TL;DR: MCP 2026-07-28 removes protocol sessions, drops the initialization handshake, and hardens authorization with OAuth 2.1, Resource Indicators, issuer verification, and new extension handling, according to WorkOS. The shift makes AI agent authentication more enterprise-ready, but it also exposes hidden session dependencies and confused-deputy risks that many MCP deployments were not built to absorb.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “The biggest MCP spec update ships July 28: What changes for AI agent authentication”.
Key questions
Q: What breaks when MCP sessions are removed from the access model?
A: Session-based accountability breaks first, because the conversation no longer carries purpose, ownership, or task continuity.
Q: Why do Resource Indicators matter for MCP authorization?
A: Resource Indicators matter because they bind a token request to a specific MCP server, which reduces confused-deputy risk and token replay across different resources.
Q: What are the main failure modes teams need to watch during the MCP 2026-07-28 migration?
A: The biggest failure modes are unremoved session dependencies, weak issuer validation, and clients that still assume the old handshake or registration flow.
Practitioner guidance
- Map every hidden session dependency Inventory any place your MCP implementation still depends on sticky routing, session IDs, or server affinity, then replace those assumptions with explicit state handles carried as normal tool arguments.
- Enforce resource-scoped authorization Require Resource Indicators, Protected Resource Metadata, and issuer verification so each token is bound to the specific MCP server it was intended for.
- Rework client registration flows Migrate away from Dynamic Client Registration where possible and adopt Client ID Metadata Documents so registration is aligned with the new spec model.
Bottom line: MCP 2026-07-28 shifts agent authentication away from sticky sessions and toward request-scoped authorization, which changes where trust is established.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Stateless protocol design is not just an engineering cleanup. It is an identity-governance reset. MCP's removal of protocol sessions collapses the assumption that identity can be tracked through a sticky conversation and then certified later. That assumption was built for stateful connections, not request-scoped authorization. The implication is that teams must reassess where identity actually lives in the transaction, because the protocol no longer carries it for them.
A few things that frame the scale:
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: How should security teams govern MCP async task handles in production?
A: Security teams should treat MCP task handles as sensitive, scoped capabilities tied to the original user, tenant, or API client. Every follow-up call should be checked against that same authorization context, with short TTLs, clear cancellation rules, and audit logs that preserve the full task lifecycle from creation to terminal state.
👉 Read our full editorial: MCP 2026-07-28 rewrites AI agent authentication and sessions