Home / Articles / Practical notes: MCP Just Changed Its Architecture: Why the 2026 Specification

This article is published in English.

Practical notes: MCP Just Changed Its Architecture: Why the 2026 Specification

Operable walkthrough of Practical notes: MCP Just Changed Its Architecture: Why the 2026 Specification: contracts, checks, and drop-in code slots for teams shipping this pattern.

4603 words

Use this as an operator-facing rebuild of the ideas in “MCP Just Changed Its Architecture: Why the 2026 Specification Makes MCP Truly Cloud-Native”: clear stages, ordered code slots, and recovery notes that survive a handoff. The Overview stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

Why Stateful MCP Broke

For the Why Stateful MCP Broke stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Authenticate at the gateway and re-authorize at the data plane. A bearer token alone is not a tenancy boundary.

What the New Spec Removes

For the What the New Spec stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline. Authenticate at the gateway and re-authorize at the data plane. A bearer token alone is not a tenancy boundary.

Client
  |
  | initialize
  v
MCP Server
  |
  | Mcp-Session-Id = ABC
  v
Client
  |
  | tools/call + Mcp-Session-Id: ABC
  v
Same logical server session
Client
  |
  | tools/call
  | protocol version
  | capabilities
  | client metadata
  v
Load Balancer
  |
  +----> MCP Instance A
  |
  +----> MCP Instance B
  |
  +----> MCP Instance C
POST /mcp HTTP/1.1
MCP-Protocol-Version: 2026-07-28
Mcp-Method: tools/call
Mcp-Name: search
Content-Type: application/json
{
  "basket_id": "bsk_8f2a..."
}
{
  "basket_id": "bsk_8f2a...",
  "item_id": "SKU-123"
}
MCP protocol state
        |
        v
       NONEApplication state
        |
        v
Explicit IDs + external state store


Long-running task state
        |
        v
Tasks extension + durable task store

Where the Handshake Info Went

For the Where the Handshake Info stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion. Authenticate at the gateway and re-authorize at the data plane. A bearer token alone is not a tenancy boundary. For the Where the Handshake Info stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

{
  "jsonrpc": "2.0",
  "id": 42,
  "method": "tools/call",
  "params": {
    "name": "search",
    "arguments": {
      "query": "MCP stateless architecture"
    },
    "_meta": {
      "io.modelcontextprotocol/protocolVersion": "2026-07-28",
      "io.modelcontextprotocol/clientCapabilities": {
        "extensions": {
          "io.modelcontextprotocol/tasks": {}
        }
      },
      "io.modelcontextprotocol/clientInfo": {
        "name": "my-agent",
        "version": "3.2.0"
      }
    }
  }
}

Round Robin And Scale To Zero

When working through the Round Robin And Scale stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Log tool name, args hash, latency, and outcome for every call. Debugging agent loops without that trail wastes hours.

                  +------------------+
                  |  Load Balancer   |
                  +---------+--------+
                            |
               +------------+------------+
               |            |            |
               v            v            v
           MCP Pod A    MCP Pod B    MCP Pod C

Managing State Yourself

When working through the Managing State Yourself stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline. Log tool name, args hash, latency, and outcome for every call. Debugging agent loops without that trail wastes hours.

create_purchase_request()
        |
        v
purchase_request_id = pr_123
        |
        v
request_approval(pr_123)
        |
        v
approval_id = appr_789
        |
        v
submit_purchase(pr_123, appr_789)
{
  "purchase_request_id": "pr_123",
  "user_id": "user_42",
  "status": "awaiting_approval",
  "items": [
    {
      "sku": "GPU-H100",
      "quantity": 100
    }
  ],
  "created_at": "2026-08-21T08:00:00Z"
}

Multi Round-Trip Requests

When working through the Multi Round-Trip Requests stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion. Log tool name, args hash, latency, and outcome for every call. Debugging agent loops without that trail wastes hours. When working through the Multi Round-Trip Requests stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

delete_customer_data(customer_id=123)
{
  "resultType": "input_required",
  "inputRequests": {
    "confirm": {
      "type": "elicitation",
      "message": "Delete 48 records?",
      "schema": {
        "type": "boolean"
      }
    }
  },
  "requestState": "..."
}
Client
   |
   | tools/call
   v
Server
   |
   | input_required
   | requestState
   v
Client
   |
   | user confirmation
   v
Client
   |
   | same operation + inputResponses + requestState
   v
Any MCP instance

HTTP Headers And Cache Hints

The HTTP Headers And Cache stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Expose tools with narrow schemas and explicit side-effect labels. Hosts need to know which calls mutate state before they auto-approve.

