Track 2026-07-28 release - #2805
Conversation
* Update Kotlin SDK tier to Tier 3 in SDK documentation * docs: fix broken links to client/sampling and spec landing The "Sampling" link in each architecture overview pointed at /specification/<version>/client, which has no index page and is not a route (only /client/sampling, /client/roots, /client/elicitation exist). Point it at /specification/<version>/client/sampling, matching the link text. Applied across all five spec versions (2024-11-05, 2025-03-26, 2025-06-18, 2025-11-25, draft). Also fix two extension overviews (apps, tasks) that linked the "core MCP specification" to /specification, which has no index/redirect. Point them at /specification/latest, the version-agnostic spec landing redirect. * Add Authorization Interest Group charter Codifies the existing #auth-ig as a chartered Interest Group following the community charter template. Documents scope, facilitators, biweekly cadence, the WG-incubation process, and the six Working Groups proposed to date. * Re-organize message patterns pages * Update links to message patterns pages after move from utilities/ * Fix typos in changelog * make server/discover support caching * fix formatting * update caching intro * removing caching specific fields from server discovery data fields * clarify that ttlMs is an integer value in milliseconds in the docs * fix formatting * Mark SEPs as final * Split auth spec * Update metadata * Update ASM discovery into its own doc * Update docs * Update docs split * Structure updates * Structure updates * Structure updates * Update docs/specification/draft/server/utilities/caching.mdx * Restore Transports group to draft spec navigation The message patterns reorg (ea7c32a) accidentally dropped the Transports group from the draft Base Protocol navigation, orphaning the stdio and Streamable HTTP transport pages. * Split auth spec * Update metadata * Update ASM discovery into its own doc * Update docs * Update docs split * Structure updates * Structure updates * Structure updates * Bundle client registration into one page, split out AS discovery - Merge Client ID Metadata Documents and Dynamic Client Registration pages (plus preregistration and authorization server binding) into a single Client Registration page - Move Authorization Server Discovery into its own page with a short pointer from the authorization overview - Update navigation and cross-references accordingly * Update page split * Fix markdown format in server/prompts doc * Update for consistency * Pulling things out of the table as normative verbiage * Need to go through PR not direct to main for this change * Add Rust MCP client tutorial * Make Messages Pattern a sub-heading under Messages * fix(docs): replace dead Python auth sample link in authorization tutorial Signed-off-by: Hugues Clouâtre <[email protected]> * (chore): sep-to-spec consistency pass (#2863) * Pulling things out of the table as normative verbiage * JSON schema security considerations from SEP * Update tiering per missing SEP callout * Update SEP guidelines with extension track * Extension naming, per SEP-2133 * SEP-2164 consistency - MUST for errors * SEP-2243 consistency, and resolves self-contradiction * Update changelog.mdx * Update sdk-tiers.mdx * Consistency with 2549 * 2575 consistency * 2575 verbiage * I don't think this is used anywhere * Update feature-lifecycle.mdx * Update feature-lifecycle.mdx * Update feature-lifecycle.mdx * Update changelog.mdx * Update docs/community/feature-lifecycle.mdx Co-authored-by: David Soria Parra <[email protected]> * Update docs/community/feature-lifecycle.mdx Co-authored-by: David Soria Parra <[email protected]> * Update docs/extensions/overview.mdx Co-authored-by: David Soria Parra <[email protected]> * Use dsp's suggestion consistently --------- Co-authored-by: David Soria Parra <[email protected]> * fix(schema): extract ElicitationCompleteNotificationParams to extend NotificationParams (#2866) Signed-off-by: Hugues Clouâtre <[email protected]> * Align client feature pages with MRTR and per-request capabilities - Show client capability declarations in their real shape: the value of _meta["io.modelcontextprotocol/clientCapabilities"] is the ClientCapabilities object, not a top-level "capabilities" wrapper (which belonged to the removed initialize request). - Relabel embedded Request/Response example pairs on elicitation, sampling, and roots pages to make the MRTR envelope clear: input requests are delivered inside InputRequiredResult.inputRequests, and client results are returned inside inputResponses on the retried request. Strip the leftover JSON-RPC result wrappers from those examples. - Replace the dangling URLElicitationRequiredError reference (the error no longer exists) with the InputRequiredResult/requestState retry flow. - Remove the unsupported pattern property from the StringSchema example in the restricted elicitation schema subset. * Fix server page examples for required _meta, resultType, and caching fields - Add a note to tools, resources, prompts, completion, and pagination pages stating that request examples omit the required _meta request metadata for brevity, with a link to the _meta documentation. - Add the missing resultType: "complete" field to result examples on the tools, completion, and pagination pages. - Remove a stray top-level resultType field from a completion/complete request example (the field belongs on results, not requests). - Add ttlMs and cacheScope to the pagination resources/list response example, matching the caching requirements for list results. - Add resultType, ttlMs, and cacheScope rows to the server/discover Response Fields table. * Restore request timeout guidance, updated for transport-specific cancellation The Timeouts section from the 2025-11-25 lifecycle page was dropped in the draft restructure. Re-add it to the cancellation page: senders SHOULD establish per-request timeouts, cancel on expiry (closing the response stream on Streamable HTTP, sending notifications/cancelled on stdio), MAY reset the clock on progress notifications, and SHOULD enforce a maximum timeout regardless. * Scope caching requirements to complete results and define the cache key - Scope the caching-hints MUST to results with resultType "complete": interim input_required results from multi round-trip requests are not CacheableResults and carry no caching hints. - Define what identifies a cached response (method plus the request parameters that affect the result) and forbid caching results produced via MRTR retries carrying inputResponses or requestState. * Add changelog entries for required resultType and SSE resumability removal - New major-changes entry: all results carry a required resultType field ("complete" or "input_required"); clients treat an absent field from earlier-protocol servers as "complete". - Reword the MRTR entry so resultType is not described as something only InputRequiredResult carries. - New major-changes entry: SSE stream resumability and redelivery (Last-Event-ID) are removed; a broken response stream loses the request and clients re-issue it as a new request. * Align draft schema with spec docs - Declare the reserved io.modelcontextprotocol/subscriptionId _meta key via a new NotificationMetaObject type, including the rule for deriving the value from the subscriptions/listen request's JSON-RPC ID - Rewrite the three list_changed notification doc comments to reflect the opt-in subscriptions model instead of unsolicited delivery - Add the HEADER_MISMATCH (-32001) error code and HeaderMismatchError type required by the Streamable HTTP transport's header validation - Update cacheScope JSDoc to the authorization-context caching model used by the caching utility doc - Make CancelledNotificationParams.requestId required - Describe cancellation as client-initiated, with one server-side use: on stdio a server sends notifications/cancelled solely to terminate a subscriptions/listen stream - Give ListRootsRequest a minimal params shape instead of RequestParams, matching other server-initiated input requests - Remove ProgressNotification from ClientNotification: only clients issue requests, so only servers report progress Regenerated schema.json and schema.mdx. * Fix direction language and subscription ID rule in pattern docs - Cancellation: describe cancellation as client-to-server, with the server-side exception for subscriptions/listen stream teardown on stdio - Progress: describe progress notifications as server-to-client only, and use Client/Server in the sequence diagram - Subscriptions: state how io.modelcontextprotocol/subscriptionId is derived from the subscriptions/listen request's JSON-RPC ID (decimal string for numeric IDs, verbatim for string IDs) * Add repository links to Registry, Server Card, and Triggers & Events charters (#2887) Add a `## Resources` section linking each group to its modelcontextprotocol org repository, matching the convention already used by the Interceptors, Tool Annotations, and Skills Over MCP charters. - registry -> modelcontextprotocol/registry - server-card -> modelcontextprotocol/experimental-ext-server-card - triggers-events -> modelcontextprotocol/experimental-ext-triggers-events Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * Move Rust client tab after Ruby * Address review feedback on cancellation wording, subscriptionId docs, and error example - Make the server-to-client direction of the stdio cancellation exception explicit in cancellation.mdx - Document why io.modelcontextprotocol/subscriptionId is optional on NotificationMetaObject (the type covers all notifications, not just subscription-stream deliveries) - Add a HeaderMismatchError example so -32001 renders in the schema Error section * Apply suggestions from code review Co-authored-by: David Soria Parra <[email protected]> * Make subscriptionId carry the JSON-RPC ID verbatim as string or number The _meta value is now typed as RequestId (string | number) instead of string, so no numeric-to-string conversion rule is needed. Update the subscriptions and resources doc examples to show a numeric ID passed through unchanged, and fix a verb agreement typo in cancellation.mdx. * Simplify subscriptionId description to just the request ID * fix extensions page nesting header names (#2895) The Extension Page Tab layout does not match the rest of the site. Currently it's Extension Name -> Extension Name. This PR switches it to be Extension Name -> Overview Also rename MCP Tasks to just Tasks, no need to have the MCP prefix. This was discussed as a docs issue in Core Maintainers meeting on 6/3 * Replace discover.mdx Response Fields table with a Data Types section Match the pattern used by the Tools, Prompts, and Resources pages: describe only the concept-specific DiscoverResult fields, leaving envelope fields (resultType, ttlMs, cacheScope) to the JSON example and the caching page. This keeps the page from needing updates whenever the message envelope changes. * Retrigger CI * Define error code allocation policy and renumber draft error codes JSON-RPC 2.0 reserves -32000..-32099 for implementation-defined server errors, and existing SDKs already use the low end of that range (request timeouts, connection closed, session not found). The error codes introduced in this draft collided with that usage: -32001 (HeaderMismatch) is also used by SDKs for request timeouts and session-not-found responses. Partition the range instead: -32000..-32009 stays implementation-defined (existing usage grandfathered, no new codes), -32010..-32099 is reserved for the MCP specification, with allocations recorded in schema.ts and starting at -32020. Renumber the draft-introduced codes accordingly: - HeaderMismatch: -32001 -> -32020 - MissingRequiredClientCapability: -32003 -> -32021 - UnsupportedProtocolVersion: -32004 -> -32022 Also add HeaderMismatchError to the schema (it previously existed only in transport prose) with an example, and document the policy in the Error Codes section of the base protocol overview. * Extend implementation-defined sub-range to -32019 Simpler boundary: implementation-defined space is -32000..-32019, the MCP specification reserves -32020..