API

The July 28, 2026 MCP Specification: What Breaks (and What Gets Simpler) for Your Custom CRM

Stateless core, multi round-trip requests, header-based routing, DCR deprecation: the technical detail of the most significant MCP update since authorization, and what it changes if your CRM exposes tools to AI assistants.

If your custom CRM or ERP already exposes tools to AI assistants via the Model Context Protocol (MCP) — or it's on your roadmap — the specification published on July 28, 2026 on blog.modelcontextprotocol.io is worth a technical audit. According to the protocol's own maintainers, it's the most significant change since authorization was added. Here is precisely what changes, verified against the official source.

The end of the persistent session: the protocol core goes stateless

The initialize/initialized handshake and the Mcp-Session-Id header are gone. Every request now carries the client's identity, protocol version, and capabilities itself in a _meta field. Direct infrastructure consequence: your MCP server no longer needs shared session storage or persistent connections, and can be distributed behind a plain round-robin load balancer, with no sticky sessions.

The tricky part: if one of your MCP tools drives a multi-step process (an assistant building a CRM order step by step, for example), you can no longer rely on a server session to carry that state. The spec requires the tool to mint an explicit handle and have the model itself pass it back as an argument on the next call. State no longer lives in the transport layer — it lives in the tool's arguments. That's an architecture change, not a patch.

Multi Round-Trip Requests: no more open connections for a user confirmation

Before this version, a tool that needed to ask the user for confirmation or a missing input (elicitation, sampling) had to keep a bidirectional stream open. Now the server simply responds with resultType: "input_required" along with what's expected, and the client retries the call with the answers in inputResponses.

For a business CRM, this is directly relevant: a tool asking "confirm deletion of these 40 contacts?" before acting no longer needs an open stream — which fixes a real production problem, since corporate proxies and firewalls that kill idle connections used to break this kind of interaction.

Mandatory header-based routing

The Mcp-Method and Mcp-Name headers, previously optional, are now mandatory on every streamable HTTP request. In practice, your API gateway or WAF can now route, rate-limit, and make authorization decisions directly on the headers, without parsing each request's JSON body — a real configuration change to make on the infrastructure side, not just in application code.

Cacheable list results: ttlMs and cacheScope

Responses from tools/list, prompts/list, resources/list, and resources/read now carry ttlMs and cacheScope fields, plus guaranteed deterministic ordering. If an AI assistant regularly queries your CRM's tool catalog, populating these fields on your server directly cuts repeated re-fetch traffic — a concrete optimization to implement, not just a theoretical recommendation.

Authorization hardening: Dynamic Client Registration on notice

  • →Authorization servers must now return the iss parameter (RFC 9207), which clients must validate before redeeming an authorization code
  • →The application_type parameter must be specified during Dynamic Client Registration, especially for desktop/CLI apps, to avoid localhost redirect rejection
  • →Client credentials are now bound to the authority that issued them — no more reuse across authorization servers
  • →Dynamic Client Registration (DCR) is formally deprecated in favor of Client ID Metadata Documents (CIMD), with an announced transition window of at least 12 months

If your CRM's OAuth registration with third-party MCP servers relies on DCR, the protocol keeps working during this window — but the migration to CIMD should be planned now, not as the deadline approaches.

What's officially deprecated: plan for it on your roadmap

  • →Roots, Sampling, and Logging features are deprecated, with a 12-month transition window
  • →The HTTP+SSE transport is officially deprecated in favor of standard HTTP/JSON-RPC
  • →TypeScript, Python, Go, and C# SDKs are updated to the 2026-07-28 version; the Rust SDK remains in beta

Auditing an existing MCP implementation or scoping its integration into a custom CRM or ERP means settling these architecture points before writing any client-side AI integration code. If you'd like us to run that technical audit with you, contact us directly — response within 24h.

Have a custom CRM project in mind?

Confidential call · Response within 24h · No strings attached

Start a Conversation