The 2026-07-28 revision of the Model Context Protocol makes a stateless core the protocol's new foundation. The initialize handshake and Mcp-Session-Id header are no longer required for basic operation. A request can reach any compatible instance, bringing MCP closer to a conventional web API and making large-scale operation easier.

The short answer

QuestionAnswer
Does MCP remove all state?No. Features that require it now use explicit mechanisms.
What is the main benefit?Normal load balancing, failover and serverless without mandatory shared sessions.
Will old clients stop working immediately?No. A minimum twelve-month deprecation cycle is planned.
Can teams remove Redis?Only if it served MCP sessions alone; inspect every other dependency first.
Does security change?Yes, including stronger issuer and resource validation.

Why sessions became a scaling problem

A client previously initialized a relationship with a server and reused an identifier. Behind a load balancer, requests needed to return to the same instance or share state through Redis. An instance failure could lose the session, while serverless functions had to reconstruct artificial continuity.

The stateless model removes that constraint from the common path. A request carries what the server needs and can be processed by an interchangeable instance. Round-robin balancing, autoscaling and failover become ordinary infrastructure choices again.

This does not mean agents lose memory. A long conversation, asynchronous task or delegated authorization may still require state. The difference is that state becomes a declared capability with a visible lifecycle instead of an implicit property of every connection.

Advanced features become explicit

The specification adds cache hints with time and scope, multi-round-trip requests and a task model for deferred work. Metadata can travel directly in _meta without relying on a hidden session channel.

That separation lets a simple implementation remain simple. A document-search server does not need distributed storage merely to satisfy the protocol. A complex orchestrator can enable the required capabilities and choose how to persist them.

Security and compatibility

The update strengthens OAuth issuer verification through RFC 9207 and resource indicators through RFC 8707. These checks reduce the chance of a token being accepted by the wrong server. JSON Schema 2020-12 also becomes the reference for inputs and outputs.

Roots, Sampling and Logging enter deprecation in their current form. The project promises at least twelve months before removal, providing a migration window but no reason to wait until the end. Beta Python v2, reorganized TypeScript, Go and C# SDKs are the first migration targets.

Preparing the transition

First inventory everything that truly depends on Mcp-Session-Id, initialization and sticky routing. Separate business state from state created only for transport. Add tests where consecutive requests reach different instances.

Then test authentication with multiple audiences, cache expiry and task recovery. During the transition, observe each client's announced protocol version and retain a compatibility path for old integrations.

Stateless operation may simplify the architecture, but hurriedly deleting shared storage can expose hidden locks, results or quotas. Measure before removal.

MCP is dropping a transport constraint that limited industrial deployment. The protocol now fits cloud infrastructure more naturally, provided teams make the state their agents really need explicit.