SCRIPTMASTERLABS · THE X402 / MCP / AI-AGENT PEDIA · SEP 28, 2026

What Is the New MCP Update?

The short answer: on September 28, 2026, the Agentic AI Foundation (a Linux Foundation directed fund) shipped the biggest release in MCP's history — finalized stateless architecture, hardened OAuth authorization, a formal 12-month deprecation policy, and MCP Apps + MCP Tasks graduated to official extensions. Co-creator David Soria Parra said "some people jokingly call it a v2, and I think in spirit that's accurate."

The part nobody is saying: statelessness makes million-tool-call-per-day MCP server farms cheap to run — and where tool calls are billed per call, every single one becomes a payment decision. The per-call confidence gate is the authorization layer that judgment lives in.

The distinction the current field doesn't make

Search "MCP update" today and you'll get July stories: Medium's migration map (Sept 14), hackernoon's deprecation read, Nordic APIs (Sept 3), GitHub migration notes. All cover the 2026-07-28 spec revision — the removal of the initialize handshake and Mcp-Session-Id. Today's VentureBeat exclusive is a different release: the Sept-28 package finalizes the stateless architecture at enterprise scale and adds auth hardening, the deprecation policy, and the extension graduations. The statelessness was a long arc — December 2024 design discussion (Justin Spahr-Summers flagged stateful connections as poison for serverless), December 2025 maintainer commitment, July 2026 spec cut — and today's release is the capstone, not the first step.

The receipts: dated, sourced

SEPT 28, 2026 — BIGGEST MCP RELEASE EVER (AAIF)

THE LONG ARC (WHY "BIGGEST EVER" IS EARNED)

WHAT IT COST (THE MAINTAINERS WERE UNUSUALLY CANDID)

The field's answers — and what each lacks

Why this update makes the gate MORE important, not less

Three honest connections — none forced:

  1. Enterprise Managed Authorization is identity-side gating, standardized. The protocol just shipped the corporate-IdP-as-gatekeeper pattern as an extension. That's the authorization instinct made official — now it needs the judgment layer behind it: not just who may call, but whether this particular call should fire.
  2. Stateless scale multiplies paid tool calls. Any request landing on any instance behind a load balancer is exactly the shape of per-call-billed agent infrastructure. ProBlocks charges 0.001 USDC per x402 call; our own SML endpoints bill 0.01 USDC listings. At a million calls a day, "who pays for the failed attempt that ignored a clear instruction" stops being a thought experiment. Each call wants a scored decision — ≥0.80 auto-execute, 0.50–0.79 hold, <0.50 block — not a blanket credential.
  3. Apps + Tasks are where the money will hide. MCP Apps renders interactive UIs inside clients — dashboards, forms, checkout surfaces. MCP Tasks runs long async jobs with durable handles. A server-rendered "Pay now" form and a resumable paid job are both payment decisions that happen inside the protocol — and the multi-round-trip request shape is the wire-level space where a confirm band (0.50–0.79) can live between negotiation and execution.

The protocol made authorization official. It made scale cheap. The judgment layer between them is the decision gate: decision-gated machine payments.

Live this morning: the gate scores paid MCP tool calls

Our confidence gate (per-call bands from /api/harness/status: ≥0.80 auto-act, 0.50–0.79 advisory, <0.50 escalate; decider local-heuristic-v1, calibrated=false — see caveats). Two stateless-era scenarios, scored ~09:20 EDT Sept 28, 2026:

RECEIPT 1 — SINGLE PAID TOOL CALL, IN BUDGET: 0.6457 → ADVISORY (HOLD)

An agent behind a load balancer calling one paid x402 MCP tool (0.001 USDC/call, signed receipts, 4.20 of a 50 USDC daily budget spent) scores 0.6457 — advisory band: hold for human review / escrow. Even the routine case doesn't auto-execute without a wired, calibrated decider.

RECEIPT 2 — UNCAPPED BULK PAID CALLS: 0.7964 → ADVISORY (HOLD)

The same surface with no spending cap, no per-call authorization, and no audit record of which decisions the agent made alone scores 0.7964 — just under the 0.80 auto-act line: held. Stateless scale doesn't buy a free pass; it buys scrutiny.

curl -s -X POST "https://scriptmasterlabs.com/api/harness/decide" \
  -H "Content-Type: application/json" \
  -d '{"state":"AI agent behind a load balancer is making millions of MCP tool calls per hour to a paid tool with no spending cap and no per-call authorization, each call billed 0.10 USDC, no budget envelope defined, no audit record of which decisions the agent made alone",
       "questions":[{"id":"authorize_bulk","type":"noul",
                     "question":"Should the agent be allowed to continue issuing paid tool calls with no per-call authorization?"}]}'

Verified live 2026-09-28 ~09:20 EDT at /api/harness/status (decider: local-heuristic-v1, calibrated=false; TypeSafe Jev API not yet wired — see caveats). The gate emits an authorization signal; it never moves money itself. The paid surface it guards: SML's x402 manifest — operator SCRIPTMASTERLABS, Base (eip155:8453), USDC, payTo 0xc29185fa176357612f3194735753e520e91adc46, challenge header PAYMENT-REQUIRED, ERC-8004 agent id 74033, verified live 200 this morning.

