New MCP Roadmap

236 points · 140 comments on HN · read original →

Points and comments are a snapshot, not live.

MCP publishes an updated roadmap with five priority areas for future development.

The Model Context Protocol roadmap focuses on agentic messaging primitives, HTTP-native transport unification, agent identity and enterprise-ready security, improved primitives like progressive discovery for tools, and improved SDK developer experience. The July 2026 release removed stateful sessions, added server discover, caching, and the Tasks extension. Enterprise security now includes DPoP, Workload Identity Federation, and Enterprise-Managed Authorization. SEPs in these areas get expedited review.

What commenters are saying

Commenters split on MCP's complexity. One camp favors "code mode" over MCP for performance and flexibility, citing Cloudflare's approach. Others criticize the initial rollout's stateful design and bespoke protocol, praising the move to HTTP-native. On security, debate centers on whether OAuth and DPoP overengineer simple token auth. Several note enterprise needs for agent identity without human-in-the-loop, with some pointing to existing solutions like workload identity federation or alternatives like SPIFFE.