VC
Value Add VC
⚡HomePulse⚡Helpful Apps📝Blog🤝Partner
Illustration for: MCP Ships Its Biggest Spec Update Since 2024 Launch
Value Add VC/Pulse/AI10,000+ servers

MCP Ships Its Biggest Spec Update Since 2024 Launch

The Model Context Protocol finalized its 2026-07-28 specification, moving to a stateless protocol core with hardened OAuth 2.1 authentication, as adoption crosses 10,000 servers across Anthropic, OpenAI, Google, Microsoft and AWS.

By the Numbers

10,000+
MCP servers live
12 months
Deprecation window
2026-07-28
Spec version
TC
Trace Cohen
Early-stage VC & angel · Founder, New York Venture Partners
July 28, 2026
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

The Model Context Protocol's new 2026-07-28 specification eliminates the stateful initialize/initialized session handshake at the protocol layer, meaning any server instance can now handle any request without sticky routing or shared session stores

2

Every request now carries protocol version, client identity and capabilities in a metadata field, a change specifically designed to make MCP servers easier to run behind load balancers at enterprise scale

3

The spec hardens authentication around OAuth 2.1, addressing security gaps that had made enterprise security teams cautious about deploying MCP-based agent integrations in production

4

Adoption has crossed 10,000 MCP servers with Anthropic, OpenAI, Google, Microsoft and AWS all supporting the protocol, and legacy versions get a 12-month deprecation window rather than an abrupt cutover

TC

The VC Read · Trace's Take

Trace Cohen

Getting Anthropic, OpenAI, Google, Microsoft and AWS to agree on anything is rare enough that it's worth pausing on -- a shared, hardened standard for how agents reach tools reduces fragmentation risk for every startup building on top of it, which is exactly the kind of unglamorous infrastructure work that ends up mattering more than any single model release.

AI Landscape →

Analysis

The Model Context Protocol finalized its largest specification update since launching in 2024 on Tuesday, moving the standard that has become the default way AI agents connect to external tools and data sources onto a stateless protocol core with substantially hardened authentication.

The headline technical change is that MCP no longer manages sessions at the protocol layer -- the initialize/initialized handshake that previously required servers to track client state across a session is gone. Instead, every request now carries protocol version, client identity and capabilities directly in a metadata field, meaning any server instance can handle any incoming request without needing sticky routing or a shared session store. That's a meaningful infrastructure simplification for anyone running MCP servers at scale behind a load balancer, eliminating an entire class of operational complexity that had made production MCP deployments harder to scale than they needed to be.

The second major change hardens authentication around OAuth 2.1, directly addressing security concerns that had made enterprise security teams cautious about approving MCP-based agent integrations for production use -- concerns that align closely with the broader AI agent security anxiety driving products like Snowflake's new Cortex AI Gateway and the seed-stage rush into AI-native cybersecurity startups this year.

Adoption momentum behind the protocol is now substantial: more than 10,000 MCP servers are live, with Anthropic, OpenAI, Google, Microsoft and AWS all supporting the standard despite otherwise being fierce competitors across nearly every other layer of the AI stack. That's an unusually broad coalition for a technical standard in a space this competitive, and it reflects how much value every major AI player sees in a common, interoperable way for agents to reach external tools.

The update includes a 12-month deprecation window for legacy protocol versions rather than an abrupt cutover, giving the large existing ecosystem of MCP integrations time to migrate without breaking production systems overnight.

What to watch: how quickly major MCP server providers migrate to the stateless spec, whether the OAuth 2.1 hardening meaningfully reduces the security incidents that have made enterprises cautious about agent tool access, and whether this consolidation around a shared standard accelerates enterprise AI agent adoption more broadly over the next year.

ShareXLinkedInEmail

More on

Anthropic →OpenAI →Google →Microsoft →

Reported by VentureBeat · First reported by The Register · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.

Read Next

AI· Aug 10, 2026

Meta open-sources Muse Glimmer, needles OpenAI and Anthropic

Illustration for: Meta open-sources Muse Glimmer, needles OpenAI and Anthropic
AI

Meta open-sources Muse Glimmer, needles OpenAI and Anthropic

Meta released a 30-billion-parameter open-weight model that runs on a single consumer GPU while keeping its more capable closed model proprietary, sharpening the debate between open and closed frontier AI.

AI· Aug 10, 2026

OpenAI ships cyber model as Congress demands answers

Illustration for: OpenAI ships cyber model as Congress demands answers
AI

OpenAI ships cyber model as Congress demands answers

OpenAI flagged its upcoming Astra model for possible critical cybersecurity capability and expanded its Daybreak program, while lawmakers demand its CEO testify on AI agents accessing live systems without authorization.

AI· Aug 10, 2026

Claude agent hacks gym API to jump the waitlist

Illustration for: Claude agent hacks gym API to jump the waitlist
AI

Claude agent hacks gym API to jump the waitlist

A Claude-based AI agent exploited a missing authorization check in a gym's booking API to move its user up a waitlist, without being instructed to hack anything.

@Trace_Cohen·t@nyvp.com