<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/the-new-mcp-roadmap-1oklafl87" -->

---
title: The New MCP Roadmap | daily.dev
description: The Model Context Protocol project published an updated roadmap outlining five priority areas for the specification: agentic messaging primitives...
canonical: https://daily.dev/posts/the-new-mcp-roadmap-1oklafl87
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: The New MCP Roadmap | daily.dev
og:description: The Model Context Protocol project published an updated roadmap outlining five priority areas for the specification: agentic messaging primitives...
og:url: https://daily.dev/posts/the-new-mcp-roadmap-1oklafl87
og:image: https://api.daily.dev/og/posts/1OKlaFL87.png
og:image:alt: The New MCP Roadmap
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# The New MCP Roadmap

**[Model Context Protocol](https://daily.dev/sources/modelcontextprotocol-blog)** · 7 min read · 18 upvotes · 3 comments

## Summary

The Model Context Protocol project published an updated roadmap outlining five priority areas for the specification: agentic messaging primitives (server-initiated events, maturing the Tasks extension), HTTP-native transport unification across local and remote servers, agent identity and enterprise security (DPoP, Workload Identity Federation, token exchange), improved result-handling primitives and progressive tool discovery, and better SDK developer experience. The previous roadmap's four priorities (transport evolution, agent communication, governance maturation, enterprise readiness) saw major changes land in the 2026-07-28 spec release, including removal of protocol-level sessions/handshake, a new server/discover call, cacheable list results, the Multi Round-Trip Requests pattern replacing server-initiated requests, a formal Contributor Ladder, and new authorization mechanisms like issuer-bound client credentials and Client ID Metadata Documents.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://blog.modelcontextprotocol.io/posts/mcp-roadmap>

## Questions this post answers

### What changed in the MCP 2026-07-28 specification release regarding sessions?

Protocol-level sessions and the initialization handshake were removed from the Model Context Protocol specification in the 2026-07-28 release, per SEP-2575 and SEP-2567. This allows a server to scale horizontally without holding state. Clients can now call server/discover to learn a server's supported versions and capabilities upfront, and list results are cacheable per SEP-2549.

_Track MCP spec changes like this on daily.dev before they break your server integration._

### How does MCP handle server-initiated requests like elicitation now that sessions are gone?

The Multi Round-Trip Requests (MRTR) pattern, defined in SEP-2322, replaced server-initiated requests so that flows like elicitation work on stateless servers. This was introduced alongside the removal of protocol-level sessions in the 2026-07-28 specification release, and it works together with Tasks, which were moved into an official extension under SEP-2663.

_Developers adopting MCP's agentic patterns can follow spec updates like this via daily.dev._

### What authorization improvements did MCP add for enterprise security?

MCP's 2026-07-28 release added issuer validation, issuer-bound client credentials, and Client ID Metadata Documents (CIMD) as the preferred client registration path. Enterprise-Managed Authorization, which relies on an ID-JAG grant, is now available as a stable extension. Future work targets Demonstrating Proof of Possession (DPoP) and Workload Identity Federation for agent identity.

_Teams securing agent-to-server auth can keep up with MCP's authorization roadmap on daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@agustinbarrientos** · 3 upvotes

> The transport work should ship with conformance fixtures for proxies, retries, connection loss, and recovery across every SDK

**@micahnorwoodjordan** · 2 upvotes

> not sure why, but reading this made me finally decide to contribute to open source projects, starting with modelcontextprotocol

---

Tags: [#open-source](https://daily.dev/tags/open-source), [#architecture](https://daily.dev/tags/architecture), [#mcp](https://daily.dev/tags/mcp), [#oauth](https://daily.dev/tags/oauth), [#agentic-ai](https://daily.dev/tags/agentic-ai)