-32099. Drops the reserved-but-unallocated buffer concept in favor of a single clean split. * Update docs/specification/draft/basic/index.mdx Co-authored-by: Peter Alexander <[email protected]> * Update docs/specification/draft/basic/index.mdx Co-authored-by: Peter Alexander <[email protected]> * Update docs/specification/draft/basic/index.mdx Co-authored-by: Peter Alexander <[email protected]> * Leave room for future spec-defined local error codes Per review feedback: the spec may want to standardize what clients receive for common local conditions (e.g. request timeouts) in the future, so the note no longer steers implementations away from numeric codes entirely. * build(deps-dev): bump esbuild (#2910) Bumps the npm_and_yarn group with 1 update in the / directory: [esbuild](https://github.com/evanw/esbuild). Updates `esbuild` from 0.28.0 to 0.28.1 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md) - [Commits](evanw/esbuild@v0.28.0...v0.28.1) --- updated-dependencies: - dependency-name: esbuild dependency-version: 0.28.1 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump esbuild (#2911) Bumps the npm_and_yarn group with 1 update in the /tools/sep-automation directory: [esbuild](https://github.com/evanw/esbuild). Updates `esbuild` from 0.27.2 to 0.28.1 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md) - [Commits](evanw/esbuild@v0.27.2...v0.28.1) --- updated-dependencies: - dependency-name: esbuild dependency-version: 0.28.1 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Remove obsolete docs/community/seps/2243-http-standardization.mdx * build(deps-dev): bump eslint from 10.4.1 to 10.5.0 Bumps [eslint](https://github.com/eslint/eslint) from 10.4.1 to 10.5.0. - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.4.1...v10.5.0) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.5.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> * build(deps-dev): bump typescript-eslint from 8.60.1 to 8.61.0 Bumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.60.1 to 8.61.0. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.61.0/packages/typescript-eslint) --- updated-dependencies: - dependency-name: typescript-eslint dependency-version: 8.61.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> * build(deps-dev): bump prettier from 3.8.3 to 3.8.4 Bumps [prettier](https://github.com/prettier/prettier) from 3.8.3 to 3.8.4. - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.8.3...3.8.4) --- updated-dependencies: - dependency-name: prettier dependency-version: 3.8.4 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> * Tighten error code policy wording per review Reframe -32000..-32019 as legacy allocations, state the emit/meaning rules for the spec-reserved sub-range explicitly, and list the historical codes as a bulleted MUST NOT emit list. * Add Security IG charter; move all charters under working-groups/ and interest-groups/ :house: Remote-Dev: homespace * build(deps-dev): bump markdown-it Bumps the npm_and_yarn group with 1 update in the / directory: [markdown-it](https://github.com/markdown-it/markdown-it). Updates `markdown-it` from 14.1.1 to 14.2.0 - [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md) - [Commits](markdown-it/markdown-it@14.1.1...14.2.0) --- updated-dependencies: - dependency-name: markdown-it dependency-version: 14.2.0 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> * Apply review feedback on range guidance Advise new implementations against using the legacy sub-range, and replace the applications clause with a uniform statement that does not depend on distinguishing applications from implementations. * charter * Format EMA interest group charter with prettier * Add Lead Maintainer sponsor and fix facilitator name in EMA IG charter * Add Discord channel link to EMA IG charter * Add Discord invite link alongside channel link in EMA IG charter * Add Ola Hungerford as Lead for Interceptors * docs: fix SEP-2243 base64 sentinel case-sensitivity contradiction * Extend Base64 sentinel encoding to the Mcp-Name header Tool and prompt names are only SHOULD-constrained to header-safe characters, so a name outside the safe set previously made the tool uncallable over Streamable HTTP: Mcp-Name is required, but no encoding was defined for it. - Allow the =?base64?...?= sentinel encoding (already defined for Mcp-Param-{Name} headers) for the Mcp-Name header value. - Require servers to decode encoded Mcp-Name and Mcp-Param-{Name} values before comparing them to the request body during server validation. * Restrict x-mcp-header to statically reachable properties The x-mcp-header extraction rule was undefined for properties nested under array 'items', inside composition or conditional keywords (oneOf/anyOf/allOf/not, if/then/else), or behind $ref: such properties have no single static location in the call arguments. - x-mcp-header annotations are now only valid on properties reachable from the schema root via a chain consisting solely of 'properties' keys. Annotations anywhere else make the tool definition invalid, triggering the existing client rejection rules. - Define extraction as reading the instance value at the annotated property's exact path; if the value is absent, the header is omitted. - Mirror the rule in the Tool.inputSchema schema documentation. * Add elicitationComplete to the subscriptions/listen filter notifications/elicitation/complete had no legal delivery channel: the HTTP GET stream is gone, response-stream notifications must relate to the in-flight request, and the subscriptions/listen filter had no field covering elicitation completion — while servers must not send notification types the client has not requested. - Add an opt-in elicitationComplete boolean to SubscriptionFilter; when true, the server may deliver notifications/elicitation/complete on that subscription's stream. - Document on ElicitationCompleteNotification that it is only sent to clients that opted in via elicitationComplete and is delivered on that subscription's stream (with the subscription ID in _meta). - Document the URL-mode elicitation flow: the client subscribes via subscriptions/listen with elicitationComplete: true, waits for the completion notification, then retries the original request. - Regenerate schema.json and the schema reference. * Clarify that core client notifications do not occur over Streamable HTTP In this revision, the only client-sent notification in the core protocol is notifications/cancelled, and it is used only on the stdio transport: on Streamable HTTP, closing the SSE response stream is itself the cancellation signal and no notifications/cancelled message is expected. - Note this in the Sending Messages section, cross-linking the cancellation pattern; the notification POST rules remain as transport mechanics, with header requirements for notification POSTs left undefined by this revision. - Scope the protocol-version header-body match requirement and the Mcp-Method header requirement to requests. Request-side rules are unchanged. * Remove notifications/elicitation/complete from draft spec With the multi round-trip request pattern, clients learn the outcome of an out-of-band URL mode elicitation by retrying the original request, so a server-initiated completion signal no longer has a place in the flow. - Drop ElicitationCompleteNotification and its params from the draft schema - Drop the elicitationComplete subscription filter field - Remove the completion notifications section from the elicitation page and update the URL mode flow diagram - Note the removal in the draft changelog * Remove elicitationId from URL mode elicitation requests The completion notification was the only consumer of this identifier. With notifications/elicitation/complete gone, servers correlate an elicitation across retries via requestState instead, so the field has no remaining protocol-level purpose. * Deduplicate x-mcp-header rules and drop redundant notification note The full reachability and extraction rules live in the Streamable HTTP transport spec; tools.mdx and the Tool schema comment now reference them instead of restating them. Also remove the protocol-version section's note about notification POSTs: the core protocol defines no client-to-server notifications over Streamable HTTP, so nobody will look for that answer there, and the Sending Messages note already covers it. * Only carve out -32002 in the legacy sub-range receiver rule -32042 falls in the spec-reserved sub-range, not the legacy one, so it does not belong in that bullet's exception; it stays listed with the codes from earlier protocol versions below. * Add Enterprise-Managed Authorization blog post :house: Remote-Dev: homespace * docs: mark Archestra.AI as supporting OAuth Client Credentials (#2950) * Update link to stable enterprise-managed authorization spec (#2949) Spec was updated to stable, so the link was broken. Fixed the link and pointed it to the new stable url. * Add PostHog Code to client-matrix documentation (#2946) Co-authored-by: Ola Hungerford <[email protected]> * docs: add Microsoft 365 Copilot to extension support matrix and MCP Apps client list (#2637) * docs: add Microsoft 365 Copilot to extension support matrix and MCP Apps client list * docs: apply Prettier formatting to client-matrix.mdx * fix: resolve prettier formatting issues in client-matrix.mdx * fix: restore Archestra.AI and PostHog Code rows dropped during merge The previous merge of main inadvertently removed the Archestra.AI (including its Enterprise Auth support) and PostHog Code entries from the client matrix, and dropped Archestra.AI from the MCP Apps overview client list. Restore them so this PR only adds Microsoft 365 Copilot. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> --------- Co-authored-by: Ola Hungerford <[email protected]> Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> * build(deps-dev): bump undici Bumps the npm_and_yarn group with 1 update in the / directory: [undici](https://github.com/nodejs/undici). Updates `undici` from 7.24.1 to 7.28.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.24.1...v7.28.0) --- updated-dependencies: - dependency-name: undici dependency-version: 7.28.0 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> * docs: complete account linking guidance in enterprise-managed authorization docs * build(deps): bump actions/checkout from 6 to 7 Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]> * build(deps-dev): bump typescript-eslint from 8.61.0 to 8.61.1 Bumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.61.0 to 8.61.1. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.61.1/packages/typescript-eslint) --- updated-dependencies: - dependency-name: typescript-eslint dependency-version: 8.61.1 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> * docs: recommend SSE comment-line keep-alive for listen streams (#2954) Add a non-normative note to the Streamable HTTP transport recommending servers periodically emit an SSE comment line (:\r\n) as a keep-alive on long-lived subscriptions/listen response streams, and stating that clients must ignore SSE comment lines rather than treat them as malformed input. * Move AI contribution policy to AI_POLICY.md :house: Remote-Dev: homespace * feat(schema): add subscriptions/listen response (#2953) * feat(schema): add subscriptions/listen response subscriptions/listen was the only request without a response object. Add an empty SubscriptionsListenResult, sent by the server to signal a graceful end of the subscription (e.g. during shutdown), distinct from an abrupt transport drop which carries no response. Like other stream messages it carries the subscriptionId in _meta. Also add the subscriptionId to the stream notification examples that were missing it, matching the spec requirement that all stream messages carry it. * Update schema/draft/schema.ts Co-authored-by: Peter Alexander <[email protected]> * Update schema/draft/schema.ts Co-authored-by: Peter Alexander <[email protected]> * chore(schema): regenerate draft schema after listen result _meta change --------- Co-authored-by: Peter Alexander <[email protected]> * docs(community): add Primitive Grouping Interest Group charter (#2942) * docs(community): add Primitive Grouping Interest Group charter Port the charter for the Primitive Grouping Interest Group from the experimental-ext-grouping incubation repo into the canonical Interest Group Charters section, and register it in docs.json navigation. Co-authored-by: Copilot <[email protected]> * docs(community): sync Primitive Grouping charter with group repo PR #6 Port the updated charter from modelcontextprotocol/progressive-disclosure-wg#6: add the #primitive-grouping-ig Discord channel, the within/beyond-scope problem statement, and the Goals, Organization Strategies, and IG Principles sections. Co-authored-by: Copilot <[email protected]> --------- Co-authored-by: Copilot <[email protected]> Co-authored-by: Ola Hungerford <[email protected]> * spec: decouple Mcp-Param-* header emission from schema TTL The Client Behavior note for custom Mcp-Param-* headers previously said clients SHOULD omit headers when the cached inputSchema is stale. With ttlMs: 0 this creates a loop: the schema is always stale, so the client always omits the header, the server rejects (header missing but value in body), the client refreshes tools/list, and the refreshed schema is still stale. Reframe the rule: clients use the most recently obtained inputSchema to construct headers, omit only when no schema has ever been obtained, and refresh-and-retry on reject (now covering both missing and mismatched headers). TTL governs re-fetch cadence for tools/list; it is not a gate on emitting routing headers. Server-side header/body validation is the freshness check. * fix links from docs to Enterprise Managed Auth spec (#2945) * fix link to Enterprise Managed Auth spec * Update link text to reflect EMA spec is now stable --------- Co-authored-by: Ola Hungerford <[email protected]> * docs: reframe server/discover version-selection bullet (#2955) * Apply suggestions from code review Co-authored-by: Paul Carleton <[email protected]> * Update seps/2243-http-standardization.md * Update docs/seps/2243-http-standardization.mdx * (docs): Update documentation for MCP security best practices (#1554) * Update security_best_practices.mdx * Update security_best_practices.mdx * Update security_best_practices.mdx * Update security_best_practices.mdx * Move OAuth URL validation content to relocated SBP doc The Security Best Practices document was moved out of the spec (specification/draft/basic/ -> docs/tutorials/security/) in 3a147cb. During merge, git's rename detection applied this PR's additions to the 2025-11-25 versioned spec instead of the new tutorials location. This moves the OAuth Authorization URL Validation and stdio Transport Security in Proxy Scenarios sections to their intended home in docs/docs/tutorials/security/security_best_practices.mdx and restores the 2025-11-25 spec to its released state. :house: Remote-Dev: homespace * Update docs/docs/tutorials/security/security_best_practices.mdx Co-authored-by: Sam Morrow <[email protected]> * Clarify http:// scope and fix stdio section anchor - Restrict http:// to loopback addresses during local development, addressing review feedback that production authorization servers must use https:// - Fix broken anchor link to the stdio Transport Security in Proxy Scenarios section :house: Remote-Dev: homespace * Wrap stdio escalation paragraph at 100 chars :house: Remote-Dev: homespace --------- Co-authored-by: Sam Morrow <[email protected]> * docs: fix elicitation example to use requestedSchema The learn/client-concepts elicitation/create example used 'schema', but the specification and JSON schema define the field as 'requestedSchema'. Signed-off-by: FenjuFu <[email protected]> * Add SDK vulnerability disclosure process and stdio trust boundary to SECURITY.md (#2973) * Add SDK vulnerability disclosure process and security policy docs :house: Remote-Dev: homespace * Update docs/community/security.mdx Co-authored-by: David Soria Parra <[email protected]> --------- Co-authored-by: David Soria Parra <[email protected]> * Add Financial Services Interest Group charter Adds docs/community/interest-groups/financial-services.mdx in the current charter template format and registers it under Interest Group Charters in docs.json. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> * fix the ordering of the dprecated features table The dperecated features table was not ordered. We are now ordereding it by the spec versions it was first deprecated in, in descending order. * build(deps-dev): bump typescript-eslint from 8.61.1 to 8.62.0 (#2985) Bumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.61.1 to 8.62.0. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.62.0/packages/typescript-eslint) --- updated-dependencies: - dependency-name: typescript-eslint dependency-version: 8.62.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump eslint from 10.5.0 to 10.6.0 (#2986) Bumps [eslint](https://github.com/eslint/eslint) from 10.5.0 to 10.6.0. - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.5.0...v10.6.0) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.6.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump prettier from 3.8.4 to 3.9.3 (#2987) * build(deps-dev): bump prettier from 3.8.4 to 3.9.3 Bumps [prettier](https://github.com/prettier/prettier) from 3.8.4 to 3.9.3. - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.8.4...3.9.3) --- updated-dependencies: - dependency-name: prettier dependency-version: 3.9.1 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> * Reformat schema and SEP files for prettier 3.9 :house: Remote-Dev: homespace --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Den Delimarsky <[email protected]> * docs: add Code of Conduct appeals channel Add an Appeals section to CODE_OF_CONDUCT.md pointing to the new [email protected] Google Group, an out-of-band email channel for appealing enforcement actions (including org-level GitHub bans). The group was stood up in modelcontextprotocol/access#123. * Update CODE_OF_CONDUCT.md * docs: fix typo (contraints -> constraints) in appeals section * Add blog post announcing SDK betas for 2026-07-28 (#2988) * Add blog post announcing Python and TypeScript SDK betas for 2026-07-28 :house: Remote-Dev: homespace * Tighten blog post wording :house: Remote-Dev: homespace * Correct validation window and mention upcoming Go and C# SDK betas :house: Remote-Dev: homespace * Make SDK betas post developer-focused Rework the announcement around what server implementers need: a compatibility section up front, runnable install and migration steps for both SDKs, links to the RC and transports posts for context, and pointers to the SDK documentation sites and migration guides. Correct the SEP-2577 deprecation scope and clarify the TypeScript wire opt-in. :house: Remote-Dev: homespace * Cover Go and C# betas alongside Python and TypeScript All four Tier 1 SDKs now have pre-releases implementing 2026-07-28: Go v1.7.0-pre.1 and C# 2.0.0-preview.1 join the Python and TypeScript betas. Add a section with install commands, the Go stateless HTTP opt-in, and links to release notes and docs sites; update the title, intro, issue trackers, and pinning advice accordingly. :house: Remote-Dev: homespace * Add Felix Weinberger and Max Isbey to byline :house: Remote-Dev: homespace * Update blog/content/posts/2026-06-29-sdk-betas-for-2026-07-28.md Co-authored-by: kfang-ant <[email protected]> * Update blog/content/posts/2026-06-29-sdk-betas-for-2026-07-28.md Co-authored-by: kfang-ant <[email protected]> * Update blog/content/posts/2026-06-29-sdk-betas-for-2026-07-28.md Co-authored-by: kfang-ant <[email protected]> * Restructure compatibility section and move protocol summary before SDK details Address review feedback: frame the betas as test-and-feedback releases with stable versions recommended for production, spell out why trying a beta is safe (opt-in at install and on the wire), and end with concrete steps for library authors. Move the SEP summary ahead of the per-SDK sections so readers see what changed before the language-specific install instructions. :house: Remote-Dev: homespace * Add stack diagram and align SDK betas post with amplification messaging - Add stack.svg showing spec -> SDKs -> clients/servers layering - Lead intro with 'stateless' and Python/TypeScript v2 - Standardize on 'v2' (drop mixed '2.0' in prose) - Rename feedback section to 'Tell us what breaks' - Reflow prose to ~100 chars and fix typos * Refine SDK betas post title and feedback section - Retitle to 'Beta SDKs for the 2026-07-28 MCP Spec Release Candidate Are Here' - Restore 'Give us your feedback' section heading - Separate spec-repo pointer from the C# issue-tracker bullet * Style "+ more" SDK tile as full-size hatched block * Update author bylines to per-SDK lead titles --------- Co-authored-by: kfang-ant <[email protected]> * Correct several claims in the SDK betas blog post (#2997) * Correct several claims in the SDK betas post - Scope the "resolves to a stable version" install claim to Python, Go, and C#: the TypeScript v2 packages are new package names with no stable release, so installing them is itself the beta opt-in. - State that Python and C# servers pick up the new revision on upgrade, in contrast to the TypeScript/Go transport-level opt-in. - Note that the v2 SDK lines are new major versions with breaking changes, separate from anything that happens on July 28. - Python: the decorator API carries over from v1's FastMCP; drop the "API got smaller" and "can now be implemented" framing. - Mcp-Name rides only on requests that name a tool, resource, or prompt, not on every request. - Soften the claim that every release's notes list exactly which SEPs are covered. - Use https for the MRTR link. - Move the post date to the actual publish date. * Keep the original post date * workflows: enable Dependabot auto-approve in slash-commands (#3018) Wire up the slash-commands action's new dependabot-auto-approve mode: - Add pull_request_target types opened/reopened and a check_suite completed trigger (gated to dependabot/ branches at the job level so suites on other branches don't start a run) - Pass dependabot-auto-approve: dev-patch-minor and the explicit file allow-list (package.json, package-lock.json) Dependabot PRs that update direct dev dependencies by patch/minor versions, touch only the lockfile pair, carry verified dependabot-authored commits, and have green CI get approved and auto-merged by mcp-commander. Everything else still requires /lgtm. Claude-Session: https://claude.ai/code/session_019ygNtiNcAaqTRnQjHCDkVS Co-authored-by: Claude <[email protected]> * build(deps-dev): bump tsx from 4.22.4 to 4.23.0 (#3015) Bumps [tsx](https://github.com/privatenumber/tsx) from 4.22.4 to 4.23.0. - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.22.4...v4.23.0) --- updated-dependencies: - dependency-name: tsx dependency-version: 4.23.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump prettier from 3.9.3 to 3.9.4 (#3012) Bumps [prettier](https://github.com/prettier/prettier) from 3.9.3 to 3.9.4. - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.9.3...3.9.4) --- updated-dependencies: - dependency-name: prettier dependency-version: 3.9.4 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump typescript-eslint from 8.62.0 to 8.62.1 (#3013) Bumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.62.0 to 8.62.1. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.62.1/packages/typescript-eslint) --- updated-dependencies: - dependency-name: typescript-eslint dependency-version: 8.62.1 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump typedoc from 0.28.19 to 0.28.20 (#3014) * build(deps-dev): bump typedoc from 0.28.19 to 0.28.20 Bumps [typedoc](https://github.com/TypeStrong/TypeDoc) from 0.28.19 to 0.28.20. - [Release notes](https://github.com/TypeStrong/TypeDoc/releases) - [Changelog](https://github.com/TypeStrong/typedoc/blob/master/CHANGELOG.md) - [Commits](TypeStrong/typedoc@v0.28.19...v0.28.20) --- updated-dependencies: - dependency-name: typedoc dependency-version: 0.28.20 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> * Regenerate schema docs for typedoc 0.28.20 typedoc 0.28.20's updated JSX renderer emits whitespace between adjacent block-level HTML tags, changing the generated schema.mdx output. Regenerated via npm run generate:schema:md so check:schema:md passes. --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Claude <[email protected]> * docs: update Goose documentation links (#3019) * docs: update Goose documentation links * docs: format Goose links table * Add AI agent contribution policy to AGENTS.md (#3009) :house: Remote-Dev: homespace --------- Signed-off-by: Hugues Clouâtre <[email protected]> Signed-off-by: dependabot[bot] <[email protected]> Signed-off-by: FenjuFu <[email protected]> Co-authored-by: devcrocod <[email protected]> Co-authored-by: Felix Weinberger <[email protected]> Co-authored-by: Sri Ujwal <[email protected]> Co-authored-by: Paul Carleton <[email protected]> Co-authored-by: Clare Liguori <[email protected]> Co-authored-by: David Soria Parra <[email protected]> Co-authored-by: John Warwick <[email protected]> Co-authored-by: David Soria Parra <[email protected]> Co-authored-by: Caitie McCaffrey <[email protected]> Co-authored-by: Den Delimarsky <[email protected]> Co-authored-by: amikai <[email protected]> Co-authored-by: Hugues Clouâtre <[email protected]> Co-authored-by: Hugues Clouâtre <[email protected]> Co-authored-by: Peter Alexander <[email protected]> Co-authored-by: Ola Hungerford <[email protected]> Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]> Co-authored-by: Felix Weinberger <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Mike Kistler <[email protected]> Co-authored-by: Den Delimarsky <[email protected]> Co-authored-by: Sambhav Kothari <[email protected]> Co-authored-by: Paul Carleton <[email protected]> Co-authored-by: Dale Seo <[email protected]> Co-authored-by: Alex Akimov <[email protected]> Co-authored-by: Joey Orlando <[email protected]> Co-authored-by: garciasces <[email protected]> Co-authored-by: Rafael Audibert <[email protected]> Co-authored-by: SuryaMSFT <[email protected]> Co-authored-by: Karan Raina <[email protected]> Co-authored-by: Kurtis Van Gent <[email protected]> Co-authored-by: Sam Morrow <[email protected]> Co-authored-by: Copilot <[email protected]> Co-authored-by: Chris Concannon <[email protected]> Co-authored-by: Sam Morrow <[email protected]> Co-authored-by: FenjuFu <[email protected]> Co-authored-by: Peder <[email protected]> Co-authored-by: Agent Orchestrator <[email protected]> Co-authored-by: Tadas Antanavicius <[email protected]> Co-authored-by: kfang-ant <[email protected]> Co-authored-by: Max <[email protected]> Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> Co-authored-by: LiuHanZhi <[email protected]>
