Skip to content

Build1 publisher3 min readPublished

MCP's September 28 release lets any server behind a load balancer answer any request

Agentic AI Foundation's September 28 MCP release finalizes stateless servers and bars removing deprecated features before July 2027. Teams moving servers off sessions now have a dated floor to plan migrations against.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying MCP's September 28 release lets any server behind a load balancer answer any request
Generated illustration

What happened

  • The release makes validation of the OAuth issuer parameter mandatory, closing a class of mix-up attacks with no known exploitation, according to Den Delimarsky.
  • Enterprise Managed Authorization, built with Okta, makes a company's identity provider the authoritative gatekeeper for MCP server access, using corporate credentials.
  • MCP Apps, server-rendered interfaces inside AI clients, and MCP Tasks, durable task handles that survive disconnects, crashes and restarts, are now official extensions.
  • The Agentic AI Foundation grew from about 40 members in December 2025 to 240, and Anthropic's share of contributions fell below half.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • contradiction Soria Parra called the 12-month window "more of a feedback period than a definite period", so July 2027 is only the earliest date a deprecated feature can go and the actual removal date stays open.
  • exposure With the corporate identity provider as gatekeeper, an identity team's policy now decides which agents reach which MCP servers.
  • cost At the post's example price of 0.001 USDC a call, a million-call day of the kind the post says statelessness makes cheap would bill 1,000 USDC, 20 times its example daily budget.

The only source for this account is a dev.to post summarizing a September 28 VentureBeat exclusive, which interviewed David Soria Parra, Den Delimarsky and Mazin Gilbert [20]. In that summary, statelessness means no protocol-level session, no sticky routing and no shared session store [3]. The post quotes the goal as "Your MCP client can speak to a load balancer that connects with any server." [4]

The wire changes came earlier. The 2026-07-28 spec revision removed the `initialize` handshake and `Mcp-Session-Id` [5]. The September 28 release finalizes that work, and co-creator David Soria Parra said "some people jokingly call it a v2, and I think in spirit that's accurate." [2]

The features deprecated in that revision are Roots, Sampling, Logging and Dynamic Client Registration [10]. The post's migration checklist runs in order:

1. Grep for `initialize`, `Mcp-Session-Id` and anything keyed to a connection [14]. 2. Replace the capability exchange with `server/discover` [14]. 3. Carry the protocol version and capabilities in each request's `_meta` [14]. 4. Make cross-call state explicit by minting handles such as draft IDs, job IDs and receipt IDs, passed as tool arguments [15].

The post lists the costs. State rides the wire, so payloads get bigger [12]. Out-of-band server logging is gone in the stateless model [12]. According to the post, the team scraped all of GitHub and found "basically nobody" used it [13]. I think this is the right tradeoff for a fleet behind a load balancer. Extra bytes per request pay for dropping the session store and sticky routing [3][12].

Per-call pricing is not among the release items the post lists [1]. The cost argument is the post author's, and it is conditional: where tool calls are billed per call, each one becomes a payment decision [16]. The author proposes auto-executing at a score of 0.80 and above, holding between 0.50 and 0.79, and blocking below 0.50 [16].

The author scored two cases on a gate whose decider is labelled `local-heuristic-v1`, `calibrated=false` [17]. A single paid x402 tool at 0.001 USDC a call, with 4.20 USDC of a 50 USDC daily budget spent, scored 0.6457 and was held [17]. That spend is 4,200 calls [1]. The same surface with no spending cap, no per-call authorization and no audit record scored 0.7964, also a hold [18].

Removing those three controls raised the score by 0.1507 [5]. A spending gate that warms to uncapped spend has its sign backwards. The uncapped case landed 0.0036 short of the auto-execute line [4]. For these scores to say anything about another team's servers, the decider would need calibrating against that team's prices and its cost of a wrong call. Its own label says it has not been calibrated [17].

What to watch

  • The published spec text for the September 28 release, to check the dev.to account of issuer validation and the July 2027 floor against primary documents.
  • Whether the foundation removes Roots, Sampling, Logging and Dynamic Client Registration at the July 2027 floor or extends the window.
  • A calibrated version of the author's decider, and whether removing spending caps still raises its score.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories