it much easier to keep improving a connector after launch.
One more piece, offered as a research preview, is MCP tunnels. It lets Claude reach MCP servers inside a private network without exposing a public endpoint. No inbound firewall rules and no IP allowlisting on the origin are required, which is aimed squarely at bringing internal tools to Claude as they are.
Summary
MCP 2026-07-28 rests on three changes: a stateless core that increases operational freedom, MCP Apps and Tasks carved out as versioned extensions, and authorization aligned with the identity platforms enterprises already run. It is a revision that hardens the specification in unglamorous ways, but it is a step forward both for people building servers and for the teams bringing them inside a company. As support widens across Claude products, the range of systems that can be connected looks set to keep growing.