Mcp-Method = tools/call
Mcp-Name   = search
tools/call + search  -> route/search-cluster
tools/call + execute -> route/execution-cluster
resources/read       -> route/resource-cluster
{
  "result": {
    "tools": [
      ...
    ],
    "ttlMs": 60000,
    "cacheScope": "public"
  }
}
fresh_until = response_received_time + ttlMs

Long Running Tasks

The Long Running Tasks stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline. Expose tools with narrow schemas and explicit side-effect labels. Hosts need to know which calls mutate state before they auto-approve.

run_ml_training_job()
{
  "resultType": "task",
  "task": {
    "taskId": "task_7b93...",
    "status": "working"
  }
}
tasks/get(taskId)
Core MCP
    |
    +---- Stateless request/response
Tasks extension
    |
    +---- Durable asynchronous state machine
MCP tools/call
      |
      v
Create task
      |
      v
Queue / workflow engine
      |
      +--> Kubernetes Job
      |
      +--> Azure Batch
      |
      +--> AWS Step Functions
      |
      +--> Databricks Job
      |
      +--> CI/CD pipeline
Client                  MCP Server               Task DB / Engine
  |                         |                           |
  |--- 1. tools/call ------>|                           |
  |                         |--- 2. Register Task ----->| (Status: working)
  |<-- 3. Return taskId ----|                           |
  |                         |                           |
  |--- 4. tasks/get ------->|                           |
  |                           \--- 5. Query state ----->| (Status: working)
  |<-- 6. Status: working --/                           |
  |                         |                           |
  |--- 7. tasks/get ------->|                           |
  |                           \--- 8. Query state ----->| (Status: completed)
  |<-- 9. Final Result -----/                           |

A Real-Time Use Case: Production AI Data and ML Operations Agent

The A Real-Time Use Case stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion. Expose tools with narrow schemas and explicit side-effect labels. Hosts need to know which calls mutate state before they auto-approve. The A Real-Time Use Case stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

search_dataset()
inspect_schema()
run_sql()
start_training_job()
get_training_metrics()
deploy_model()
rollback_deployment()
search_dataset("customer churn latest")
{
  "dataset_id": "ds_2026_08_20_0042"
}
inspect_schema("ds_2026_08_20_0042")
start_training_job("ds_2026_08_20_0042")
task_id = "task_train_98af..."
tasks/get("task_train_98af...")
QUEUED
   |
RUNNING
   |
EVALUATING
   |
INPUT_REQUIRED
   |
RUNNING
   |
COMPLETED
inputResponses = {
    "approve": true
}
                  Ingress
                      |
              Load Balancer
                      |
        +------+------+------+------+
        |      |      |      |      |
       MCP1   MCP2   MCP3   MCP4   MCP5
                      |
                      v
               Task Store
                      |
              +-------+-------+
              |               |
           Redis          PostgreSQL
              |
              v
        Workflow Engine
              |
        +-----+------+
        |            |
     GPU Job     Model Registry

Authorization And Security Hardening

For the Authorization And Security Hardening stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Authenticate at the gateway and re-authorize at the data plane. A bearer token alone is not a tenancy boundary.

basket_id = bsk_123
user_id   = user_456
authenticated_subject == basket.owner
User Request
    |
    v
Agent
    |
    | traceparent
    v
MCP Client
    |
    | traceparent
    v
MCP Gateway
    |
    v
MCP Server
    |
    v
Database / Queue / API

Extensions Become First-Class

For the Extensions Become First-Class stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline. Authenticate at the gateway and re-authorize at the data plane. A bearer token alone is not a tenancy boundary.

                    MCP
                     |
          +----------+----------+
          |                     |
       Core Protocol        Extensions
          |                     |
      Stateless HTTP      +-----+------+
                          |            |
                       Tasks       MCP Apps

Deprecations And Upgrading

For the Deprecations And Upgrading stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion. Authenticate at the gateway and re-authorize at the data plane. A bearer token alone is not a tenancy boundary. For the Deprecations And Upgrading stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

What This Means For MCP Architecture

When working through the What This Means For stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Log tool name, args hash, latency, and outcome for every call. Debugging agent loops without that trail wastes hours.

