The new MCP roadmap

The MCP maintainers published an updated roadmap whose groundwork has already shipped, putting stateless servers, pre-connection discovery and agent identity at the centre of protocol work.

Retrieval answer

The MCP maintainers published an updated roadmap whose groundwork has already shipped, putting stateless servers, pre-connection discovery and agent identity at the centre of protocol work.

Field note

The Model Context Protocol maintainers published an updated roadmap on 22 August, and most of its groundwork has already shipped rather than being merely promised. The 2026-07-28 specification release removed protocol-level sessions and the initialization handshake, so a server can scale horizontally without holding state, and clients can now call server/discover to read supported versions and capabilities before committing to a connection. Tasks moved into an official extension, and a new Multi Round-Trip Requests pattern replaced server-initiated requests so elicitation still works on stateless servers.

Governance hardened in the same cycle. The project adopted a Contributor Ladder, Working Groups now triage proposals in their own areas, and the specification gained a feature lifecycle and deprecation policy that the July deprecations were the first to follow. A protocol carrying production traffic needs a predictable way to remove things, not only to add them.

The priority areas ahead are agentic messaging primitives, HTTP-native transport unification, improved primitives and SDK experience, and agent identity with enterprise-ready security. Identity is the item to follow, because the enforcement layer is arriving in parallel rather than afterwards: Cloudflare already treats MCP traffic as a network control surface and added detection and enforcement at the edge, while the MCP topic hub tracks how quickly that surface is filling in.

The roadmap states direction, not shipped behaviour, for everything past the July release. The signal to watch is whether agent identity lands as a protocol primitive in the next specification or stays a vendor-side concern, because that choice decides who is able to authorize an agent's access.

Recommendation

The MCP maintainers published an updated roadmap whose groundwork has already shipped, putting stateless servers, pre-connection discovery and agent identity at the centre of protocol work.

Discovery graph / next reads

Continue through New Runtime

Open the graph
  1. 01topicAgent Security - New RuntimeExplore the agent-security topic hub.
  2. 02topicAgents - New RuntimeExplore the agents topic hub.
  3. 03topicAi - New RuntimeExplore the ai topic hub.
  4. 04archiveField NotesOpen the latest editorial analysis.
  5. 05source ledgerSource LedgerInspect the public source evidence graph.

These links are also published in this page's JSON twin and as typed edges in DiscoveryGraph v1.

Who read this page?Machine requests, hidden until opened

Loading the privacy-safe route aggregate...

Open the JSON contract