Official MCP blog post locking the 2026-07-28 release candidate (final ships July 28, 2026). Headline: fully stateless protocol core — initialize/initialized handshake removed (SEP-2575), Mcp-Session-Id removed (SEP-2567), per-request _meta for client info/capabilities, server/discover for on-demand capability fetch. Routing headers Mcp-Method and Mcp-Name required (SEP-2243). Explicit state-handle pattern for cross-call application state. Extensions first-class (SEP-2133): MCP Apps (SEP-1865) for sandboxed server-rendered HTML UIs; Tasks extension for durable async handles (tasks/get, tasks/update, tasks/cancel). Authorization hardening: mandatory iss validation per RFC 9207 (SEP-2468), OIDC application_type in DCR, issuer-bound credentials. Feature lifecycle policy (SEP-2577): Roots, Sampling, Logging deprecated with ≥12-month window (SEP-2596). Full JSON Schema 2020-12 for tool schemas (SEP-2106). Trace context in _meta (SEP-414). RC locked May 21, 2026; Tier 1 SDKs expected to ship support in the ten-week validation window.