MCP Release 2026-07-28: What Changes, What Breaks, and What You Need to Do About It
The 2026-07-28 spec is the largest change to MCP since launch, and it carries breaking changes: the session handshake is removed, servers have to become formal OAuth 2.1 resource servers, extensions become first-class, and features like Sampling and Roots are now deprecated. Some of these change session-based architectures the day the spec lands; others put you on a 12-month migration clock. They also force new strategic and tactical shifts. For example, how you re-architect authorization once bring-your-own-token stops working is a tactical call every team has to get right, and whether you run both protocol versions yourself or put a runtime in front is the strategic one that shapes the rest.
In 30 minutes this webinar will cover:
- What's actually changing across the protocol core, authorization, extensions, and deprecations
- Why it matters, and which changes are urgent versus which you can stage
- The tactical and strategic shifts your team needs to make to stay ahead of the migration
- Demos and your questions answered live during Q&A
Register to join the webinar live and get the recording afterward.
What we'll cover
In 30 minutes, Mateo Torres walks through what the 2026-07-28 MCP spec changes, what breaks, and what your team needs to do about it:
- What's actually changing — the removed session handshake, servers as formal OAuth 2.1 resource servers, first-class extensions, and deprecated Sampling & Roots
- Which changes are urgent versus which you can stage — and the 12-month migration clock this release starts
- The tactical and strategic calls: re-architecting authorization once bring-your-own-token stops working, and whether to run both protocol versions or put a runtime in front