Dev.to AI πŸ€– Ai πŸ‘ 0 πŸ“– 4 min read

What Is the New MCP Update? September 2026's Biggest-Ever Release, With Receipts

What Is the New MCP Update? September 2026's Biggest-Ever Release, With Receipts The short answer: on September 28, 2026, the Agentic AI Foundation (a Linux Foundation directed fund) shipped the biggest release in MCP'

What Is the New MCP Update? September 2026's Biggest-Ever Release, With Receipts

The short answer: on September 28, 2026, the Agentic AI Foundation (a Linux Foundation directed fund) shipped the biggest release in MCP's history β€” finalized stateless architecture, hardened OAuth authorization, a formal 12-month deprecation policy, and MCP Apps + MCP Tasks graduated to official extensions. Co-creator David Soria Parra said "some people jokingly call it a v2, and I think in spirit that's accurate."

The part nobody is saying: statelessness makes million-tool-call-per-day MCP server farms cheap to run β€” and where tool calls are billed per call, every single one becomes a payment decision.

The distinction the field doesn't make

Search "MCP update" today and you'll get July stories: Medium's migration map, hackernoon's deprecation read, Nordic APIs. All cover the 2026-07-28 spec revision β€” the removal of the initialize handshake and Mcp-Session-Id. The Sept-28 release is a different release: the enterprise finalization of that same long arc.

The receipts: dated, sourced

  • Sept 28, 2026 (VentureBeat exclusive): "the largest update since Anthropic released it twenty months ago" β€” "finally makes agentic AI ready for massive enterprise production deployments." Interviews with Soria Parra, Den Delimarsky, Mazin Gilbert.
  • Stateless, finalized: no protocol-level session, no sticky routing, no shared session store. "Your MCP client can speak to a load balancer that connects with any server." Tens of thousands of agents per deployment now architecturally possible.
  • Auth hardening: mandatory validation of the OAuth issuer (iss) parameter β€” closes an entire class of mix-up attacks. Delimarsky explicitly: no known exploitation β€” "preventive engineering, not incident response."
  • Enterprise Managed Authorization (built with Okta): corporate IdP becomes the authoritative gatekeeper for MCP server access β€” corporate credentials, not personal ones.
  • Apps + Tasks graduated: MCP Apps (server-rendered interactive UIs inside AI clients) and MCP Tasks (durable task handles β€” disconnect, crash, restart, resume polling) are now official extensions. Plus multi-round-trip requests.
  • Governance: AAIF went from ~40 members (Dec 2025) to 240 β€” the fastest-growing foundation in Linux Foundation history. Anthropic's contribution share fell below half.
  • 12-month deprecation policy: nothing in the 2026-07-28 cohort (Roots, Sampling, Logging, Dynamic Client Registration) can be removed before July 2027. "It's more of a feedback period than a definite period" (Soria Parra).
  • The honest costs: bigger payloads (state rides the wire); out-of-band server logging is gone in the stateless model β€” the team scraped all of GitHub and "basically nobody" used it. "Probably a handful of people β€” quite literally a handful of people."

Why this makes the payment gate MORE important, not less

Three connections, none forced:

  1. Enterprise Managed Authorization is identity-side gating, standardized. The protocol shipped corporate-IdP-as-gatekeeper as an extension. That's the authorization instinct made official β€” now it needs the judgment layer behind it: not just who may call, but whether this particular call should fire.
  2. Stateless scale multiplies paid tool calls. Any request landing on any instance behind a load balancer is exactly the shape of per-call-billed agent infrastructure. At a million calls a day, each call wants a scored decision β€” β‰₯0.80 auto-execute, 0.50–0.79 hold, <0.50 block β€” not a blanket credential.
  3. Apps + Tasks are where the money will hide. A server-rendered "Pay now" form and a resumable paid job are both payment decisions inside the protocol. The multi-round-trip request shape is the wire-level space where a confirm band (0.50–0.79) lives between negotiation and execution.

Live this morning: the gate scores paid MCP tool calls

Our confidence gate (decider local-heuristic-v1, calibrated=false), scored ~09:20 EDT Sept 28:

  • Receipt 1 β€” single paid tool call, in budget: 0.6457 β†’ ADVISORY (hold). One paid x402 MCP tool (0.001 USDC/call, 4.20 of a 50 USDC daily budget spent). Even the routine case doesn't auto-execute without a wired, calibrated decider.
  • Receipt 2 β€” uncapped bulk paid calls: 0.7964 β†’ ADVISORY (hold). Same surface, no spending cap, no per-call authorization, no audit record β€” just under the 0.80 auto-act line. Stateless scale doesn't buy a free pass; it buys scrutiny.

Do it yourself: 5 steps, this week

  1. Find your stateful assumptions: grep for initialize, Mcp-Session-Id, anything keyed to a connection. Replace capability exchange with server/discover, carry protocol version and capabilities in per-request _meta.
  2. Make cross-call state explicit: mint handles (draft IDs, job IDs, receipt IDs) as ordinary tool arguments. Expiring, ownable, log-searchable.
  3. Put yourself on the 12-month clock: Roots β†’ tool parameters/resource URIs; Sampling β†’ direct LLM calls; protocol logging β†’ stderr/OpenTelemetry; DCR β†’ explicit OAuth registration. Earliest removal: July 2027.
  4. Adopt Enterprise Managed Authorization for anything paid or corporate β€” wire it before your auditors ask.
  5. Gate every paid tool call with a scored decision. At stateless scale there is no per-request human; the score is the human.

Honest caveats

  • The release details come from a single outlet's exclusive (VentureBeat, Sept 28, 2026) β€” interviews, not a second independently verified source.
  • The "July vs today" distinction is my framing from the community migration field and the VentureBeat piece β€” no canonical release-notes delta from the protocol team yet.
  • Gate receipts are from a local-heuristic-v1 decider (calibrated=false) β€” an honest demo of the pattern, not a calibrated production score.
  • Enterprise Managed Authorization is an extension, not core spec β€” adoption is ecosystem-dependent.

Full writeup with the claim-receipts table, the live curl commands, and the complete migration checklist:

Canonical version with live receipts: https://scriptmasterlabs.com/mcp-biggest-update-september-2026

πŸ“° Read the original article on Dev.to AI

Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.