The fifth major spec release transforms the Model Context Protocol with a stateless architecture, enterprise-grade security, and dynamic UI extensions—fueling a new generation of seamless AI integrations.
- Massive Growth and a Stateless Shift: With over 400 million monthly SDK downloads, MCP’s transition to a stateless, request/response core allows developers to easily scale AI agents on edge and serverless infrastructure.
- Enterprise-Grade Security and UI Extensions: Hardened authentication now perfectly aligns with industry standards like OAuth 2.0, while standardized extensions introduce interactive, inline UIs directly within conversations.
- Deepening Claude Integration: Claude’s ecosystem now boasts over 950 MCP servers, rolling out powerful new tools like enterprise-managed zero-touch auth, developer observability dashboards, and private network tunnels.
The landscape of artificial intelligence is no longer just about the models themselves; it is entirely dependent on how effectively those models can connect with the tools, data, and applications we use every day. The Model Context Protocol (MCP) has rapidly emerged as the undisputed industry standard for bridging this gap. Recently surpassing a staggering 400 million monthly SDK downloads—a fourfold increase in just this year alone—MCP is the engine powering the modern AI ecosystem. Today, that engine gets its most significant upgrade yet with the live rollout of the fifth spec release: MCP 2026-07-28.

At the heart of this milestone release is a fundamental architectural shift. The protocol is moving away from its traditional bidirectional stateful design in favor of a sleek, stateless request/response model. For developers, this is a game-changer. By embracing a stateless core, MCP servers can now be deployed natively on modern serverless and edge computing infrastructure. This dramatically simplifies the experience of building custom MCP servers for Claude, ensuring they remain resilient, cost-effective, and effortlessly scalable as user adoption grows.
Security and extensibility have also taken a massive leap forward. In an era where AI agents handle increasingly sensitive enterprise data, authentication workarounds are no longer acceptable. The new spec introduces hardened authorization that seamlessly aligns with production OAuth 2.0 and OIDC deployments. This means MCP servers can directly and securely interface with heavyweight enterprise identity systems like Microsoft Entra and Okta straight out of the box. Alongside this security upgrade comes a formalized, versioned framework for standardized extensions. Capabilities like interactive UIs (MCP Apps) and long-running workflows (Tasks) can now be implemented without altering the core protocol, providing developers with a stable, predictable path for innovation.
As the new spec goes live, its impact is already reverberating across Claude’s product lineup. The Claude ecosystem is thriving, currently listing over 950 MCP servers in its connectors directory, facilitating millions of user interactions daily. With the integration of MCP 2026-07-28, Claude is actively deploying features designed to make building, deploying, and using these tools more intuitive than ever.
One of the most noticeable improvements for end-users is the rollout of MCP Apps, which allows servers to render highly interactive user interfaces directly inside the chat window. Instead of constantly switching tabs to monitor what a connector is doing or to approve an action, users can now engage with inline tools organically as part of their conversation with Claude.
For IT administrators and development teams, the updates are equally transformative. The new enterprise-managed auth framework allows admins to provision MCP connectors for an entire organization through their existing Identity Provider (IdP). Administrators authorize a connector once, and users automatically inherit access based on their IdP groups, resulting in a frictionless, zero-touch setup upon their first login. Meanwhile, developers publishing connectors in the directory gain access to comprehensive observability dashboards. This crucial tooling allows creators to track adoption rates, diagnose latency or errors, and break down usage metrics across various Claude product surfaces, ensuring high-quality performance.
Perhaps most intriguingly for enterprise security, Claude is introducing MCP tunnels as a research preview. This feature bridges Claude to MCP servers hosted deep within a company’s private network, entirely bypassing the public internet. Organizations can now unleash Claude on their highly sensitive internal tools without the headache of configuring inbound firewall rules, opening public endpoints, or managing complex IP allowlists.
The arrival of MCP 2026-07-28—championed by its stateless core, standardized extensions, and impenetrable auth—marks a new chapter for AI connectivity. It empowers developers to bring richer, more secure applications to Claude while drastically lowering friction for the end-user. As the standard continues to mature, ongoing investments from the open-source community and product teams alike ensure that building robust, production-ready AI workflows will only become faster, safer, and more universally accessible.

