MCP 2026-07-28 Without Sessions: What Changes for Magento MCP Servers
MCP 2026-07-28 removed the initialize handshake and protocol-level sessions. Every request now carries its own protocol version, and every server must answer a new server/discover call. For a Magento MCP server this is mostly a change of envelope: the tools stay the same, and a guest cart id already works the way the new spec wants state to work.
No more handshake and no more sessions – a store server needs server/discover and a new request envelope, not new tools.
What changed
MCP 2026-07-28 is the first revision without a connection handshake. The changelog lists nine major changes; these are the ones a store’s MCP server feels:
| Before (2025-11-25 and earlier) | Now (2026-07-28) |
|---|---|
initialize / notifications/initialized handshake | Removed. Every request carries its protocol version and client capabilities in _meta |
Mcp-Session-Id header, per-connection sessions | Removed. State the server needs is passed as ordinary tool arguments – for a store, a cart id |
Capabilities and instructions in the initialize result | New server/discover: servers must implement it, clients may call it first |
ping, logging/setLevel | Removed; log level travels per request in _meta |
| Results without a type | Every result has resultType ("complete" or "input_required") |
tools/list without caching hints | ttlMs and cacheScope required on list results; tools in a deterministic order |
| Headers optional | Mcp-Method and Mcp-Name required on Streamable HTTP POST requests |
GET stream, resources/subscribe | One subscriptions/listen stream for change notifications |
The spec now names two eras. Legacy versions use the initialize handshake (2025-11-25 and earlier). Modern versions use per-request metadata. A dual-era server supports both.
Will my existing server stop working?
Not by itself. The spec keeps a path for old servers: a client that supports both eras sends a modern request first and, if the server answers with a plain 400 Bad Request or an error it does not recognize as modern, falls back to initialize. So a legacy server keeps working with dual-era clients.
It stops working with clients that speak only the modern protocol. Which assistants will drop legacy support, and when, is not published. The deprecation policy in this revision promises at least twelve months for deprecated features – but the handshake was removed, not deprecated.
Why a store server is easier to move than most
A commerce MCP server rarely needed sessions. Catalog tools are read-only, and a guest cart already lives behind its own id. That is the pattern 2026-07-28 asks for: state as an explicit handle in the tool arguments, not in the connection. The migration is mostly about the envelope, not the tools.
Checklist for a Magento MCP server
- Implement
server/discover: returnsupportedVersions,capabilitiesandinstructions. - Read the version from each request (
_metaio.modelcontextprotocol/protocolVersionand theMCP-Protocol-Versionheader). Answer an unknown version withUnsupportedProtocolVersionError(code-32022) and the list you support. - Validate
Mcp-MethodandMcp-Nameagainst the body; reject a mismatch withHeaderMismatchError(-32020). - Add
resultType: "complete"to every result, andttlMspluscacheScopetotools/listandprompts/list. Catalog tool lists can use"public". - Return tools in a fixed order. It helps client-side and prompt caching.
- Keep the legacy path (
initialize,ping) while clients still use it – that makes the server dual-era. - Never cache the endpoint in the full-page cache – this has not changed.
Where angeo/module-mcp-server stands
angeo/module-mcp-server 2.2.x implements protocol 2025-06-18 and negotiates down to 2025-03-26 and 2024-11-05. It does not implement server/discover or the modern envelope yet. It never used protocol-level sessions – catalog tools are stateless and the checkout tools pass a cart id – so the move is the checklist above, not a redesign. Until then it works with clients that still support the legacy handshake.
To see what your server exposes today:
bin/magento angeo:mcp:tools
Questions
- What changed in MCP 2026-07-28?
- The protocol became stateless. The initialize handshake and Mcp-Session-Id were removed, every request carries its version and capabilities in _meta, and servers must implement server/discover.
- Does my old MCP server stop working?
- Not with clients that support both eras: they try a modern request and fall back to initialize. It stops working with clients that speak only the modern protocol.
- What is server/discover?
- A request every 2026-07-28 server must implement. It returns the supported protocol versions, the server’s capabilities and its instructions, so a client can choose a version before any other call.
- How do I keep state without sessions?
- Pass an explicit handle as a tool argument. For a store, the cart id returned by create_cart is that handle.
- Does angeo/module-mcp-server support 2026-07-28?
- Not yet. Version 2.2.x implements 2025-06-18 and older versions. It already works without sessions, so adding the modern envelope and server/discover is the remaining work.
Related
- MCP and agentic commerce glossary
- MCP for commerce – definition
- MCP for Magento
- MCP modules: configuration reference
- Magento MCP servers compared