                 +----------------------------+
                 |        MCP Protocol        |
                 | JSON-RPC + request model   |
                 +-------------+--------------+
                               |
                 +-------------v--------------+
                 |         Transport          |
                 | stdio / Streamable HTTP    |
                 +-------------+--------------+
                               |
                 +-------------v--------------+
                 |      Application Layer     |
                 | explicit IDs + databases   |
                 +-------------+--------------+
                               |
                 +-------------v--------------+
                 |         Extensions         |
                 | Tasks / MCP Apps / others   |
                 +----------------------------+

The Trade-Offs

When working through the The Trade-Offs stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline. Log tool name, args hash, latency, and outcome for every call. Debugging agent loops without that trail wastes hours.

The Most Important Conceptual Shift

When working through the The Most Important Conceptual stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion. Log tool name, args hash, latency, and outcome for every call. Debugging agent loops without that trail wastes hours. When working through the The Most Important Conceptual stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

Final Thoughts

The Final Thoughts stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish. Expose tools with narrow schemas and explicit side-effect labels. Hosts need to know which calls mutate state before they auto-approve.

sticky sessions
      +
shared session store
      +
long-lived connections
      +
connection affinity
stateless request handling
      +
ordinary load balancing
      +
external durable state
      +
explicit handles
      +
asynchronous task primitives

Operational checklist

When working through the Operational checklist stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest.

Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments.

Log tool name, args hash, latency, and outcome for every call. Debugging agent loops without that trail wastes hours.

Pin dependency versions and record the image digest that ran the demo. Reproducibility beats tribal knowledge.

Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

Log tool name, args hash, latency, and outcome for every call. Debugging agent loops without that trail wastes hours.

Before promoting the stack, freeze versions, capture a golden transcript for the critical path, and confirm rollback steps. Shared environments need rate limits, tenancy checks, and a clear owner for secret rotation. Prefer boring reliability over clever one-off demos.

Batch note for 6d88094bc74f: keep provider keys out of the repo, set a per-session token ceiling, and store transcripts next to the eval fixtures so later model swaps stay comparable.

When working through the hardening note 0 stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Hardening detail 0/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

The hardening note 1 stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

Hardening detail 1/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

For the hardening note 2 stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline.

Hardening detail 2/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

When working through the hardening note 3 stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments.

Hardening detail 3/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

The hardening note 4 stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish.

Hardening detail 4/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

For the hardening note 5 stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Hardening detail 5/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

When working through the hardening note 6 stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

Hardening detail 6/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

The hardening note 7 stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline.

Hardening detail 7/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

For the hardening note 8 stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments.

Hardening detail 8/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

When working through the hardening note 9 stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish.

Hardening detail 9/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

The hardening note 10 stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Hardening detail 10/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

For the hardening note 11 stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

Hardening detail 11/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

When working through the hardening note 12 stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline.

Hardening detail 12/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

The hardening note 13 stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments.

Hardening detail 13/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

For the hardening note 14 stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish.

Hardening detail 14/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

When working through the hardening note 15 stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Hardening detail 15/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

The hardening note 16 stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

Hardening detail 16/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

For the hardening note 17 stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Prefer small, testable units over sprawling scripts. When a step fails, the failure should point at a single responsibility rather than a tangled pipeline.

Hardening detail 17/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

When working through the hardening note 18 stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Record timings and token or query cost next to functional results. Cost visibility early prevents surprise bills when the path moves from demo to shared environments.

Hardening detail 18/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

The hardening note 19 stage works best when treated as a measurable surface. Capture one golden transcript, one failure case, and the rollback note before expanding scope. Document the happy path and the recovery path together. Retries, human gates, and dead-letter handling are part of the product, not later polish.

Hardening detail 19/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

For the hardening note 20 stage, define the inputs, the owner of the step, and the exit criteria before changing code. Operators should be able to re-run the step from a known checkpoint without guessing hidden state. Treat this stage as a contract between inputs and validated outputs. Name the artifacts, define success checks, and refuse silent partial completion.

Hardening detail 20/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.

When working through the hardening note 21 stage, write down the contract first: required inputs, success signal, and what happens on partial failure. That checklist keeps later code changes honest. Keep configuration outside application code. Environment files, secret stores, and feature flags belong in one place operators can audit without reading the whole graph.

Hardening detail 21/829: measure wall time, error class, and token spend for this note, then decide whether to keep the change based on a fixed question set rather than anecdote.