📰 Blog Preview Deployed
Includes drafts and future-dated posts. All pages served with |
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Workflows to automatically generate PRs for you. |
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Workflows to automatically generate PRs for you. |
…elease-with-main-2 Sync docs/2026-07-28-release with main (merge with a merge commit, do not squash)
* Version the documentation section alongside the specification The Documentation tab now uses the same Mintlify version picker as the Specification tab. The current guides move to docs/docs/2026-07-28/ as the canonical, in-progress version, and identical snapshots are stored under 2025-11-25, 2025-06-18, 2025-03-26, and 2024-11-05 so every released spec version has matching docs. No content backfill: the snapshots are a copy of today's docs. Internal links inside each versioned tree point within that version. Old unversioned /docs/ URLs redirect to the 2026-07-28 pages, and a /docs/latest alias mirrors /specification/latest so links and the warning banner survive future version bumps. The spec version warning script is generalized to also show a banner on older docs versions. Version labels are chosen so the picker entries unify with the Specification tab when cut-release.yml promotes the draft spec to 2026-07-28 on this branch. :house: Remote-Dev: homespace * Use a Draft docs version, promoted to a dated version at release cut Replace the docs/docs/2026-07-28 directory with docs/docs/draft so the Documentation tab mirrors the Specification tab exactly: dated released versions plus a Draft entry. Both tabs now share identical version labels, so the picker unifies immediately instead of after the cut. Unversioned /docs/... URLs and /docs/latest now point at the latest released version (2025-11-25), matching the spec's redirect semantics. cut-release.yml promotes docs/docs/draft alongside the spec draft: copies it to docs/docs/<version>, rewrites internal links, patches the Documentation tab nav, retargets the latest-alias and legacy redirects (including /specification/latest, which was never retargeted), and adds dated siblings for draft-source redirects. Also fixes the promoted version being inserted after older versions instead of first. :house: Remote-Dev: homespace * Reorder top nav: Documentation, Specification, Extensions first :house: Remote-Dev: homespace * Propagate base-branch docs updates into all versioned copies after rebase During the rebase onto docs/2026-07-28-release, git's rename detection paired the old docs/docs/* paths only with the 2025-06-18 snapshot, so docs edits that landed on the base branch (Rust client tutorial, Claude Desktop connector UI text, requestedSchema fix, Kotlin SDK tier, auth sample link, OAuth URL validation guidance) were merged into that copy alone. Copy the merged 2025-06-18 files over draft, 2025-11-25, 2025-03-26, and 2024-11-05 with internal links rewritten to each version's prefix, keeping all snapshots identical per the PR's intent. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01N5Z3TGJTN8cH6goHhdekqc --------- Co-authored-by: Claude <[email protected]>
… concepts The 2026-07-28 draft removes the resources/subscribe RPC. Update the resource protocol operations table to show subscriptions/listen and explain the resourceSubscriptions filter. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_016WBaED7Rta4YsYVz66Qoru
…itecture overview Rework the Real-time Updates step around the subscriptions/listen stream: clients opt in with a notifications filter (toolsListChanged), the server acknowledges the filter, and every notification carries io.modelcontextprotocol/subscriptionId in _meta. Add the required ttlMs and cacheScope fields to the example tools/list response with short field descriptions. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_016WBaED7Rta4YsYVz66Qoru
Point the tool definition caching guidance at the spec's caching utility: ttlMs is a freshness hint that decides when to re-fetch, list_changed notifications invalidate early, and cacheScope private results must stay within one authorization context. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_016WBaED7Rta4YsYVz66Qoru
Tasks moved out of the core protocol into an official extension for the 2026-07-28 release. Point the architecture page at the Tasks extension instead of listing Tasks as an experimental core utility, and group Tasks with MCP Apps as extensions in the SDK tiering page. Co-Authored-By: Claude <[email protected]> Claude-Session: https://claude.ai/code/session_016WBaED7Rta4YsYVz66Qoru
The draft spec lets stdio servers write any logging to stderr and tells clients not to assume stderr output indicates errors. Update the two develop guides that still described the Claude Desktop per-server log files as error-only. Co-Authored-By: Claude <[email protected]> Claude-Session: https://claude.ai/code/session_016WBaED7Rta4YsYVz66Qoru
…ples-v2-resolved docs: modernise the Python examples for the 2026-07-28 release
…al-sweep-2026-07-28 Sync docs/2026-07-28-release with main for the release (merge commit required)
There was a problem hiding this comment.
This is the read-only adversarial conventions pass requested ahead of the 2026-07-28 release. The normative spec and schema trees came back clean: the PR touches nothing under schema/, every schema identifier referenced from the new docs resolves in schema/draft, and all 47 JSON examples in the new draft guide tree validate against schema/draft/schema.json. The inline comments below are the confirmed mismatches, each independently verified against the dated schemas and the draft spec.
Not individually re-verified but worth a look:
- The draft-tier authorization tutorial presents Dynamic Client Registration as the registration mechanism and never mentions CIMD.
- Its Streamable HTTP server example uses the initialize/Mcp-Session-Id session model the draft removed.
- A couple of prompt examples use
PromptArgumentfields the draft schema does not define (type,items).
Generated by Claude Code
The server/discover response now includes resultType, ttlMs, and cacheScope, carries serverInfo in _meta, and advertises 2026-07-28. The client capabilities example stamps the 2026-07-28 protocol version instead of 2025-06-18.
Unversioned /docs/tutorials/ and /docs/learn/ links in the draft spec resolved through catch-all redirects to the frozen 2025-11-25 guides, which lack some of the cited security content. Rewrite all nine links to /docs/draft/. Also uppercase a normative MUST in the authorization scope hierarchy requirement.
The 2024-11-05 and 2025-03-26 guides described elicitation and outputSchema, which first shipped in 2025-06-18. The 2024-11-05 tree also documented the Streamable HTTP transport, which arrived in 2025-03-26, and both trees showed 2025-06-18 initialize examples. Strip those sections, set initialize examples to each snapshot's own protocol version, use HTTP with SSE wording in the 2024-11-05 tree, and point spec links at each snapshot's own dated spec. Authorization spec links in the 2024-11-05 tree point at 2025-03-26, the first revision with an authorization spec.
Frozen guide pages linked to /specification/draft/ and /specification/latest/, so their spec citations would drift as the draft changes. Rewrite them to each snapshot's own dated spec tree, drop the tool name validation bullet from the 2025-06-18 tree since the tool name format section first appears in 2025-11-25, and fix the 2025-11-25 initialize example to negotiate 2025-11-25.
Prettier realigns the table columns after the elicitation row removal.
…ew-fixes Address adversarial review feedback on the release tracking PR
No textual conflicts. Rename detection applied main's server-concepts.mdx wording update (PR #2981) only to the 2025-06-18 copy, so the same edit was propagated by hand to the 2024-11-05, 2025-03-26, 2025-11-25, and draft copies. Main's NumberSchema erratum (PR #3139) applied cleanly to schema/2025-06-18 and schema/2025-11-25. npm run prep is clean.
The promote step now self-dates /specification/draft/ links in the copied spec, docs, and schema trees.
…nto-release-0728 Sync main into the 2026-07-28 release branch
…ew-fixes Rewrite spec links when cutting a release
updateSummaryFromStaleness was called without await, so process() returned summaryData before it was written. Proposal and accepted SEPs lost their entries outright; draft and in-review raced. Runs pinged authors and closed proposals while the digest reported no activity. await alone is not enough. The method re-ran analyzer.analyze() to rebuild state the caller already had, and by then executePing had posted a bot comment, so the second pass took the ping cooldown branch and returned shouldClose false with a null pingTarget. Thread the analysis down from checkStaleness and read the recipient from result.action.targetUser, as the maintainer accountability block already does. The method drops async, getTargetUser is now unused, and each stale SEP costs three fewer API calls. processor.ts had no tests; adds coverage for all four summary branches. Merge pull request #3133 from koic/blog-ruby-sdk-1-0 Add blog post announcing Ruby SDK 1.0 Merge pull request #3204 from maxiboch/patch-1 docs: add Maxi Boch to Tool Annotations IG membership docs: add Maxi Boch to Tool Annotations IG membership Adds myself as a Participant, per the onboarding step in the IG meeting notes. I'm contributing the io.modelcontextprotocol/display-templates extension proposal in the experimental-ext-tool-annotations repo. Merge pull request #3200 from LucaButBoring/feat/agents-wg-charter docs: add Agents WG charter Merge pull request #3199 from modelcontextprotocol/davidsp/aldridge-emeritus Move Nick Aldridge to Core Maintainer Emeritus Move Nick Aldridge to Core Maintainer Emeritus No-Verification-Needed: docs-only maintainer roster update docs: add Agents WG charter Add blog post announcing Ruby SDK 1.0 Announce the first stable release of the MCP Ruby SDK: a stable public API under the Semantic Versioning policy, a 100% server and client conformance pass rate, and the Tier 2 assessment (#3127). If accepted, this post is intended to be published after #3128, which moves the Ruby SDK to Tier 2 in the official SDK listing, is merged. Merge pull request #3195 from modelcontextprotocol/dependabot/npm_and_yarn/npm_and_yarn-f5a5c7d1ef Bump undici from 7.28.0 to 7.29.0 in the npm_and_yarn group across 1 directory Bump undici in the npm_and_yarn group across 1 directory Bumps the npm_and_yarn group with 1 update in the / directory: [undici](https://github.com/nodejs/undici). Updates `undici` from 7.28.0 to 7.29.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0) --- updated-dependencies: - dependency-name: undici dependency-version: 7.29.0 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> docs: rewrite the MCP Inspector documentation for v2 (#3143) * docs: rewrite the Inspector documentation for v2 Replaces the single legacy-era Inspector page with a folder of pages covering the three clients (web, CLI, TUI) behind one mcp-inspector binary, and the legacy vs. modern (2026-07-28) protocol-era fork that now drives most of the tool's behavior. New pages under docs/tools/inspector/: - protocol-eras the era setting and negotiation, then the fork feature by feature: logging, resource subscriptions, tasks, MRTR, x-mcp-header mirrored params and excluded tools, and the Mcp-* header / error taxonomy. Each section names the test-servers config that reproduces it. - web tab-by-tab walkthrough, session token, monitoring sidebar, server settings, deep links. - cli method reference, argument coercion, output formats, app probing, exit codes and error envelopes, CI recipes. - tui tabs, keyboard reference, loopback OAuth. - configuration the launcher/client flag split, catalog vs. config, the -- separator, and every environment variable attributed to the layer that reads it. - authorization the OAuth flow end to end, callback URLs, mid-session re-authorization and step-up, non-interactive runs, and the web-to-CLI token handoff. - recipes transports, importing client configs, reviewing an MCP App, Docker, and hosting on a network. /docs/tools/inspector keeps its URL as the overview page; the subpages are nested under it in the Developer tools navigation group. Screenshot slots are marked with TODO captions and are still to be captured. Refs modelcontextprotocol/inspector#1803 * docs: add Inspector screenshots Captures 21 screenshots against the repo's composable test servers, so every era-fork claim in the prose has a picture that reproduces from a named config: - protocol eras: the era selector, the Logs fork (session-scoped Set Active Level vs. per-request Log Level), the modern subscription LISTENING badge, the Tasks fork (tasks/list + blocking result vs. polled handles with an inlined result), an MRTR round paused at the pending-request modal, the SEP-2243 mirrored-header panel beside the struck-through