Summary
The MCP spec released a new revision on 2026-07-28 (announced at https://blog.modelcontextprotocol.io/posts/2026-07-28/) that moves from the stateful bidirectional protocol to a stateless request/response model. Key changes relevant to us:
- The
initialize/initialized handshake and session IDs are eliminated; each request is self-describing.
- Server-initiated elicitation is replaced by "Multi Round-Trip Requests" (MRTR).
- Sampling is deprecated.
- Roots and Logging are also deprecated.
- Header-based routing, cacheable list results, tasks moved to an official extensions framework.
- Security: RFC 9207 issuer validation required, shift from Dynamic Client Registration toward Client ID Metadata Documents (CIMD).
- Deprecations get a 12-month minimum window; legacy HTTP+SSE transport gets a year-long offramp. No fire drill, but not indefinite either.
As of this issue, @modelcontextprotocol/sdk on npm is still on the 1.x line (1.30.0 latest) — there is no separate 2.0.0 package. The new spec appears to be supported via 1.x releases, not a major SDK version bump.
Why this needs a dedicated pass, not an incidental bump
This repo is actively building on the mechanisms this spec revision replaces/deprecates — most concretely, the in-progress add-preview-token-elicitation work (PR #57) depends on server-initiated elicitation, the exact thing MRTR replaces. Migrating means redesigning against whatever MRTR's actual API surface turns out to be, not just bumping a dependency version.
What to check before starting
Non-goals for now
- No urgency given the 12-month deprecation window.
- The routine SDK dependency bump (
1.29.0 → 1.30.0) is handled separately and does not itself adopt the new spec — see the corresponding PR.
See also mapbox/mcp-server#245 for the equivalent tracking issue there.
Summary
The MCP spec released a new revision on 2026-07-28 (announced at https://blog.modelcontextprotocol.io/posts/2026-07-28/) that moves from the stateful bidirectional protocol to a stateless request/response model. Key changes relevant to us:
initialize/initializedhandshake and session IDs are eliminated; each request is self-describing.As of this issue,
@modelcontextprotocol/sdkon npm is still on the1.xline (1.30.0latest) — there is no separate2.0.0package. The new spec appears to be supported via 1.x releases, not a major SDK version bump.Why this needs a dedicated pass, not an incidental bump
This repo is actively building on the mechanisms this spec revision replaces/deprecates — most concretely, the in-progress
add-preview-token-elicitationwork (PR #57) depends on server-initiated elicitation, the exact thing MRTR replaces. Migrating means redesigning against whatever MRTR's actual API surface turns out to be, not just bumping a dependency version.What to check before starting
elicitInput/Sampling beyond the in-progress PR [security] Add MCP elicitation for secure preview token handling #57 work.Non-goals for now
1.29.0→1.30.0) is handled separately and does not itself adopt the new spec — see the corresponding PR.See also mapbox/mcp-server#245 for the equivalent tracking issue there.