Build1 publisher3 min readPublished
MCP's roadmap fast-tracks five priorities and quietly queues everything else
Five named priorities now decide which specification proposals get read first, which makes the August roadmap a resource-allocation call for anyone building unattended agents.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Soria Parra and Delimarsky published an updated MCP roadmap on August 22nd naming five priority areas, among them machine identity and transport consolidation.
- Specification Enhancement Proposals that match those priorities get expedited review; the rest face a longer queue and a higher bar.
- The first priority pulls Tasks, subscriptions and progress notifications into one lifecycle and adds server-initiated webhooks and channels in place of polling.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Anyone running a polling loop against MCP servers now chooses between waiting on a lifecycle with no committed date and shipping a mechanism the core specification will later supersede.
- constraint Agent designs that none of the five priorities describe cannot buy maintainer attention on merit alone; they have to clear a bar the aligned proposals do not.
- exposure Until machine identity is standardized, every operator running unattended or sub-delegating agents scopes those permissions in its own code, differently per vendor, and owns the failures.
- capability One transport across remote and local deployment would let a team test a single set of server behaviors instead of two, making the local and hosted server the same artifact.
Nine months separate the two documents that define this protocol. Anthropic released MCP as an open-source standard on November 25th, 2024 [6], and the roadmap carries an August 22nd date [1], about nine months later [17]. The problem it was originally built for was one person copying information between Claude Desktop, which could render artifacts, and a development environment that could see his code, generalized into the M-by-N integration problem [16]. The problem it is being rebuilt for is a job that outlives the exchange that started it, may need new instructions midway, and may produce a server-generated result after the original request has closed [14].
The roadmap covers the next specification release and the six to twelve months after it, and offers direction rather than firm delivery dates [2]. That absence is what turns the expedited-review lane into scheduling information: the list of five is the only ordering anyone gets.
Transport consolidation is the priority most likely to read as housekeeping and least likely to be free. The July 28th revision already removed protocol-level sessions and made remote MCP servers behave more like ordinary stateless HTTP services, according to RuntimeWire's earlier reporting [8]. The roadmap extends that HTTP-native model to other deployment modes, including local servers speaking Streamable HTTP over stdio [9]. Note where the stated benefit lands: simpler server and client development, and fewer behaviors for developers to implement and test [10]. Local stdio is the case where HTTP semantics do the least work at runtime, so the payoff shows up in SDKs and test matrices while the migration cost shows up in every existing local server.
The boundary with agent-to-agent work is where the framing and the content pull apart. Google describes its Agent2Agent protocol as complementary, with A2A handling collaboration between agents and MCP connecting agents to tools and context [7]. That division still describes intent. It no longer describes feature sets, because MCP now needs many of the same operational properties, including long-running tasks, streaming updates and asynchronous state changes [15].
Identity is the area where current behavior sits furthest from the target. The existing authorization flow assumes a person is available to approve access in a browser [11], while cloud agents may run with no active user at all, act on a user's behalf, or create sub-agents that should hold narrower permissions than the parent process [12]. It is also the one area with a publicly named owner: Delimarsky, who worked on security and authorization at Microsoft before joining Anthropic, is among the maintainers assigned to it, and the roadmap calls for standardized agent identity [13].
For anyone already running a server against clients including Claude, ChatGPT, Visual Studio Code and Cursor [5], the practical reading is not technical. Read as engineering, the document is a set of intentions. Read as scheduling, it names the five agent architectures the protocol expects to support within a year, and leaves the rest to integrators' own code for at least that long.
What to watch
- Whether the Tasks extension actually lands in the core specification at the next release or stays an extension for another cycle.
- Whether the standardized agent identity work covers sub-agent delegation with narrower scopes, or only unattended service credentials.
- Whether any off-roadmap Specification Enhancement Proposal clears the higher bar, which would show the fast lane is a preference rather than a gate.