excluded tool, and a -32022 rendered in both the Network and Protocol views - web: tab bar, monitoring sidebar, server settings, tools, resources, prompts, apps, protocol - tui: Tools and Auth tabs - authorization: Connection Info after a completed OAuth flow Web and OAuth shots are driven headlessly through Playwright; the TUI shots are captured from a real pty and replayed through a terminal emulator, so they keep their colors. All were taken against an isolated HOME so no real catalog or token appears. The hero image now shows the v2 client instead of the v1 screenshot. The one shot not captured is the mid-session re-authorization banner: the test authorization server grants every configured scope on the initial DCR exchange, so no step-up fires. That frame is omitted rather than faked. Refs modelcontextprotocol/inspector#1803 * docs: correct what a freshly seeded catalog contains The seed is not empty everywhere — it differs by client, and the pages flattened both cases into "seeded empty". The web backend seeds a writable catalog with two sample servers (DEFAULT_SEED_CONFIG in core/mcp/serverList.ts): a filesystem server scoped to /tmp and the everything reference server, so a first launch has something to connect to. The CLI and TUI seed an empty mcpServers object instead (seedEmptyCatalog in core/mcp/node/config.ts). Verified both by running each surface against a throwaway HOME rather than reading the code alone. A read-only --config is still never seeded on any surface. Refs modelcontextprotocol/inspector#1803 * docs: drop "fork" wording from the Inspector docs Addresses review feedback from @BobDickinson and @olaservo: "fork" was used to mean "the legacy/modern split", which collides with its git meaning. Every use is now phrased in terms of protocol eras, matching the `protocolEra` config field and the Protocol Era selector in the UI. Also reframes the "Reproducing each era locally" section so it reads as setup for the per-feature "Reproduce with ..." pointers rather than a non-sequitur, and replaces one remaining "the 2026-07-28 leg" jargon. * docs: address review feedback on the Inspector docs - Tighten the Node/npx and server-README sentences in the Inspector index - Move Protocol eras after the client and configuration pages, in both the navigation and the "Where to go next" cards — it only makes sense once the basics are understood - Drop the client-side-negotiation implementation detail in favour of the takeaway: era selection behaves the same in all three clients - Explain the -32602 error panels in relation to legacy rendering, and stop implying the difference is isError vs. JSON-RPC error * Update docs/docs/draft/tools/inspector.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector/configuration.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector/configuration.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector/configuration.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector/configuration.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector/cli.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector/web.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector/web.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector/configuration.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector/web.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector/web.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector/web.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector/web.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector/web.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector/web.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector/web.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector/configuration.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector/configuration.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector/recipes.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector/recipes.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector/configuration.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/draft/tools/inspector.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Update docs/docs/2026-07-28/tools/inspector.mdx Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> * Apply review suggestions to Inspector v2 docs Editorial pass across the eight Inspector pages, applied to both the draft and 2026-07-28 copies: clearer first-use bridging from the npx command to the mcp-inspector binary, definitions and cross-links for protocol era, MRTR, roots, MCP Apps, CIMD, and the session token, plus corrections where the prose drifted from the current draft (serverInfo now rides in the result _meta, the -32021 client-capability wording, the 401 WWW-Authenticate resource_metadata description, and the optional legacy session id). Also fixes the CI recipe whose exit-code branch could never fire, and swaps the marked em dashes, unicode arrows, ellipsis glyphs, curly quotes, and bold-lead list walls for plain ASCII prose. A number of remaining dashes still need the page-wide sweep called out in review. No-Verification-Needed: docs-only prose changes :house: Remote-Dev: homespace * Sweep remaining em dashes and unicode glyphs from Inspector docs Finish the page-wide pass the review called for: replace the remaining em dashes, unicode arrows, and ellipsis glyphs with plain ASCII punctuation (commas, colons, semicolons, or parentheses as the sentence reads), including inside Frame captions and code samples, and spell out the placeholder table cells as None. Applied identically to the draft and 2026-07-28 copies. No-Verification-Needed: docs-only prose changes :house: Remote-Dev: homespace * Quote tui.mdx description containing a colon The unquoted YAML value with a colon after 'Inspector' failed frontmatter parsing and broke the Mintlify deploy. Quote it in both the draft and 2026-07-28 copies, matching cli.mdx. No-Verification-Needed: docs-only frontmatter fix :house: Remote-Dev: homespace --------- Co-authored-by: Den Delimarsky <[email protected]> Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> Co-authored-by: Den Delimarsky <[email protected]> Add Ruby SDK Tier 2 assessment to SDK listing (#3128) This refers to assessment report https://github.com/modelcontextprotocol/modelcontextprotocol/issues/3127. The Ruby SDK is currently at tier 2 in the assessment and development toward tier 1 is ongoing. Merge pull request #3159 from DaleSeo/docs/sep-2575-identity-metadata docs: record post-final SEP-2575 changes Merge pull request #3147 from jhauga/docs docs/authorization: add 3 csharp copy/paste code-blocks Apply suggestions from code review Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> docs(registry-wg): remove @tadasant from Registry WG Leads (#3175) * docs(registry-wg): remove @tadasant from Registry WG leadership @tadasant is stepping down as Registry WG co-lead; @rdimitrov becomes the sole Lead. @tadasant remains an MCP maintainer and a Registry WG member, and stays champion of the Server Card / server.json alignment work item. Leadership-only change: the Membership row moves from Lead to WG Member and the Emeritus table is untouched. * Update registry.mdx --------- Co-authored-by: Tadas Antanavicius <[email protected]> Merge pull request #3186 from neiljar/typo-mcp-docs fix: correct typos in SEP documents Merge pull request #3190 from modelcontextprotocol/copilot/remove-disclosure-txt-file Remove accidental `disclosure.txt` from the repository Apply remaining changes Initial plan docs: remove experimental term from Task docs and repo name. (#3177) Task is now an official MCP extension with 7-28 release. Signed-off-by: Sameera Jayasoma <[email protected]> fix: correct typos in SEP documents Fix misspellings in SEP sources and regenerate the corresponding docs pages. Merge branch 'main' into docs fix(scripts): parse wrapped Author(s) lines in render-seps (#3178) The Author(s) regex used `.` to capture the field value, which does not match newlines. When an author list wrapped onto an indented continuation line, every author after the first line was silently dropped from the generated docs/seps/*.mdx table, leaving a dangling comma in the cell. Capture the first line plus any indented continuation lines that do not begin a new list item, and collapse interior whitespace when the value is used. Regenerated the three affected SEP documents: 2322 (was losing 1 of 3 authors), 1865 (6 of 9), and 2575 (2 of 5). Co-authored-by: Gabriel Zimmerman <[email protected]> Co-authored-by: Claude Opus 5 <[email protected]> Merge pull request #3166 from modelcontextprotocol/claude/final-sep-historical-notice Mark Final SEP pages as historical records Merge pull request #3116 from jamadeo/jamadeo/correct-error-codes fix: correct MISSING_REQUIRED_CLIENT_CAPABILITY error code in SEP-2663 Merge pull request #3173 from modelcontextprotocol/fix/issue-3169-versioning-current docs: state 2026-07-28 as the current protocol version on the versioning page ci: stamp the current protocol version into learn/versioning.mdx at cut The promote step rewrites draft-tier links but not the hardcoded dated version in the Revisions section, which is how the 2026-07-28 copy shipped naming 2025-11-25 as current. Stamp the new version into the promoted copy and the draft source, mirroring the existing changelog rewrite. docs: state 2026-07-28 as the current protocol version on the versioning page The learn/versioning page under the 2026-07-28 docs path, and its draft source, still named 2025-11-25 as the current protocol version. Update the Revisions section on both to 2026-07-28 to match the rest of the page. Fixes #3169 docs: record subscription completion change docs: record SEP-2575 identity metadata changes Refactor ResourceMetadata in authorization.mdx Removed redundant `ResourceMetadata` assignment and updated Resource and `ResourceDocumentation` URIs. Apply suggestions from code review Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com> Co-authored-by: John Haugabook <[email protected]> Merge branch 'main' into docs Mark Final SEP pages as historical records Final SEPs are point-in-time records of the design as accepted. The protocol can change after a SEP is finalized, so a Final SEP page can drift from the current specification. SEP-2322 still documents tasks/result and tasks/input_response even though SEP-2663 removed them (#3142). The SEP generator now injects a notice at the top of every Final SEP page pointing readers to the current specification. The SEP guidelines now state that Final SEPs are not updated after finalization and that the current specification is authoritative. Closes #3142 Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01XY2THv6f61qBZdC8j7uPZP Merge pull request #3165 from modelcontextprotocol/fix/quotes-carousel-arrow-drift Fix blog quotes carousel next arrow stalling before the end on phones Fix quotes carousel next arrow stalling before the end of the strip The next arrow derived the page index from scrollLeft divided by the viewport width while scroll targets were quantized to card starts. On phone widths each card is 44px narrower than the viewport, so the deficit grew by 44px per page and after a few pages the derived index rounded down below the real one. The next click then recomputed the position the track was already at and the arrow went dead until a prev click reset the drift. Position math now works in whole cards, which round-trips exactly between targets and the derived index and also absorbs the fractional scrollLeft values Android Chrome reports at non-integer device pixel ratios. A pending scroll target lets clicks that land during the smooth scroll animation keep advancing from the intended position instead of a stale mid-flight scrollLeft. