Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

MCP separates three concerns: JSON-RPC defines the message envelope, a transport carries messages between an application and a server, and server primitives expose context or actions. The standard transports are STDIO for local deployments and Streamable HTTP for remote ones. Prompts are user-controlled, resources are application-controlled, and tools are model-controlled. The specification dated July 28, 2026, also changes how HTTP routing and multi-step tool interactions work.

How MCP is layered

Model Context Protocol (MCP) connects an application to servers that expose capabilities. The application side includes a host and MCP client; the server provides operations the application can use. To understand a message, keep its format, route, and purpose separate:

  • JSON-RPC envelope: identifies the method and carries its parameters and response. MCP uses JSON-RPC for its message envelopes.
  • Transport: moves serialized messages between client and server. It does not define what a method means.
  • Server primitive: determines whether a capability supplies a prompt, provides data as a resource, or performs an action as a tool.

This distinction matters in practice. Changing from a local to a remote transport does not, by itself, change a method’s meaning; likewise, knowing a method name does not tell an application whether the operation is user-, application-, or model-controlled.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What MCP RPC schemas describe

An RPC schema specifies the structure and meaning of a protocol operation: its method, inputs, outputs, and any applicable constraints. MCP’s JSON-RPC envelope carries method names and parameters, but the envelope alone is not a complete catalog of MCP’s wire-level rules. The public overview of server primitives does not provide every RPC’s field-by-field schema.

For an implementation, consult the normative specification version that the client or server actually supports. Do not infer required fields, types, validation rules, or error behavior from a method name or from a high-level overview. Those details can be version-specific; an SDK’s support for a particular release should also be checked before relying on a feature.

At the architectural level, separate the questions: the method identifies the operation, parameters describe its inputs, and the transport carries the message. This article explains that model and selected changes in the July 28, 2026 specification; it is not a substitute for the complete, version-matched RPC schema definitions.

How prompts, resources, and tools differ

MCP servers expose three distinct primitives. Their control roles describe how an interaction is initiated or used, not a complete authorization or safety policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prompts: user-controlled

Prompts are predefined templates or instructions. They let an application offer reusable guidance that a user can choose to apply. A prompt is not an executable function merely because it contains instructions.

Resources: application-controlled

Resources provide structured data or other content for use as context. The application controls how it discovers, selects, and supplies that context; a resource is not the same thing as a tool invocation.

Tools: model-controlled

Tools are executable functions. In the control model, the model can select a tool to perform an action. That role does not mean a tool should run without appropriate application policy, user consent, or authorization checks.

Which transport should an MCP deployment use?

The specification’s two official transport choices serve different deployment settings. Custom transports are also allowed for specialized requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Transport Intended deployment What it means operationally
STDIO Local The client and server communicate through standard input and standard output.
Streamable HTTP Remote HTTP carries MCP messages and can fit into web infrastructure such as gateways. Under the July 28, 2026 release, requests require the Mcp-Method and Mcp-Name routing headers.
Custom transport Specialized needs An implementation can use an alternative transport, though the official ecosystem is organized around STDIO and Streamable HTTP.

Streamable HTTP makes operation information visible in headers so gateways, rate limiters, and web application firewalls can route or meter requests without parsing JSON bodies. The JSON-RPC message remains the protocol format; the headers serve a transport and infrastructure role. Implementations should keep header values consistent with the request body.

Why the transport choice affects deployment

Transport design affects how traffic reaches a server, not just how bytes are sent. A persistent, stateful connection can create sticky-routing and backend session-storage requirements. HTTP-native patterns can let conventional infrastructure participate in routing. Those are design considerations, not a guarantee that HTTP will be faster or better for every workload.

The July 28, 2026 release deprecated legacy HTTP+SSE and described a year-long offramp. Deprecation is version-sensitive: check the current specification and the specific SDK before migrating or assuming a given implementation still supports that transport.

