MCP 2026-07-28 goes stateless, adds extensions and enterprise auth

ClaudeDevs says MCP 2026-07-28 is the protocol’s biggest update yet, shifting to a stateless model that should make remote servers easier to deploy, scale, and run on edge or serverless infrastructure. The release also makes extensions first-class, with new Apps, Tasks, and managed enterprise auth.

mcp cover

TL;DR

  • MCP 2026-07-28 released: Claimed “largest update” since launch; MCP now stateless
  • Deployment simplified: No session-state management; supports serverless/edge, horizontal scaling, and load balancers
  • Routing change: Shift from “sticky session” routing to load-balanced requests handled by any MCP instance
  • Extensions now first-class: MCP Apps (sandboxed iframe UIs), Tasks (long-running/async), Enterprise Managed Auth (IdP-controlled access)
  • Protocol governance/security: Auth hardening plus a formal deprecation policy
  • Community response mixed: Some cite easier enterprise use; others call removed initialize handshake/session header breaking

ClaudeDevs announced on X that MCP 2026-07-28 is live, describing it as the protocol’s “largest update” since launch and saying MCP is now “stateless,” a change the account claims will make remote servers easier to deploy and scale.

Before the update, the company says running a remote MCP server meant managing session state, which limited where it could run. With that requirement removed, Anthropic says MCP can now be deployed on serverless and edge infrastructure, or scaled horizontally behind a load balancer. An accompanying explainer graphic credited to @sharqwy casts the change as a move from “sticky session” routing to a load-balanced setup in which any MCP instance can handle a request.

The same announcement also elevates extensions to a “first-class” path for protocol changes. The examples listed were MCP Apps, described as server-rendered UIs in a sandboxed iframe; Tasks, for long-running and async operations; and Enterprise Managed Auth, for centrally controlling MCP server access through an identity provider. ClaudeDevs also pointed to auth hardening and a formal deprecation policy in the release.

A broader graphic attached to the release presents the update as a way to make MCP “production-grade web infrastructure for agents.” It breaks the change into several areas, including human approval flows, long-running tasks, interactive apps, enterprise auth and ops-oriented routing and policy. The same material argues the release could support workflows such as approving high-risk actions in context, running larger exports or deployments, and using visual interfaces for plans, designs or dashboards.

Source: ClaudeDevs on X

Continue the conversation on Slack

Did this article spark your interest? Join our community of experts and enthusiasts to dive deeper, ask questions, and share your ideas.

Join our community