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_014gUz1xdMLzxdAvXZ6tmV5Y Merge branch 'main' into docs Merge pull request #3164 from modelcontextprotocol/claude/posthog-logo-refresh Update PostHog logo in GA post with light and dark variants Update PostHog logo in GA post with light and dark variants PostHog provided refreshed brand SVGs with fixed colors, so the single currentColor file no longer fits. The quote shortcode gains an optional logo-dark param that inlines a second SVG, and quotes.css shows one variant per theme via PaperMod's body.dark toggle. The GA post now uses posthog.svg in light mode and posthog-white.svg in dark mode. Co-Authored-By: Claude <[email protected]> Merge pull request #3163 from modelcontextprotocol/claude/fix-3160-date-draft-links Date remaining draft links in the 2026-07-28 spec tree Date remaining draft links in the 2026-07-28 spec tree The cut-release promote step rewrote /specification/draft/ links but left /docs/draft/ and schema/draft/ links untouched in the promoted spec tree, so 13 links in docs/specification/2026-07-28/ still pointed at the living draft tiers. Date all 13 to 2026-07-28, matching the hand-cut 2025-11-25 snapshot, and extend the workflow so future cuts rewrite both patterns plus the changelog compare link. Fixes #3160 Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01DrwuUqBvFfzvqAFmefi7pU Merge pull request #3155 from modelcontextprotocol/localden/cut-release-redirect-dedup Skip existing redirect sources when cutting a release Merge pull request #3162 from modelcontextprotocol/blog/release-quotes-runlayer-stacklok Add Runlayer and Stacklok quotes to the 2026-07-28 release post Add Runlayer and Stacklok quotes to 2026-07-28 release post Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01NfLeWYXCrMXtNpV8nMU5vT docs/authorization: add 3 csharp copy/paste code-blocks Merge pull request #3161 from modelcontextprotocol/localden/publish-ga-post Publish the 2026-07-28 specification post Publish the 2026-07-28 specification post :house: Remote-Dev: homespace Merge pull request #3145 from modelcontextprotocol/blog/2026-07-28-ga Blog: The 2026-07-28 Specification Is Generally Available Link the getting-started guides in the GA post Swap the TBD placeholder in the Getting started list for the versioned 2026-07-28 documentation entry point now that the docs are published. :house: Remote-Dev: homespace Merge pull request #3158 from modelcontextprotocol/claude/subscriptions-listen-envelope Align subscriptions/listen result naming and add response envelope fix(schema): apply subscriptions/listen envelope and MetaObject rename to 2026-07-28 Port the SubscriptionsListenResultMetaObject rename and the SubscriptionsListenResultResponse envelope from draft into the released 2026-07-28 schema, add the validated example, and regenerate schema.json and schema.mdx for both versions. Also add 2026-07-28 to the generator's version list so its schema.json is generated and checked. Merge pull request #3157 from modelcontextprotocol/localden/docs-typo-redeploy Fix typo in 2025-11-25 authorization spec Fix typo in 2025-11-25 authorization spec Remove the stray "the" in the localhost redirect URI attack steps, matching the wording already used in the draft and 2026-07-28 copies of this page. :house: Remote-Dev: homespace schema(draft): align subscriptions/listen with envelope and _meta naming conventions Fixes #2989 Rename SubscriptionsListenResultMeta to SubscriptionsListenResultMetaObject to match the MetaObject-suffix convention used by MetaObject, RequestMetaObject, and NotificationMetaObject, and add the SubscriptionsListenResultResponse envelope so subscriptions/listen matches the per-method *ResultResponse pattern used by the other nine request methods. Adds a listen-closed-response.json example validated against the new envelope. schema.json and schema.mdx are regenerated. Merge pull request #3156 from modelcontextprotocol/localden/docs-default-version Mark 2026-07-28 as the default docs version Mark 2026-07-28 as the default docs version Mintlify falls back to guessing the latest version when no entry sets default, and it currently resolves 2025-11-25 even though 2026-07-28 is first. Set default: true on the 2026-07-28 entry in both the Documentation and Specification tabs so the version chooser and the outdated-version banner point at the new release. :house: Remote-Dev: homespace Merge pull request #3154 from modelcontextprotocol/release/2026-07-28 Add 2026-07-28 MCP specification Reformat promoted 2026-07-28 pages after path rewrite The release promotion rewrites /specification/draft/ and /docs/draft/ paths to their dated equivalents inside the copied pages. The longer paths push some lines past the 80-column prose wrap, so prettier flags the promoted copies even though the draft originals are clean. Re-run prettier over the affected pages so the format check passes; only line wrapping changes. :house: Remote-Dev: homespace Skip redirect sources that already exist when cutting a release The nav patch step in cut-release adds a dated sibling redirect for every /specification/draft/... entry, but it never checked whether that dated source was already present. When main already carries the <version>/ redirects, the loop appends a second copy of each source and Mintlify rejects the resulting docs.json for reusing a source path, which is exactly what broke the 2026-07-28 release PR. Track the existing sources in a set and skip any collision so the step is idempotent regardless of what main already contains. :house: Remote-Dev: homespace Remove duplicate 2026-07-28 redirects from docs.json The cut-release nav patch appended a dated sibling for every /specification/draft/... redirect, but main already carried these five 2026-07-28 entries, so the sources ended up listed twice. Mintlify rejects a docs.json where a source path is used more than once, which blocks the deploy for this release PR. Drop the duplicated tail entries; the original definitions are unchanged. :house: Remote-Dev: homespace Add 2026-07-28 MCP specification Merge pull request #3153 from modelcontextprotocol/claude/redeploy-docs-20260728 Fix PyPI capitalization in registry FAQ Fix PyPI capitalization in registry FAQ Drop GA from the post title and slug Merge pull request #2805 from modelcontextprotocol/docs/2026-07-28-release Track 2026-07-28 release Merge pull request #3152 from modelcontextprotocol/claude/pr2805-review-fixes Rewrite spec links when cutting a release Update David Soria Parra's quote Mention the Rust SDK's beta support Merge pull request #3151 from modelcontextprotocol/claude/sync-main-into-release-0728 Sync main into the 2026-07-28 release branch Rewrite spec links when promoting draft to a dated version The promote step now self-dates /specification/draft/ links in the copied spec, docs, and schema trees. Merge main into docs/2026-07-28-release No textual conflicts. Rename detection applied main's server-concepts.mdx wording update (PR #2981) only to the 2025-06-18 copy, so the same edit was propagated by hand to the 2024-11-05, 2025-03-26, 2025-11-25, and draft copies. Main's NumberSchema erratum (PR #3139) applied cleanly to schema/2025-06-18 and schema/2025-11-25. npm run prep is clean. Merge pull request #3139 from modelcontextprotocol/paulc/2025-11-25-numberschema-erratum schema: fix NumberSchema numeric fields typed integer in released generated JSON (2025-06-18, 2025-11-25) Merge pull request #2981 from Uomocapra/codex/clarify-weather-tool-flow docs: clarify weather tool selection flow Merge branch 'main' into codex/clarify-weather-tool-flow Merge pull request #3150 from modelcontextprotocol/claude/pr2805-review-fixes Address adversarial review feedback on the release tracking PR Update David Soria Parra's quote Add Cloudflare quote from Brendan Irvine-Broque Reformat client concepts feature tables Prettier realigns the table columns after the elicitation row removal. Self-date spec links in the 2025-06-18 and 2025-11-25 guide snapshots Frozen guide pages linked to /specification/draft/ and /specification/latest/, so their spec citations would drift as the draft changes. Rewrite them to each snapshot's own dated spec tree, drop the tool name validation bullet from the 2025-06-18 tree since the tool name format section first appears in 2025-11-25, and fix the 2025-11-25 initialize example to negotiate 2025-11-25. Remove anachronistic content from the two oldest guide snapshots The 2024-11-05 and 2025-03-26 guides described elicitation and outputSchema, which first shipped in 2025-06-18. The 2024-11-05 tree also documented the Streamable HTTP transport, which arrived in 2025-03-26, and both trees showed 2025-06-18 initialize examples. Strip those sections, set initialize examples to each snapshot's own protocol version, use HTTP with SSE wording in the 2024-11-05 tree, and point spec links at each snapshot's own dated spec. Authorization spec links in the 2024-11-05 tree point at 2025-03-26, the first revision with an authorization spec. Extend David Soria Parra's quote Use the Honeycomb vector logo with theme-aware text Add David Soria Parra's quote Point draft spec cross-references at the draft docs tier Unversioned /docs/tutorials/ and /docs/learn/ links in the draft spec resolved through catch-all redirects to the frozen 2025-11-25 guides, which lack some of the cited security content. Rewrite all nine links to /docs/draft/. Also uppercase a normative MUST in the authorization scope hierarchy requirement. Fix extensions overview examples to match the draft schema The server/discover response now includes resultType, ttlMs, and cacheScope, carries serverInfo in _meta, and advertises 2026-07-28. The client capabilities example stamps the 2026-07-28 protocol version instead of 2025-06-18. Replace OpenAI PNG with theme-switching SVG logo Replace GIF placeholder with the stateless core demo video Add Prefect quote from Jeremiah Lowin Make quote divider overhang symmetric Use a slash separator in breadcrumbs Fix horizontal scrollbar from the footer hairline's 100vw breakout Order quote cards alphabetically by company Fix carousel backward navigation from the last page Add placeholder quote card for David Soria Parra Add Microsoft quote from Tina Schuchman Add PostHog and Supabase logos to quote cards Add Google Cloud, Arcade, Netlify, Xero, and Manufact logos to quote cards Align quote card logos to a shared top line Add partner logos to quote cards Add Honeycomb quote from Austin Parker Remove the quote shortcode's built-in quotation marks around quote text Simplify quote attributions to plain name, title, company Merge pull request #3146 from modelcontextprotocol/claude/release-final-sweep-2026-07-28 Sync docs/2026-07-28-release with main for the release (merge commit required) Add missing periods in build-client and authorization tutorial Add 2026-07-28 GA announcement post Merge main into docs/2026-07-28-release Merge pull request #3141 from modelcontextprotocol/feat/quote-component Blog: add quotes shortcode for testimonial cards Merge pull request #3144 from modelcontextprotocol/claude/python-examples-v2-resolved docs: modernise the Python examples for the 2026-07-28 release Remove quote component test post Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01YWbYcGYDQESh3KWwpfoc4V Bold the attribution name and move the title to its own line The figcaption now renders the name and title as separate block spans instead of one "Name, Title" line. The name is 700 in the body text color, the title stays 400 in the muted secondary color. A quote with no title renders the name alone. The test post gains a no-title variant to exercise that path. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01YWbYcGYDQESh3KWwpfoc4V Set quote attribution and text-logo fallback to regular weight PaperMod bolds figure > figcaption, which made the Name, Title line read too heavy. Override it to font-weight 400 so the attribution is a quiet secondary line, and drop the 600 weight on the no-logo company name fallback to match. Break the quote strip out of the prose column The quotes row now bleeds horizontally past the post column, capped at 1200px and centered in the viewport, with a slice of the next card peeking at the right edge whenever more cards exist than fit one view. The bleed bound leaves a 32px gutter that absorbs the page scrollbar, so the page never scrolls horizontally. Carousel init now waits for DOMContentLoaded so every quotes block on a page gets its controls, and the arrow disabled state follows the actual scroll position. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01YWbYcGYDQESh3KWwpfoc4V Merge branch 'docs/2026-07-28-release' into python-examples-v2 Resolves a prose conflict in docs/docs/draft/learn/architecture.mdx by taking the base branch's discovery-era paragraph, which already subsumes this branch's removal of the initialization wording. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_016ffRGFfKafAtUJ4fTYsf7U Align quote attributions to a shared start line Cards in a quotes row now adopt the track's explicit logo, quote, and attribution rows via CSS subgrid, so every attribution starts at the same line across a row and across carousel pages. Long quotes spill downward without clamping and short cards keep the open space. Attributions that wrap do so below the shared line. Browsers without subgrid fall back to the previous bottom-aligned flex layout. Subgrid is skipped below 600px where cards render one per view. Test post quotes now vary in length to show the behavior. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01YWbYcGYDQESh3KWwpfoc4V Merge pull request #3138 from modelcontextprotocol/dependabot/npm_and_yarn/tools/sep-automation/npm_and_yarn-6b7f7a8c69 build(deps-dev): bump postcss from 8.5.15 to 8.5.23 in /tools/sep-automation in the npm_and_yarn group across 1 directory Merge pull request #3134 from modelcontextprotocol/dependabot/github_actions/actions/labeler-7 build(deps): bump actions/labeler from 6 to 7 Merge pull request #3125 from kerlenton/fix/rc-blog-input-required docs(blog): fix resultType value in 2026-07-28 RC post Merge pull request #3069 from modelcontextprotocol/claude/rc-stateless-lifecycle docs: reflect the stateless protocol, server/discover, and session removal schema: fix 2025-06-18 NumberSchema min/max to number in generated JSON Same generator artifact as 2025-11-25: schema.ts declares number, the generated JSON says integer. 