we_are_coded.by CODE · The world, decoded
БГ
Model Context Protocol

The protocol for AI tools threw out the session - and that cuts the cost of running your own server

MCPBuilders

The new Model Context Protocol specification drops the handshake and the session ID - every request now carries everything it needs on its own. Cloudflare shipped its implementation on 6 August. Three of the old capabilities enter a 12-month corridor before removal.

In short
  • The specification is dated 28 July and belongs to the MCP project under the Linux Foundation, not to Cloudflare. Its official name is the date, not 'version 2'.
  • The handshake and the session ID are gone. Mandatory headers appear, letting a firewall route and measure traffic without opening the content.
  • Roots, Sampling and Logging are marked deprecated but still work. For the first time there is a written rule: a minimum of 12 months before removal.
Checked on7 August 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

The mechanics are simple. The consequence is big. Until now, the server feeding tools to an AI agent remembered who it was talking to - a handshake at the start, a session number on every request after that. Which means it couldn't just be cloned behind a load balancer, because someone had to hold the state. The new specification removes exactly that.

The facts: the revision is dated 28 July 2026 and is published by the Model Context Protocol project, which lives under the Linux Foundation; the lead maintainers are David Soria Parra and Den Delimarsky. On 6 August, Cloudflare announced it supports the new specification across its agent stack, and that its endpoint accepts both the new and the old way of talking. The protocol drops the initial handshake and the session ID header; every request now carries the client's version and capabilities on its own. A mandatory call is introduced, through which the server declares what it supports. Headers naming the method and the tool become mandatory, so a gateway or firewall can route and count traffic without unpacking the content. Tool and resource lists now carry a cache lifetime and a scope - public or private. Roots, Sampling and Logging are marked deprecated, along with the old server-sent-events transport and dynamic client registration. For the first time there is a written policy: active, deprecated and removed states, with a minimum of 12 months between the last two.

Two things here we'll see play out fast. The first is cost - a server with no session memory can run on cheap infrastructure and scale by copies, with no shared storage underneath. The second is control: once the method name sits in the header, rate limiting, logging and caching happen at the edge, not somewhere deep in the application. That's exactly where security is cheap.

The spec belongs to the project, not to Cloudflare. Cloudflare is just the first to ship it in a product.

And one word about the name, because I've already seen it get muddled. Cloudflare's post URL contains "mcp-v2", but neither the specification nor the text talks about a second version. Protocol revisions are named by their date. It's a small thing, but exactly this kind of small thing is how arguments over who announced what get started.

The 12 months are the only firm planning signal in this whole story. Anything you've tied to dynamic client registration, to Roots, Sampling or Logging now carries an expiry date and belongs on the task list. It's not urgent today. But it has a date.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→MCP - the 2026-07-28 specification→MCP - changelog→Cloudflare - The next generation of MCP
Original: https://wearecoded.com/en/articles/mcp-specifikaciya-bez-sesiya.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news