What changed in the July 28, 2026 specification

The release describes a shift toward a stateless protocol core. These are changes attributed to that dated specification, not claims about every earlier version or every SDK implementation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Initialization and protocol sessions

The release removes the initialize/initialized exchange and the Mcp-Session-Id header. Requests carry protocol and client metadata in _meta; a client can optionally call server/discover to learn server capabilities. With no protocol-level shared session requirement, a request can be routed to any server instance.

That does not require an application to discard state. A server can issue an explicit handle and accept it as an ordinary tool argument in a later operation. The application’s continuity is then represented in data passed between operations rather than hidden in a transport session.

Rank #4
JSON Programming Logo for Programmers Tank Top
  • JSON Programming Language design with small pocket logo for JSON Software Engineers and Developers.
  • JSON Programming Language design.
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Routing headers for Streamable HTTP

For Streamable HTTP, requests must include Mcp-Method and Mcp-Name. The release presents these as routing and metering signals for infrastructure that should not need to inspect the JSON body. Keep the header values aligned with the operation represented in the body.

Multi Round-Trip Requests

Multi Round-Trip Requests (MRTR) support a tool interaction that needs additional input while it is running. Instead of relying on a server-initiated request over a held-open bidirectional stream, the server can return resultType: "input_required" with the requested input. The client then retries the original call with answers in inputResponses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The release says this replaces server-initiated elicitation/create, sampling/createMessage, and roots/list requests that previously required an open stream. Applications adopting the flow need compatible clients, servers, and SDK support; verify those versions rather than assuming support from the protocol date alone.

Other release changes

The release also describes cache hints, deterministic ordering for list results, authorization changes including issuer validation and a move from Dynamic Client Registration toward Client ID Metadata Documents, a formal extensions framework, and a deprecation policy with a minimum twelve-month window. These details can affect security and compatibility decisions, so use the dated normative specification for implementation work.

Best Value
The SQL Programming Language: .
  • Used Book in Good Condition
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to evaluate an MCP implementation

Before connecting a client to a server or upgrading an existing deployment, check the requirements that affect your specific interaction:

  • Protocol version: identify which specification version each side implements, especially if you depend on initialization, session behavior, or a deprecated transport.
  • SDK version and transport module: confirm support for the feature you intend to use. A release announcement is not an evergreen guarantee that every SDK package includes every feature.
  • Deployment location: use STDIO for the standard local setup or Streamable HTTP for the standard remote setup; choose a custom transport only when the specialized requirement justifies it.
  • State boundary: determine whether continuity belongs in explicit application data such as a handle or in an older, version-specific session mechanism.
  • Interaction flow: establish whether the call is a straightforward request/response or can require client input through MRTR.
  • Infrastructure routing: for Streamable HTTP on the July 28, 2026 release, ensure the required method/name headers and the JSON request body describe the same operation.

The maintainers reported that TypeScript, Python, Go, and C# were Tier 1 SDKs updated for the July 28 release, and Rust support was in beta at that time. This is a dated status report, not a guarantee about current package versions or complete feature parity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is roadmap work rather than released behavior?

An August 22, 2026 maintainer roadmap says that most planned changes landed in the July 28 release. It identifies ongoing priorities in agentic messaging, HTTP-native transport unification and hardening, agent identity and enterprise security, improved primitives, and SDK developer experience. These are roadmap priorities, not automatically normative protocol features. For conformance or production decisions, distinguish published specification requirements from work that maintainers describe as ongoing.

Quick Recap

Bestseller No. 2
Bestseller No. 4
JSON Programming Logo for Programmers Tank Top
JSON Programming Logo for Programmers Tank Top
JSON Programming Language design.; Lightweight, Classic fit, Double-needle sleeve and bottom hem
$19.99
Bestseller No. 5
The SQL Programming Language: .
The SQL Programming Language: .
Used Book in Good Condition
$4.23

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.