2025-06-18 has no default field on NumberSchema, so only minimum/maximum change. No-Verification-Needed: JSDoc-only source edit plus script-regenerated schema.json docs: restore the reviewed serverInfo and clientInfo placement Reverts d438d8e. Review feedback on this PR asked for the #3002 shape, with serverInfo carried in the result _meta as io.modelcontextprotocol/serverInfo and clientInfo as a SHOULD. The schema on the release branch predates #3002 and main still carries it. Merge remote claude/rc-stateless-lifecycle, keeping the acknowledgment example docs: move serverInfo to the discover result body and state required _meta fields The Discover Response example carried serverInfo under a nonexistent io.modelcontextprotocol/serverInfo key in the result _meta. The draft schema defines serverInfo as a required top-level field of DiscoverResult. The surrounding prose also described clientInfo as optional, while the schema and the base protocol page mark it required on every request. Add quotes shortcode for testimonial cards on the blog Adds a quotes/quote shortcode pair that renders testimonial cards in a row with hairline dividers, matching the docs site's design language. When more quotes than fit one view are given, a scroll-snap carousel with arrow buttons and pagination dots takes over. A lone quote renders full width as a pull quote. Includes a draft test post with fictional companies and original SVG wordmarks so the component can be reviewed in the PR preview. Drop the test post before or at merge. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01YWbYcGYDQESh3KWwpfoc4V Merge docs/2026-07-28-release into claude/rc-stateless-lifecycle Merge branch 'docs/2026-07-28-release' into claude/rc-stateless-lifecycle Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01DhtN33k4CMKjzsQL2jd6Z9 Merge pull request #3068 from modelcontextprotocol/claude/rc-server-concepts docs: document subscriptions/listen and CacheableResult in draft learn and client pages docs: align Python examples with the v2 SDK client API schema: fix 2025-11-25 NumberSchema min/max/default to number in generated JSON The TypeScript source declares these fields as `number`, but typescript-json-schema emits `integer` without an explicit hint, so the released 2025-11-25 schema.json rejects fractional values like `default: 95.5` that the schema.ts source of truth allows. Add the same @TJS-type annotations #2710 applied to the draft schema and regenerate. Same shape as 357adac4, which corrected Task.ttl nullability in the released 2025-11-25 generated schema when it contradicted schema.ts. No-Verification-Needed: JSDoc-only source edit plus script-regenerated schema.json docs: note that discovery is a cacheable per-server flow build(deps-dev): bump prettier from 3.9.5 to 3.9.6 (#3137) Bumps [prettier](https://github.com/prettier/prettier) from 3.9.5 to 3.9.6. - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](https://github.com/prettier/prettier/compare/3.9.5...3.9.6) --- updated-dependencies: - dependency-name: prettier dependency-version: 3.9.6 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> build(deps-dev): bump eslint from 10.7.0 to 10.8.0 (#3135) Bumps [eslint](https://github.com/eslint/eslint) from 10.7.0 to 10.8.0. - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/compare/v10.7.0...v10.8.0) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.8.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> build(deps-dev): bump postcss Bumps the npm_and_yarn group with 1 update in the /tools/sep-automation directory: [postcss](https://github.com/postcss/postcss). Updates `postcss` from 8.5.15 to 8.5.23 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/postcss/postcss/compare/8.5.15...8.5.23) --- updated-dependencies: - dependency-name: postcss dependency-version: 8.5.23 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> build(deps-dev): bump typescript-eslint from 8.64.0 to 8.65.0 (#3136) Bumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.64.0 to 8.65.0. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/typescript-eslint) --- updated-dependencies: - dependency-name: typescript-eslint dependency-version: 8.65.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> build(deps): bump actions/labeler from 6 to 7 Bumps [actions/labeler](https://github.com/actions/labeler) from 6 to 7. - [Release notes](https://github.com/actions/labeler/releases) - [Commits](https://github.com/actions/labeler/compare/v6...v7) --- updated-dependencies: - dependency-name: actions/labeler dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]> Merge docs/2026-07-28-release into claude/rc-stateless-lifecycle docs: update client concept guides for the 2026-07-28 protocol changes (#3067) * docs: update client concept guides for the 2026-07-28 draft - describe the form and URL elicitation modes and reframe the privacy guidance around URL mode - rewrite the elicitation and sampling flows for Multi Round-Trip Requests (InputRequiredResult / inputRequests) - mention tool calling in sampling and retarget the /docs/concepts/sampling redirect to the latest spec - drop roots/list_changed and logging/setLevel references and document the per-request io.modelcontextprotocol/logLevel _meta field - add deprecation callouts for Roots, Sampling, and Logging with suggested migrations Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_016WBaED7Rta4YsYVz66Qoru * docs: tighten deprecation wording in client guides Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01X5bczitGsFmjopooZXfbSQ * docs: explain MRTR once and link elsewhere Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01X5bczitGsFmjopooZXfbSQ * docs: make sampling params example match the draft schema Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01X5bczitGsFmjopooZXfbSQ * docs: drop duplicated logging advice in debugging warning Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01X5bczitGsFmjopooZXfbSQ * Update docs/docs/draft/learn/client-concepts.mdx * docs: group deprecated client features below the list Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01X5bczitGsFmjopooZXfbSQ --------- Co-authored-by: Claude <[email protected]> Co-authored-by: Den Delimarsky <[email protected]> Co-authored-by: Den Delimarsky <[email protected]> Merge pull request #3126 from jhauga/docs docs/authorization: resolve demo Python server 401 error docs: point the client tutorial at Claude Opus 5 The model id in the build-client examples was past its end-of-life date, so the Anthropic client warns on every run and a reader copying the page may get an error instead of a working chatbot. Move all eight language tabs to claude-opus-5. No-Verification-Needed: docs-only string swap docs/authorization: resolve demo Python server 401 error docs/authorization: resolve demo Python server 401 error docs(blog): fix resultType value in 2026-07-28 RC post docs: bring the Python examples up to SDK v2 The Python tabs across the release-branch guides were written against the v1 SDK. Two of them no longer run at all: the authorization tutorial imports `mcp.server.fastmcp`, which v2 deleted, and the debugging page calls `ctx.session.send_log_message`, where v2's `Context` has no `session`. The rest execute but teach shapes v2 replaced. - build-server: `from mcp.server import MCPServer`, and httpx2 in place of httpx. The SDK depends on httpx2, so `uv add "mcp[cli]"` already brings it in and the install line no longer needs to name an HTTP library. The stdio logging guidance moves to a module logger. - build-client: rebuilt on the high-level `Client` instead of `ClientSession` plus `AsyncExitStack`, which removes the connect and cleanup pair entirely. Tool schemas are read as `tool.input_schema`, and tool results are narrowed to text blocks with `is_error` handed to the model rather than raised. - architecture: the four pseudo-code blocks use `Client`, and the notification one follows changes with `client.listen(...)`. - debugging: standard library logging. The protocol logging capability is deprecated at 2026-07-28 and the SDK marks its `Context.log` deprecated alongside it. - authorization: `MCPServer`, with host, port and path moved from the constructor to `run()`, and httpx2 in the token verifier. - oauth-client-credentials: both snippets wrapped in `main()` so they run as pasted rather than raising a SyntaxError. Each block was assembled into the file a reader would actually create and executed against the shipping v2 SDK over stdio. The build-client tutorial was run against the build-server tutorial's server: it lists the tools, calls one, and negotiates 2026-07-28. Only the Python tabs changed. The other language tabs are untouched. No-Verification-Needed: docs-only change, examples driven end-to-end instead Merge pull request #3117 from jhauga/docs docs/authorization: resolve demo server 'Internal Server Error' Merge pull request #3123 from modelcontextprotocol/dependabot/npm_and_yarn/npm_and_yarn-04db377a11 build(deps): bump fast-uri from 3.1.2 to 3.1.4 in the npm_and_yarn group across 1 directory Merge pull request #3107 from modelcontextprotocol/dependabot/github_actions/actions/setup-node-7 build(deps): bump actions/setup-node from 6 to 7 build(deps): bump fast-uri in the npm_and_yarn group across 1 directory Bumps the npm_and_yarn group with 1 update in the / directory: [fast-uri](https://github.com/fastify/fast-uri). Updates `fast-uri` from 3.1.2 to 3.1.4 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.4) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.4 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Merge pull request #3110 from modelcontextprotocol/dependabot/npm_and_yarn/npm_and_yarn-7429694490 build(deps-dev): bump brace-expansion from 5.0.6 to 5.0.7 in the npm_and_yarn group across 1 directory Disable SEP reminder Fix formatting in authorization tutorial docs/authorization: resolve demo server 'Internal Server Error' fix: correct MISSING_REQUIRED_CLIENT_CAPABILITY error codes in SEP-2663 Merge pull request #3099 from modelcontextprotocol/claude/security-best-practices-relocation Move security guidance narratives to the security best practices page docs: broaden caching guidance to server/discover and resources/read; note best-effort notification delivery Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_018Ep4aMzUcNqroQQuXdiHKn docs: drop the session close step from the client example docs: link remaining subscriptions/listen mentions to the subscriptions spec page Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_018Ep4aMzUcNqroQQuXdiHKn docs: use client naming in the architecture examples Merge pull request #3111 from nbarbettini/patch-1 docs: Fix broken anchor to _meta build(deps-dev): bump brace-expansion Bumps the npm_and_yarn group with 1 update in the / directory: [brace-expansion](https://github.com/juliangruber/brace-expansion). Updates `brace-expansion` from 5.0.6 to 5.0.7 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](https://github.com/juliangruber/brace-expansion/compare/v5.0.6...v5.0.7) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 5.0.7 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> Merge pull request #3106 from olaservo/feature/add-note-on-structured-content docs: clarify structuredContent is not LLM "structured outputs" docs: state the per-request version declaration directly Merge pull request #3098 from modelcontextprotocol/claude/rc-java-examples docs: switch Java quickstart examples from SSE to Streamable HTTP docs: keep versioned tutorial pages scoped to the current protocol Merge pull request #3092 from DaleSeo/fix/sep-2575-error-codes docs: align SEP-2575 error codes docs: consolidate caching guidance and link subscription docs Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01AfPKVFyxGAbS7i2f2vhT2G Merge pull request #3064 from modelcontextprotocol/claude/rc-deprecations docs: reflect feature lifecycle deprecations and the Tasks recategorization Merge pull request #3066 from modelcontextprotocol/claude/rc-sdk-v2-examples docs: update code examples to the v2 SDKs docs: extract text blocks from tool results in the client quickstart docs: align SEP-2575 error codes Merge branch 'docs/2026-07-28-release' into claude/rc-deprecations Merge pull request #2992 from DaleSeo/docs/clarify-sep-2243-header-mismatch-code docs: clarify SEP-2243 HeaderMismatch error code build(deps-dev): bump typescript-json-schema from 0.67.4 to 0.68.0 (#3108) Bumps [typescript-json-schema](https://github.com/YousefED/typescript-json-schema) from 0.67.4 to 0.68.0. - [Commits](https://github.com/YousefED/typescript-json-schema/compare/v0.67.4...v0.68.0) --- updated-dependencies: - dependency-name: typescript-json-schema dependency-version: 0.68.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> build(deps): bump actions/setup-node from 6 to 7 Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/v6...v7) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]> docs: clarify structuredContent is not LLM "structured outputs" Add a note to the Structured Content section of the server tools spec clarifying that `structuredContent` is server-produced result data, unrelated to LLM provider "structured outputs" (schema-constrained model generation). The terms are routinely conflated. Applied to the draft, 2025-11-25, and 2025-06-18 revisions. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Apply review feedback docs: scope the subscription acknowledgment ordering guarantee Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01DhtN33k4CMKjzsQL2jd6Z9 docs: use American spelling in elicitation example and drop logging from client features bullet docs: tighten tools list-change prose Apply review feedback docs: tidy phrasing in changed prose docs: align identity exchange with the per-request _meta fields docs: use httpx2 in client credentials examples docs: cite SEP-2663 for the Tasks extension in roadmap docs: update Spring AI client customizer bullet to generic McpClientCustomizer docs: apply review wording for clientInfo and subscription acks Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01AfPKVFyxGAbS7i2f2vhT2G Align relocated text with the spec countermeasure list docs: add 'Changes since SEP became Final' section to SEP-2243 Preserve SEP-2243 as a historical record instead of editing its body, and document the HeaderMismatch error code reassignment from -32001 to -32020 (#2907) in a dedicated section per maintainer feedback. Also regenerate SEP-2549 docs, whose rendered mdx had drifted from its source on main, so 'npm run check:seps' passes on PR CI. Move security guidance narratives to the security best practices page Relocate attack walkthroughs and scope-strategy guidance from the authorization spec to the security best practices docs page. All normative requirements remain in the spec. docs: assume SDK 2.0.0 stable and drop unrelated SEP-1686 edit Unpin the Python SDK install commands in the client and server quickstarts and the OAuth client credentials guide, since these docs ship with the 2026-07-28 release when the stable 2.0.0 package is expected on PyPI. Update the system requirements lines to match. Restore the draft specification wording in the SEP-1686 historical note and regenerate the SEP docs. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01KGEZeUktW3zbqbqm5yuCEc docs: switch Java quickstart examples from SSE to Streamable HTTP docs: move Java example updates to a separate PR Merge pull request #2747 from spacewander/patch-1 Fix typos and clarify error handling for missing ttlMs Update seps/2549-TTL-for-list-results.md feat(schema): add optional serverInfo response metadata and make clientInfo optional (#3002) * feat(schema): add optional serverInfo response metadata and make clientInfo optional Merge pull request #3085 from modelcontextprotocol/docs/reserved-keys-table docs: add a consolidated table of reserved `_meta` keys Update docs/specification/draft/basic/index.mdx Co-authored-by: Den Delimarsky <[email protected]> Update docs/specification/draft/basic/index.mdx Co-authored-by: Den Delimarsky <[email protected]> Update docs/specification/draft/basic/index.mdx Co-authored-by: Den Delimarsky <[email protected]> Update docs/specification/draft/basic/index.mdx Co-authored-by: Den Delimarsky <[email protected]> Update docs/specification/draft/basic/index.mdx Co-authored-by: Den Delimarsky <[email protected]> docs: carry _meta on the tools/list example and fix listChanged prose Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01AfPKVFyxGAbS7i2f2vhT2G docs: keep apps build guide on v1 SDK and add node types to tsconfig examples The published @modelcontextprotocol/ext-apps (1.7.3) peer-depends on the v1 SDK and types registerAppTool against the v1 McpServer, so the MCP Apps build guide reverts to the v1 install commands and imports until a compatible ext-apps release ships. The quickstart tsconfig examples set "types": ["node"] because newer TypeScript versions dropped automatic @types inclusion. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01KGEZeUktW3zbqbqm5yuCEc docs: pin mcp 2.0.0b1 in examples and fix SEP-1686 wording Pin the Python SDK install commands in the client quickstart and the OAuth client credentials guide to mcp==2.0.0b1, since uv and pip skip prereleases and would otherwise install v1.x against v2-only code. Add the matching SDK version note to the client quickstart system requirements. Inline the InMemoryTokenStorage class into the PrivateKeyJWT Python example so the block runs as pasted. Name the 2026-07-28 specification in the SEP-1686 historical note instead of calling it the draft specification, and regenerate the SEP docs. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01KGEZeUktW3zbqbqm5yuCEc docs: tighten deprecation wording per review docs: link deprecation notes and mark Roots and Sampling in client features table Merge pull request #3065 from modelcontextprotocol/claude/rc-nav-redirects docs: add redirects for restructured spec pages build(deps-dev): bump typescript-eslint from 8.63.0 to 8.64.0 (#3087) Bumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.63.0 to 8.64.0. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.64.0/packages/typescript-eslint) --- updated-dependencies: - dependency-name: typescript-eslint dependency-version: 8.64.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Merge pull request #3084 from modelcontextprotocol/docs/improvements Small Spec Improvements Merge pull request #3086 from modelcontextprotocol/fix/pin-typescript-6 build(deps-dev): pin typescript back to 6.x docs: add a consolidated table of reserved `_meta` keys The keys reserved by the spec were scattered across prose in several pages (per-request fields, logging, subscriptions, OpenTelemetry), making it easy to miss one. List them in a single table in the General fields section, pointing to where each key is normatively defined. Extension-defined keys stay in each extension's own documentation. No-Verification-Needed: doc-only change Update docs/specification/draft/basic/patterns/subscriptions.mdx Co-authored-by: Den Delimarsky <[email protected]> Update docs/specification/draft/basic/index.mdx Co-authored-by: Den Delimarsky <[email protected]> docs: remove confusing sentence docs: define the subscription acknowledgment ordering per subscription, not per stream The rule said the acknowledgment MUST be the first message "on the stream", which is meaningless on stdio, where every subscription shares one channel. An implementation could read it as vacuous there and emit notifications for a subscription before acknowledging it, leaving the client with data it cannot yet interpret. State the rule in terms of the subscription ID instead, and say explicitly that messages for other subscriptions may be interleaved ahead of it. No-Verification-Needed: doc-only change (JSDoc, prose, and regenerated output) docs: make MUST NOT in General Field's section bold docs: `_meta` is just part of the schema. It's not more or less reserved than any other field. docs: explain the optional `data` field in the error response build(deps-dev): pin typescript back to 6.x typedoc 0.28.20 declares a peer range of 5.0.x - 6.0.x and has no release supporting TypeScript 7, so bumping typescript to 7.0.2 made `npm ci` fail to resolve. This broke every job that installs dependencies, on main and on all open pull requests. Restore package.json and package-lock.json to their pre-bump state and tell Dependabot to hold back typescript majors until typedoc supports them. No-Verification-Needed: dependency revert, lockfile, and CI config only Merge pull request #3083 from jhauga/docs docs: inline style to proportionally render icons docs: inline style to proportionally render icons Merge pull request #3079 from modelcontextprotocol/dependabot/npm_and_yarn/typescript-7.0.2 build(deps-dev): bump typescript from 6.0.3 to 7.0.2 fix(spec): replace Mcp-Param-* implementation note with rejection-retry guidance (#3071) Remove the implementation note about constructing Mcp-Param-* headers when the inputSchema has not been obtained, which contradicted the validation table labeling header omission as non-conforming. Keep the recovery path as inline prose: on a HeaderMismatch rejection, clients SHOULD re-fetch tools/list and retry. Fixes #2974 Merge branch 'main' into dependabot/npm_and_yarn/typescript-7.0.2 build(deps-dev): bump prettier from 3.9.4 to 3.9.5 (#3078) Bumps [prettier](https://github.com/prettier/prettier) from 3.9.4 to 3.9.5. - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](https://github.com/prettier/prettier/compare/3.9.4...3.9.5) --- updated-dependencies: - dependency-name: prettier dependency-version: 3.9.5 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> build(deps-dev): bump eslint from 10.6.0 to 10.7.0 (#3077) Bumps [eslint](https://github.com/eslint/eslint) from 10.6.0 to 10.7.0. - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/compare/v10.6.0...v10.7.0) --- updated-dependencies: - dependency-name: eslint dependency-version: 10.7.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> build(deps-dev): bump typescript from 6.0.3 to 7.0.2 Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]> build(deps-dev): bump typescript-eslint from 8.62.1 to 8.63.0 (#3080) Bumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.62.1 to 8.63.0. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.63.0/packages/typescript-eslint) --- updated-dependencies: - dependency-name: typescript-eslint dependency-version: 8.63.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> build(deps-dev): bump tsx from 4.23.0 to 4.23.1 (#3076) Bumps [tsx](https://github.com/privatenumber/tsx) from 4.23.0 to 4.23.1. - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](https://github.com/privatenumber/tsx/compare/v4.23.0...v4.23.1) --- updated-dependencies: - dependency-name: tsx dependency-version: 4.23.1 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Merge pull request #3073 from jhauga/docs-develop docs/develop: img and text edits to latest Claude UI version resolve: md formatting error docs/develop: img and text edits to latest Claude UI version docs: clean up remaining tasks, sse, and client logging references docs: leave debugging logging sections to the client concepts PR Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01DhtN33k4CMKjzsQL2jd6Z9 docs: clarify cacheScope semantics in architecture guide cacheScope controls who may cache a response, while ttlMs controls how long the result stays fresh. The previous wording attributed reuse duration to both fields. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_016WBaED7Rta4YsYVz66Qoru docs: address review feedback on stateless lifecycle bundle - Note that tools/list also accepts an optional cursor for pagination - Add the Logging deprecation warning to the debugging guide - Show the mandatory subscriptions/listen acknowledgment in the architecture walkthrough - Retitle the new session hijacking subsections to Title Case to match the file's heading convention Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_016WBaED7Rta4YsYVz66Qoru docs: make draft protocol examples in architecture overview spec-valid Add the required per-request _meta fields to the subscriptions/listen and follow-up tools/list examples, and add resultType: "complete" to the tools/list response that shows the ttlMs and cacheScope hints. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_016WBaED7Rta4YsYVz66Qoru docs: update extension negotiation phrasing to per-request capabilities Extensions are declared in the extensions field of the per-request clientCapabilities carried in _meta and in the server capabilities returned by server/discover, so replace the initialize-time phrasing in the client matrix and the auth and tasks overviews. Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_016WBaED7Rta4YsYVz66Qoru docs: scope session hijacking guidance and cover state handles Protocol revision 2026-07-28 removes protocol-level sessions and the Mcp-Session-Id header, so scope the session hijacking attacks to protocol versions 2025-11-25 and earlier and add guidance for securing the explicit …
Tracking PR for the 2026-07-28 specification release. Merging this branch publishes the documentation for the release.
What ships
server/discover, and session removal reflected across the learn and debugging pages (docs: reflect the stateless protocol, server/discover, and session removal #3069)subscriptions/listenand theCacheableResultcaching fields (docs: document subscriptions/listen and CacheableResult in draft learn and client pages #3068)mainand a quality sweep of the release diff (Sync docs/2026-07-28-release with main for the release (merge commit required) #3146)Issue tracking
The documentation work for this release was tracked in the 2026-07-28 Specification Release milestone. All 27 documentation issues in the milestone (#3026 to #3052) were closed as completed on 2026-07-27, so this PR carries no closing keywords.