MCP 2026 年 9 月 28 日大版本更新解读:无状态架构定稿与迁移清单
What Is the New MCP Update? September 2026's Biggest-Ever Release, With Receipts
作者解读 2026 年 9 月 28 日 MCP 的大版本更新:无状态架构定稿、强制校验 OAuth iss 参数、与 Okta 合建的企业托管授权、MCP Apps 和 MCP Tasks 升级为官方扩展,以及 12 个月弃用政策(最早移除时间为 2027 年 7 月)。
What Is the New MCP Update? September 2026's Biggest-Ever Release, With Receipts
The short answer: on September 28, 2026, the Agentic AI Foundation (a Linux Foundation directed fund) shipped the biggest release in MCP's history — finalized stateless architecture, hardened OAuth authorization, a formal 12-month deprecation policy, and MCP Apps + MCP Tasks graduated to official extensions. Co-creator David Soria Parra said "some people jokingly call it a v2, and I think in spirit that's accurate."
The part nobody is saying: statelessness makes million-tool-call-per-day MCP server farms cheap to run — and where tool calls are billed per call, every single one becomes a payment decision.
The distinction the field doesn't make
Search "MCP update" today and you'll get July stories: Medium's migration map, hackernoon's deprecation read, Nordic APIs. All cover the 2026-07-28 spec revision — the removal of the initialize handshake and Mcp-Session-Id. The Sept-28 release is a different release: the enterprise finalization of that same long arc.
The receipts: dated, sourced
- Sept 28, 2026 (VentureBeat exclusive): "the largest update since Anthropic released it twenty months ago" — "finally makes agentic AI ready for massive enterprise production deployments." Interviews with Soria Parra, Den Delimarsky, Mazin Gilbert.
- Stateless, finalized: no protocol-level session, no sticky routing, no shared session store. "Your MCP client can speak to a load balancer that connects with any server." Tens of thousands of agents per deployment now architecturally possible.
-
Auth hardening: mandatory validation of the OAuth issuer (
iss) parameter — closes an entire class of mix-up attacks. Delimarsky explicitly: no known exploitation — "preventive engineering, not incident response." - Enterprise Managed Authorization (built with Okta): corporate IdP becomes the authoritative gatekeeper for MCP server access — corporate credentials, not personal ones.
- Apps + Tasks graduated: MCP Apps (server-rendered interactive UIs inside AI clients) and MCP Tasks (durable task handles — disconnect, crash, restart, resume polling) are now official extensions. Plus multi-round-trip requests.
- Governance: AAIF went from ~40 members (Dec 2025) to 240 — the fastest-growing foundation in Linux Foundation history. Anthropic's contribution share fell below half.
- 12-month deprecation policy: nothing in the 2026-07-28 cohort (Roots, Sampling, Logging, Dynamic Client Registration) can be removed before July 2027. "It's more of a feedback period than a definite period" (Soria Parra).
- The honest costs: bigger payloads (state rides the wire); out-of-band server logging is gone in the stateless model — the team scraped all of GitHub and "basically nobody" used it. "Probably a handful of people — quite literally a handful of people."
Why this makes the payment gate MORE important, not less
Three connections, none forced:
- Enterprise Managed Authorization is identity-side gating, standardized. The protocol shipped corporate-IdP-as-gatekeeper as an extension. That's the authorization instinct made official — now it needs the judgment layer behind it: not just who may call, but whether this particular call should fire.
- Stateless scale multiplies paid tool calls. Any request landing on any instance behind a load balancer is exactly the shape of per-call-billed agent infrastructure. At a million calls a day, each call wants a scored decision — ≥0.80 auto-execute, 0.50–0.79 hold, <0.50 block — not a blanket credential.
- Apps + Tasks are where the money will hide. A server-rendered "Pay now" form and a resumable paid job are both payment decisions inside the protocol. The multi-round-trip request shape is the wire-level space where a confirm band (0.50–0.79) lives between negotiation and execution.
Live this morning: the gate scores paid MCP tool calls
Our confidence gate (decider local-heuristic-v1, calibrated=false), scored ~09:20 EDT Sept 28:
- Receipt 1 — single paid tool call, in budget: 0.6457 → ADVISORY (hold). One paid x402 MCP tool (0.001 USDC/call, 4.20 of a 50 USDC daily budget spent). Even the routine case doesn't auto-execute without a wired, calibrated decider.
- Receipt 2 — uncapped bulk paid calls: 0.7964 → ADVISORY (hold). Same surface, no spending cap, no per-call authorization, no audit record — just under the 0.80 auto-act line. Stateless scale doesn't buy a free pass; it buys scrutiny.
Do it yourself: 5 steps, this week
- Find your stateful assumptions: grep for
initialize,Mcp-Session-Id, anything keyed to a connection. Replace capability exchange withserver/discover, carry protocol version and capabilities in per-request_meta. - Make cross-call state explicit: mint handles (draft IDs, job IDs, receipt IDs) as ordinary tool arguments. Expiring, ownable, log-searchable.
- Put yourself on the 12-month clock: Roots → tool parameters/resource URIs; Sampling → direct LLM calls; protocol logging → stderr/OpenTelemetry; DCR → explicit OAuth registration. Earliest removal: July 2027.
- Adopt Enterprise Managed Authorization for anything paid or corporate — wire it before your auditors ask.
- Gate every paid tool call with a scored decision. At stateless scale there is no per-request human; the score is the human.
Honest caveats
- The release details come from a single outlet's exclusive (VentureBeat, Sept 28, 2026) — interviews, not a second independently verified source.
- The "July vs today" distinction is my framing from the community migration field and the VentureBeat piece — no canonical release-notes delta from the protocol team yet.
- Gate receipts are from a local-heuristic-v1 decider (calibrated=false) — an honest demo of the pattern, not a calibrated production score.
- Enterprise Managed Authorization is an extension, not core spec — adoption is ecosystem-dependent.
Full writeup with the claim-receipts table, the live curl commands, and the complete migration checklist:
Canonical version with live receipts: https://scriptmasterlabs.com/mcp-biggest-update-september-2026
来源:Google AI:DEV 作者专属(RSS) · dev.to