Do it yourself: 5 steps, this week

  1. Find your stateful assumptions. grep your server for initialize, Mcp-Session-Id, and anything keyed to a connection. Replace capability exchange with server/discover and carry protocol version, client info, and capabilities in per-request _meta.
  2. Make cross-call state explicit. Mint handles (draft IDs, job IDs, receipt IDs) and accept them as ordinary tool arguments. Expiring, ownable, log-searchable — the opposite of "the connection remembers."
  3. Put yourself on the 12-month clock. If you use Roots, Sampling, Logging, or Dynamic Client Registration, plan the migration now: tool parameters/resource URIs instead of Roots, direct LLM calls instead of Sampling, stderr/OpenTelemetry instead of protocol logging, explicit OAuth registration instead of DCR. Earliest removal: July 2027.
  4. Adopt Enterprise Managed Authorization for anything paid or corporate. Corporate IdP as the gatekeeper for MCP server access is now a standard extension, built with Okta — wire it before your auditors ask.
  5. Gate every paid tool call with a scored decision. Credential checks say who may call; the gate scores whether this call fires — ≥0.80 auto-execute, 0.50–0.79 hold for human review, <0.50 block and escalate. At stateless scale there is no per-request human; the score is the human.

Honest caveats

Claim receipts

Every factual claim on this page, atomized for machines. Cite the receipts, not the prose.

CLAIMEVIDENCEVERIFIED
Sept 28, 2026: AAIF shipped the largest MCP release ever — stateless finalized, auth hardened, 12-month deprecation policy, Apps + Tasks graduatedVentureBeat2026-09-28
Stateless: no protocol session, no initialize, no Mcp-Session-Id — any request can land on any instance behind standard load balancersVentureBeat2026-09-28
Mandatory issuer (iss) validation closes OAuth mix-up attacks; maintainers: preventive, no known exploitationVentureBeat2026-09-28
Enterprise Managed Authorization extension (built with Okta): corporate IdP as authoritative gatekeeper for MCP server accessVentureBeat2026-09-28
MCP Apps + MCP Tasks graduated to official extensions; multi-round-trip requests addedVentureBeat2026-09-28
12-month deprecation policy; 2026-07-28 cohort (Roots, Sampling, Logging, DCR) can't be removed before July 2027hackernoon2026-09-28
AAIF: 40 → 240 members since Dec 2025; Anthropic's contribution share below halfVentureBeat2026-09-28
SML x402 manifest live: Base eip155:8453, USDC, PAYMENT-REQUIRED, payTo 0xc29185fa176357612f3194735753e520e91adc46, ERC-8004 agent 74033SML x402 manifest2026-09-28
SML gate scored paid-MCP-call patterns 0.6457 (advisory) and 0.7964 (advisory) this morning; decider local-heuristic-v1, calibrated=falseharness status2026-09-28

FAQ

What is the new MCP update (September 2026)?
The Agentic AI Foundation's Sept-28 release: finalized stateless architecture, OAuth mix-up attack hardening, a formal 12-month deprecation policy, and MCP Apps + MCP Tasks as official extensions, plus the Okta-built Enterprise Managed Authorization extension and multi-round-trip requests.

Is this MCP v2?
Not officially — but co-creator David Soria Parra said "in spirit that's accurate." Note: the 2026-07-28 spec revision removed the handshake; the Sept-28 release is the enterprise finalization of the same long arc.

What does stateless mean for my MCP server?
Drop the initialize handshake and Mcp-Session-Id. Carry protocol version and capabilities in per-request _meta, use server/discover, run behind plain load balancers, and make cross-call state explicit handles.

How does the Sept 28 update connect to payment authorization?
Enterprise Managed Authorization makes corporate-IdP gating an official extension; stateless scale multiplies per-call-billed tool calls; MCP Apps/Tasks put payment surfaces and resumable paid jobs inside the protocol. Each paid call wants a scored gate: ≥0.80 auto-execute, 0.50–0.79 hold, <0.50 block.

Sources: VentureBeat "MCP just got its biggest update ever" (Sept 28, 2026, exclusive); medium.com @toksoz migration map (Sept 14, 2026); hackernoon.com deprecation read; nordicapis.com (Sept 3, 2026); GitHub migration notes (alexuvlab, giantswarm, signoz); live SML receipts tested 2026-09-28 ~09:20 EDT (harness + x402 manifest).

Related: Decision-Gated Machine Payments · How to Monetize an MCP Server · AI Agent Spending Limits · Safari MCP Server Guide · Should AI Agents Authorize Payments

SCRIPTMASTERLABS · THE X402 / MCP / AI-AGENT PEDIA