Guide

MCP 2026-07-28 Without Sessions: What Changes for Magento MCP Servers

MCP 2026-07-28 removed the initialize handshake and protocol-level sessions. Every request now carries its own protocol version, and every server must answer a new server/discover call. For a Magento MCP server this is mostly a change of envelope: the tools stay the same, and a guest cart id already works the way the new spec wants state to work.

In one sentence

No more handshake and no more sessions – a store server needs server/discover and a new request envelope, not new tools.

What changed

MCP 2026-07-28 is the first revision without a connection handshake. The changelog lists nine major changes; these are the ones a store’s MCP server feels:

Before (2025-11-25 and earlier)Now (2026-07-28)
initialize / notifications/initialized handshakeRemoved. Every request carries its protocol version and client capabilities in _meta
Mcp-Session-Id header, per-connection sessionsRemoved. State the server needs is passed as ordinary tool arguments – for a store, a cart id
Capabilities and instructions in the initialize resultNew server/discover: servers must implement it, clients may call it first
ping, logging/setLevelRemoved; log level travels per request in _meta
Results without a typeEvery result has resultType ("complete" or "input_required")
tools/list without caching hintsttlMs and cacheScope required on list results; tools in a deterministic order
Headers optionalMcp-Method and Mcp-Name required on Streamable HTTP POST requests
GET stream, resources/subscribeOne subscriptions/listen stream for change notifications

The spec now names two eras. Legacy versions use the initialize handshake (2025-11-25 and earlier). Modern versions use per-request metadata. A dual-era server supports both.

Will my existing server stop working?

Not by itself. The spec keeps a path for old servers: a client that supports both eras sends a modern request first and, if the server answers with a plain 400 Bad Request or an error it does not recognize as modern, falls back to initialize. So a legacy server keeps working with dual-era clients.

It stops working with clients that speak only the modern protocol. Which assistants will drop legacy support, and when, is not published. The deprecation policy in this revision promises at least twelve months for deprecated features – but the handshake was removed, not deprecated.

Why a store server is easier to move than most

A commerce MCP server rarely needed sessions. Catalog tools are read-only, and a guest cart already lives behind its own id. That is the pattern 2026-07-28 asks for: state as an explicit handle in the tool arguments, not in the connection. The migration is mostly about the envelope, not the tools.

Checklist for a Magento MCP server

  1. Implement server/discover: return supportedVersions, capabilities and instructions.
  2. Read the version from each request (_meta io.modelcontextprotocol/protocolVersion and the MCP-Protocol-Version header). Answer an unknown version with UnsupportedProtocolVersionError (code -32022) and the list you support.
  3. Validate Mcp-Method and Mcp-Name against the body; reject a mismatch with HeaderMismatchError (-32020).
  4. Add resultType: "complete" to every result, and ttlMs plus cacheScope to tools/list and prompts/list. Catalog tool lists can use "public".
  5. Return tools in a fixed order. It helps client-side and prompt caching.
  6. Keep the legacy path (initialize, ping) while clients still use it – that makes the server dual-era.
  7. Never cache the endpoint in the full-page cache – this has not changed.

Where angeo/module-mcp-server stands

Status on 24 September 2026

angeo/module-mcp-server 2.2.x implements protocol 2025-06-18 and negotiates down to 2025-03-26 and 2024-11-05. It does not implement server/discover or the modern envelope yet. It never used protocol-level sessions – catalog tools are stateless and the checkout tools pass a cart id – so the move is the checklist above, not a redesign. Until then it works with clients that still support the legacy handshake.

To see what your server exposes today:

bin/magento angeo:mcp:tools

Questions

What changed in MCP 2026-07-28?
The protocol became stateless. The initialize handshake and Mcp-Session-Id were removed, every request carries its version and capabilities in _meta, and servers must implement server/discover.
Does my old MCP server stop working?
Not with clients that support both eras: they try a modern request and fall back to initialize. It stops working with clients that speak only the modern protocol.
What is server/discover?
A request every 2026-07-28 server must implement. It returns the supported protocol versions, the server’s capabilities and its instructions, so a client can choose a version before any other call.
How do I keep state without sessions?
Pass an explicit handle as a tool argument. For a store, the cart id returned by create_cart is that handle.
Does angeo/module-mcp-server support 2026-07-28?
Not yet. Version 2.2.x implements 2025-06-18 and older versions. It already works without sessions, so adding the modern envelope and server/discover is the remaining work.

Related

Sources

Checked 24 September 2026 against the MCP specification repository (changelog, versioning and Streamable HTTP pages of 2026-07-28, schema.ts) and the source of angeo/module-mcp-server. Disclosure: we build the module.

More on this topic