MCP 2026-07-28 Goes Stateless: An AI Agent Integration Buyer Guide

On 28 July 2026, the Model Context Protocol working group published spec revision 2026-07-28 on modelcontextprotocol.io: Streamable HTTP as the primary stateless transport, deprecation of the SSE-only transport, OAuth 2.1 alignment, and capability stabilisation. A six-point buyer framework for an MCP-based, model-agnostic AI agent architecture on nearshore Morocco delivery.

CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai

MCP 2026-07-28 Goes Stateless: An AI Agent Integration Buyer Guide

On 28 July 2026, the Model Context Protocol working group published spec revision 2026-07-28 on modelcontextprotocol.io: Streamable HTTP as the primary stateless transport, deprecation of the SSE-only transport, OAuth 2.1 alignment, and capability stabilisation. A six-point buyer framework for an MCP-based, model-agnostic AI agent architecture on nearshore Morocco delivery.

Questions Fréquemment Posées

What did the MCP 2026-07-28 spec revision change?

The Model Context Protocol working group published spec revision 2026-07-28 on modelcontextprotocol.io and mirrored it to the reference server and client SDKs on github.com/modelcontextprotocol. Three material changes: Streamable HTTP is consolidated as the primary stateless transport for MCP servers, with Server-Sent Events used for streaming responses; the older SSE-only stateful transport is deprecated on the standard timeline; the authorisation model is tightened around OAuth 2.1, including discovery of the authorisation server from MCP server metadata; and a set of governance capabilities (tool listings, prompts, elicitation, resource templates) move from experimental to stable.

Do existing MCP servers need migration?

Servers built against the earlier stateful SSE transport need migration to the Streamable HTTP transport on the deprecation timeline set in the 2026-07-28 spec. Integrations built around pre-stable capability shapes (tool listings, prompts, elicitation, resource templates) need review against the stabilised definitions. A serious integrator scopes both migrations explicitly rather than leaving them to be discovered in production later. Both migrations are typically executable in weeks per server rather than months, but the schedule needs to be planned before the deprecation window closes.

Why should a mid-market buyer care about MCP right now?

Because MCP is the closest thing the 2026 AI-agent space has to a portable, cross-vendor integration standard. An MCP layer beneath a model-agnostic client keeps the buyer's integration surface (CRM, ERP, knowledge base, internal APIs, standard SaaS) portable across model and orchestration choices rather than locking it inside a single vendor's agent stack. That is the buyer-side architectural leverage that lets the mid-market avoid a rent-forever contract on a single-vendor agent platform while still consuming vendor MCP servers where they add value.

Is MCP a substitute for OpenAI Presence, Microsoft Frontier or a hosted agent platform?

No. MCP is the integration layer beneath any of those platforms, not an alternative to them. Choosing MCP is a decision about the integration surface. Choosing a hosted agent platform (OpenAI Presence, Microsoft Frontier, Google Vertex Agents, or another vendor product) is a decision about the orchestration and model layer above it. A buyer can adopt MCP without renouncing a hosted platform, and often should. The relevant framing is that MCP lets the buyer keep the integration surface portable even when the orchestration layer above it is a vendor product.

What is the six-point MCP buyer framework?

One, spec-version discipline — target 2026-07-28 for new builds and budget quarterly compatibility review. Two, transport choice explicit in contracts — Streamable HTTP for every server, with a written migration commitment for any vendor server still on the deprecated SSE-only transport. Three, authorisation aligned with the enterprise identity provider through OAuth 2.1 per the 2026-07-28 clarifications, with per-user per-scope tokens rather than static API keys. Four, buyer-owned integration surface with a model-agnostic client layer, so the model selection remains a run-time or contract-time decision. Five, sandboxing, per-tool rate limits, cost caps and human-in-the-loop on write actions above a defined blast-radius threshold. Six, portability and exit posture negotiated at contract time for every vendor-provided MCP server.

What is the biggest MCP integration risk?

Prompt-injection-induced misuse of tool-calling on MCP servers that expose write actions. MCP standardises the transport and the shape of tool definitions, not the semantics of the model's tool-selection behaviour. The compensating controls are sandboxing on the server's filesystem and network capabilities, per-tool rate limits and cost caps, adversarial evaluation of the tool-selection surface, and explicit human-in-the-loop confirmation for write actions above a defined blast-radius threshold (financial transactions, production data mutation, external communication). These remain buyer responsibilities regardless of which MCP spec revision the servers target.

How does Call IT Dev deliver a model-agnostic MCP build from Morocco?

Call IT Dev operates software development, AI-automation and dedicated development team engagements from Morocco with nearshore EU-time-zone overlap, multilingual delivery in English, French, Spanish and Arabic, and a regulatory posture aligned with CNDP Law 09-08 and GDPR obligations. A representative programme deploys named engineers on the 2026-07-28 spec: three to five buyer-owned MCP servers on Streamable HTTP with OAuth 2.1 authorisation, a model-agnostic client integration across OpenAI, Anthropic, Google, Mistral and self-hosted open-weight models, sandboxing and human-in-the-loop on write actions, and an evaluation harness the buyer owns end-to-end. A typical scoped pilot runs six to ten weeks, followed by a production hardening phase and a steady-state operating model with the buyer holding all artefacts.

CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai — contact@callitdev.com — +212-537-373777