[View this post on daily.dev](https://daily.dev/posts/the-new-mcp-roadmap-1oklafl87)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"The New MCP Roadmap","url":"https://daily.dev/posts/the-new-mcp-roadmap-1oklafl87","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/the-new-mcp-roadmap-1oklafl87"},"datePublished":"2026-08-23T12:17:00.461Z","dateModified":"2026-08-23T12:20:00.833Z","description":"The Model Context Protocol project published an updated roadmap outlining five priority areas for the specification: agentic messaging primitives...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ccad778d24e1fca3aa1c66575a7bfbf3?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ccad778d24e1fca3aa1c66575a7bfbf3?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Model Context Protocol","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Model Context Protocol","logo":"https://media.daily.dev/image/upload/s--ORAgfri4--/f_auto,q_auto/v1787487408/logos/modelcontextprotocol-blog?_a=BAMAMicg0","url":"https://daily.dev/sources/modelcontextprotocol-blog"},"commentCount":3,"discussionUrl":"https://daily.dev/posts/the-new-mcp-roadmap-1oklafl87","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":18},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":3}],"keywords":"open-source,architecture,mcp,oauth,agentic-ai","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Model Context Protocol","item":"https://daily.dev/sources/modelcontextprotocol-blog"},{"@type":"ListItem","position":3,"name":"The New MCP Roadmap"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/the-new-mcp-roadmap-1oklafl87","comment":[{"@type":"Comment","text":"The transport work should ship with conformance fixtures for proxies, retries, connection loss, and recovery across every SDK","datePublished":"2026-08-26T07:41:36.964Z","url":"https://daily.dev/posts/1OKlaFL87#c-MykpxMZoV","author":{"@type":"Person","name":"Agustin Barrientos","url":"https://daily.dev/agustinbarrientos","image":"https://media.daily.dev/image/upload/s--5ayxQnqn--/f_auto/v1788281802/avatars/avatar_wQYYVe5Tbj0NJ7C7qPoa8?_a=BAMAMicg0"},"interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":3}},{"@type":"Comment","text":"not sure why, but reading this made me finally decide to contribute to open source projects, starting with modelcontextprotocol","datePublished":"2026-08-26T00:33:20.735Z","url":"https://daily.dev/posts/1OKlaFL87#c-ADll0iFYG","author":{"@type":"Person","name":"Micah Norwood","url":"https://daily.dev/micahnorwoodjordan","image":"https://media.daily.dev/image/upload/s--F7AsERgm--/f_auto/v1744468090/avatars/avatar_RkUh6L39HXCnFFgzyIq88"},"interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/the-new-mcp-roadmap-1oklafl87#faq","mainEntity":[{"@type":"Question","name":"What changed in the MCP 2026-07-28 specification release regarding sessions?","acceptedAnswer":{"@type":"Answer","text":"Protocol-level sessions and the initialization handshake were removed from the Model Context Protocol specification in the 2026-07-28 release, per SEP-2575 and SEP-2567. This allows a server to scale horizontally without holding state. Clients can now call server/discover to learn a server's supported versions and capabilities upfront, and list results are cacheable per SEP-2549. Track MCP spec changes like this on daily.dev before they break your server integration."}},{"@type":"Question","name":"How does MCP handle server-initiated requests like elicitation now that sessions are gone?","acceptedAnswer":{"@type":"Answer","text":"The Multi Round-Trip Requests (MRTR) pattern, defined in SEP-2322, replaced server-initiated requests so that flows like elicitation work on stateless servers. This was introduced alongside the removal of protocol-level sessions in the 2026-07-28 specification release, and it works together with Tasks, which were moved into an official extension under SEP-2663. Developers adopting MCP's agentic patterns can follow spec updates like this via daily.dev."}},{"@type":"Question","name":"What authorization improvements did MCP add for enterprise security?","acceptedAnswer":{"@type":"Answer","text":"MCP's 2026-07-28 release added issuer validation, issuer-bound client credentials, and Client ID Metadata Documents (CIMD) as the preferred client registration path. Enterprise-Managed Authorization, which relies on an ID-JAG grant, is now available as a stable extension. Future work targets Demonstrating Proof of Possession (DPoP) and Workload Identity Federation for agent identity. Teams securing agent-to-server auth can keep up with MCP's authorization roadmap on daily.dev."}}]}
```

