Quick summary

  • The MCP 2026-07-28 specification removes the initialize handshake and Mcp-Session-Id, carrying protocol and client context on each request.
  • Teams can remove protocol-specific sticky sessions and session stores while keeping business state explicit through identifiers.
  • Inventory sticky routing and session stores, make tools idempotent, then canary the MCP 2026-07-28 protocol with compatibility monitoring.

What happened

Stateless at the protocol layer

The July 28, 2026 MCP revision makes the protocol core stateless. The initialize handshake and Mcp-Session-Id header are no longer required; each request carries the protocol version and client context it needs. A client’s first message can therefore be a real tool call handled by any instance behind a load balancer instead of returning to the server that created a session.

AWS stresses that stateless protocol does not mean stateless application. When a tool needs continuity, the server stores data in a datastore and returns an identifier. The model supplies that identifier as a later tool argument. State becomes explicit, observable, and closer to ordinary REST discipline instead of being hidden in a transport header.

Deployment consequences

Existing stacks can retire ALB stickiness and protocol-only session stores, use round-robin routing, and treat Lambda as a natural request-in, response-out target. The server/discover method exposes versions, capabilities, and identity. The ttlMs and cacheScope fields support tool-list caching, while W3C Trace Context and OpenTelemetry provide a standard observability path. Recovery shifts toward idempotent tools that clients can safely retry.

Migration still has security constraints. A public cacheScope can disclose tenant-specific tool data through shared intermediaries, so private should remain the default. Operators should inventory older clients, provide bounded compatibility, progressively remove session infrastructure, and test retries to ensure tools do not repeat side effects.

Source

MCP went stateless: Is your AWS MCP server deployment well-architected?

Why developers should care

Teams can remove protocol-specific sticky sessions and session stores while keeping business state explicit through identifiers.

  1. 1Inventory sticky routing and session stores, make tools idempotent, then canary the MCP 2026-07-28 protocol with compatibility monitoring.