VC
Value Add VC
⚡HomePulse⚡Helpful Apps📝Blog
Illustration for: MCP Ships Its Biggest Spec Update Since 2024 Launch
Value Add VC/Pulse/AI10,000+ servers

MCP Ships Its Biggest Spec Update Since 2024 Launch

The Model Context Protocol finalized its 2026-07-28 specification, moving to a stateless protocol core with hardened OAuth 2.1 authentication, as adoption crosses 10,000 servers across Anthropic, OpenAI, Google, Microsoft and AWS.

10,000+
MCP servers live
12 months
Deprecation window
2026-07-28
Spec version
TC
Trace Cohen
Early-stage VC & angel · Founder, New York Venture Partners
July 28, 2026
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

The Model Context Protocol's new 2026-07-28 specification eliminates the stateful initialize/initialized session handshake at the protocol layer, meaning any server instance can now handle any request without sticky routing or shared session stores

2

Every request now carries protocol version, client identity and capabilities in a metadata field, a change specifically designed to make MCP servers easier to run behind load balancers at enterprise scale

3

The spec hardens authentication around OAuth 2.1, addressing security gaps that had made enterprise security teams cautious about deploying MCP-based agent integrations in production

4

Adoption has crossed 10,000 MCP servers with Anthropic, OpenAI, Google, Microsoft and AWS all supporting the protocol, and legacy versions get a 12-month deprecation window rather than an abrupt cutover

TC

The VC Read · Trace's Take

Trace Cohen

Getting Anthropic, OpenAI, Google, Microsoft and AWS to agree on anything is rare enough that it's worth pausing on -- a shared, hardened standard for how agents reach tools reduces fragmentation risk for every startup building on top of it, which is exactly the kind of unglamorous infrastructure work that ends up mattering more than any single model release.

AI Landscape →

Analysis

The Model Context Protocol finalized its largest specification update since launching in 2024 on Tuesday, moving the standard that has become the default way AI agents connect to external tools and data sources onto a stateless protocol core with substantially hardened authentication.

The headline technical change is that MCP no longer manages sessions at the protocol layer -- the initialize/initialized handshake that previously required servers to track client state across a session is gone. Instead, every request now carries protocol version, client identity and capabilities directly in a metadata field, meaning any server instance can handle any incoming request without needing sticky routing or a shared session store. That's a meaningful infrastructure simplification for anyone running MCP servers at scale behind a load balancer, eliminating an entire class of operational complexity that had made production MCP deployments harder to scale than they needed to be.

The second major change hardens authentication around OAuth 2.1, directly addressing security concerns that had made enterprise security teams cautious about approving MCP-based agent integrations for production use -- concerns that align closely with the broader AI agent security anxiety driving products like Snowflake's new Cortex AI Gateway and the seed-stage rush into AI-native cybersecurity startups this year.

Adoption momentum behind the protocol is now substantial: more than 10,000 MCP servers are live, with Anthropic, OpenAI, Google, Microsoft and AWS all supporting the standard despite otherwise being fierce competitors across nearly every other layer of the AI stack. That's an unusually broad coalition for a technical standard in a space this competitive, and it reflects how much value every major AI player sees in a common, interoperable way for agents to reach external tools.

The update includes a 12-month deprecation window for legacy protocol versions rather than an abrupt cutover, giving the large existing ecosystem of MCP integrations time to migrate without breaking production systems overnight.

What to watch: how quickly major MCP server providers migrate to the stateless spec, whether the OAuth 2.1 hardening meaningfully reduces the security incidents that have made enterprises cautious about agent tool access, and whether this consolidation around a shared standard accelerates enterprise AI agent adoption more broadly over the next year.

ShareXLinkedInEmail
More onAnthropic →OpenAI →Google →Microsoft →

Analysis and editorial commentary by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.

Read Next

AI· Jul 28, 2026

Anthropic's Claude Code Reigns Despite Codex Rise

Illustration for: Anthropic's Claude Code Reigns Despite Codex Rise
AI~42% share

Anthropic's Claude Code Reigns Despite Codex Rise

Claude Code holds roughly 42% of enterprise AI-coding market share, more than double OpenAI's, even as Codex's open-source Apache-2.0 release and OpenCode both gain developer interest.

AI· Jul 27, 2026

Microsoft Launches In-House Rival To Anthropic's Mythos

Illustration for: Microsoft Launches In-House Rival To Anthropic's Mythos
AI96% CyberGym

Microsoft Launches In-House Rival To Anthropic's Mythos

Microsoft unveiled MAI-Cyber-1-Flash, an in-house cybersecurity model that scores 96% on the CyberGym benchmark, beating Anthropic's Mythos, Gemini and GPT while cutting costs roughly in half.

AI· Jul 28, 2026

Moonshot Seeks More Blackwell Chips For Next Model

Illustration for: Moonshot Seeks More Blackwell Chips For Next Model
AI

Moonshot Seeks More Blackwell Chips For Next Model

Chinese lab Moonshot AI is seeking additional Nvidia Blackwell chips to train Kimi K4, its next model, days after the White House accused it of illegally accessing banned GB300 chips through Thailand-based infrastructure.

@Trace_Cohen·t@nyvp.com