Skip to content

SEP-3318: Verifiable Conversation Handles - #3318

Closed
ryan-s-roberts wants to merge 5 commits into
modelcontextprotocol:mainfrom
ryan-s-roberts:sep/conversation-handle
Closed

ryan-s-roberts wants to merge 5 commits into
modelcontextprotocol:mainfrom
ryan-s-roberts:sep/conversation-handle

Conversation

@ryan-s-roberts

@ryan-s-roberts ryan-s-roberts commented Aug 28, 2026 •

Copy link
Copy Markdown

Summary

Standards Track SEP (Awaiting Sponsor) for a client-carried, server-minted, sequenced conversation identifier in _meta (io.modelcontextprotocol/conversation-handle).

  • Ordering (seq) is the main protocol contribution — ACLs alone cannot recover “is this the current handle?”
  • MAC enables lookup-free rejection of fabricated tokens at the edge; it is not a substitute for §2.3 principal association (same enforcement point SEP-2567 already recommends)
  • Negotiated via SEP-2133 extensions map; does not restore core sessions

Venues

Venue Role
transports-wg#36 Canonical Conversation/Thread ID thread — this SEP answers lifecycle (§4) and list-scope (§6.4: no list mutation)
Security IG Threat model, §2.3, exchange/expiry, IFC example
Agents WG Memory/orchestration fit; orthogonal to Tasks

Prior art cited: SEP-1655 (why not cookie+MAC), SEP-1685, discussion #2894, SEP-2822 → #36.

Behaviour notes (review remediation)

  • Exchange of expired handles is gated on §2.3 association + retention (no fresh handle for unauthenticated / mismatched principal)
  • Concurrent replacements: client keeps highest seq; opaque commitments are LWW by seq

Evidence of work (human-owned)

Operational origin: Plasm / conversation-scoped memory + IFC needs — not a cold speculative write-up.

AI disclosure (AI_POLICY.md)

This PR’s SEP prose and supporting edits were produced with Cursor agent assistance (drafting, restructuring, formatting, CI fixes). Design choices, Quint model, conformance suite, and reference implementation were directed and reviewed by the author (@ryan-s-roberts). Extent: substantial documentation/editing assistance; not unattended generation.

Seeking sponsor

Looking for a Core Maintainer / Maintainer sponsor. Transports WG (#36) is the natural product venue; Security IG for threat review; Agents WG for memory/orchestration.

CC: @kurtisvg (transports-wg#36) @SamMorrowDrums @olaservo @PederHP @ostefano @CaitieM20 @LucaButBoring @pja-ant

ryan-s-roberts and others added 2 commits August 28, 2026 11:02
Standards Track draft for MAC-bound conversation identity, co-presented
to Security IG and Agents WG. Seeking sponsor.

Co-authored-by: Cursor <[email protected]>
Matches SEP process: file and header use the pull request number.

Co-authored-by: Cursor <[email protected]>
@ryan-s-roberts ryan-s-roberts changed the title SEP-0000: Verifiable Conversation Handles SEP-3318: Verifiable Conversation Handles Aug 28, 2026
Satisfy markdown format check and render-seps by formatting the SEP
and regenerating docs/seps artifacts via npm run generate:seps.

Co-authored-by: Cursor <[email protected]>
@ryan-s-roberts
ryan-s-roberts requested review from a team as code owners August 28, 2026 10:12
ryan-s-roberts and others added 2 commits August 28, 2026 11:18
Mintlify rejects <https://...> as JSX. Convert References to markdown
links and simplify the Foundry table cell that broke nested backticks.

Co-authored-by: Cursor <[email protected]>
Awaiting Sponsor; Transports WG + Agents WG; seq-first framing; gate
exchange on association; drop conversationId response mirror; cite
transports-wg#36 and SEP-1655 prior art.

Co-authored-by: Cursor <[email protected]>
@ryan-s-roberts

Copy link
Copy Markdown
Author

Docs / Status note (hybrid remediation): Status is now Awaiting Sponsor (not Draft). CI’s render-seps requires generated docs/seps/* whenever a file exists under seps/; the regenerated nav places this SEP under an Awaiting sponsor group rather than Draft/Final. If maintainers prefer proposal SEPs omitted from the docs site until sponsorship, say the word and we can discuss an exception — deleting the docs artifacts alone fails check:seps.

Normative tightening called out for reviewers: §4.4 exchange is now explicitly gated on §2.3 association + retention; response _meta no longer mirrors conversationId.

@kurtisvg

Copy link
Copy Markdown
Contributor

Sessions / Conversation IDs is covered in the Transports WG Roadmap as not planned:

Note — not planned for the 2026-12-15 release. Protocol-level sessions and the initialization handshake were removed in 2026-07-28. The WG will only reconsider something session-shaped if compelling, concrete use cases cannot be addressed by narrower mechanisms. Until that bar is met, this track remains problem-definition work rather than protocol design.

There is currently a problem statement here that summarizes the problems: modelcontextprotocol/transports-wg#47

My 2c is that this SEP doesn't address those problems, or make a clear case for why conversation ids belong in the protocol other than "lots of other places have them".

@ryan-s-roberts

Copy link
Copy Markdown
Author

Let me park this while I take modelcontextprotocol/transports-wg#47 into account

@ryan-s-roberts

Copy link
Copy Markdown
Author

Yes this is far too complex for reasonable adoption outside of my use cases. Closing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants