MCP's 2026-07-28 revision deletes the initialize handshake and Mcp-Session-Id, so a server must answer each request from what arrives with it. A developer who rebuilt the spec against 708 tests wrote one test whose only job is proving no state leaks between server instances.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence60
MCP servers that skip audience binding accept tokens minted for other servers, says a dev.to OAuth 2.1 guide that puts it in the 80% most guides skip. The check depends on RFC 9728 metadata the server publishes and a resource parameter the client sends.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence35
The MCP spec mandates OAuth 2.1 with PKCE, dynamic client registration and metadata discovery for remote servers. The one-hour tokens and customer-facing audit logs procurement asks about come from a guide's own bar.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence48
Developer clients reach a key-protected Azure Functions MCP server by attaching a header; the Claude desktop app has no such field, and the one-click fix still left VS Code holding an invalid_target error from Entra.
Reality
- Evidence54
- Adoption21
- Hype gap−9
- Incentives27
- Confidence56
The GA release registers KAGENT_STS_RESOURCE and KAGENT_STS_AUDIENCE with descriptions that name the RFC, then defaults both to empty, and whether that default is an exposure depends on what your own STS hands back.
Reality
- Evidence68
- Adoption22
- Hype gap+12
- Incentives35
- Confidence60
A dev.to writeup documents Amazon Cognito killing a spec-compliant MCP connector at the first redirect, and the only fix on offer is a proxy that strips one parameter and nothing else.
Reality
- Evidence46
- Adoption18
- Hype gap−6
- Incentives30
- Confidence44