Technology

MCP Goes Stateless and Changes How Enterprises Run Remote Agent Servers

The Model Context Protocol's July specification removes mandatory sessions, sticky routing and the initialize handshake. AWS says the change makes serverless deployment a natural fit, though teams must preserve a compatibility lane for older clients.

By Leo W ·

MCP Goes Stateless and Changes How Enterprises Run Remote Agent Servers

The Model Context Protocol has removed mandatory protocol sessions, changing the infrastructure required to operate remote tool servers for AI agents. Under the July 28, 2026 specification, the initialize handshake and Mcp-Session-Id header are gone. Each request carries its protocol version and client context, allowing any healthy server instance to respond. AWS is now advising teams to migrate away from sticky routing and shared session stores once their older clients have been retired.

The change is architectural rather than cosmetic. Earlier MCP servers often pinned a conversation to one instance or placed session state in DynamoDB or ElastiCache. That machinery existed because later requests depended on context established during initialization. Stateless MCP puts the information needed to understand a call in the request, closer to ordinary HTTP practice. Horizontal scaling becomes simpler because an instance can fail without taking its sessions with it.

Stateless does not mean an application cannot preserve state. A tool can store a job, document or transaction and return an identifier. The model includes that identifier in later calls. The state remains in the application's database while the protocol carries the reference explicitly. This distinction matters because teams might otherwise remove storage that supports real business continuity rather than infrastructure that only compensated for the old handshake.

Stateless MCP allows any server instance to handle a request, removing the need to pin an agent session to one machine.
Stateless MCP allows any server instance to handle a request, removing the need to pin an agent session to one machine.

Serverless Moves From Workaround to Default

AWS Lambda naturally expects a request to arrive, execute and finish without a persistent connection to one process. Session-based MCP could run there, but developers had to externalize handshake state and manage continuity. The new core matches the platform: request in, response out. For bursty agent traffic, that can reduce idle infrastructure and eliminate a session store whose only purpose was keeping the protocol alive.

AWS estimates that a small two-node ElastiCache session store costs about $23 a month, but the direct bill is not the main saving. Removing a stateful dependency reduces patching, monitoring, failure modes and on-call work. At larger scale, sticky routing also wastes capacity because load follows the sessions held by each instance rather than distributing evenly across the fleet.

The specification adds a server/discover method that exposes supported protocol versions, capabilities and identity. Clients do not have to call it before every task, but servers must implement it. Discovery gives gateways a cleaner negotiation path and helps organizations inventory what a remote endpoint can do before an agent uses it. Capability metadata should still be treated as a claim and checked against policy.

Routing and throttling can now use Mcp-Method and Mcp-Name HTTP headers instead of parsing the request body. That lets gateways apply controls earlier and more cheaply. It also makes header integrity important. A server must verify that routing metadata matches the actual request rather than trusting a client to label a dangerous tool call as a harmless read operation.

The new protocol carries routing and tracing context explicitly, giving gateways better signals for policy, throttling and observability.
The new protocol carries routing and tracing context explicitly, giving gateways better signals for policy, throttling and observability.

Retries Become a Tool Design Responsibility

The protocol no longer relies on stream resumption for a broken response. A client reissues the call, which means tools that produce side effects must be idempotent. Creating the same invoice, sending the same message or changing the same record twice cannot be an acceptable retry behavior. Developers need operation keys, deduplication and clear status queries so a network failure does not turn into duplicated work.

Multi-round-trip requests replace the pattern in which a server pushed a question back to the client during a held-open call. A server that needs confirmation or more information returns input_required with a set of requests and an opaque requestState token. The client gathers the response and resends the original operation. Any instance can resume because the token carries the continuity required by the protocol.

That design is cleaner for distributed systems, but the continuation token becomes sensitive. It may authorize or reveal part of an unfinished workflow. Tokens need integrity protection, bounded lifetime and replay rules. The model can reason about an explicit identifier, which is useful, yet anything placed in model context can also be exposed to prompt injection or accidental disclosure. Applications should keep the token opaque and scope it to one operation.

Observability improves through W3C Trace Context carried in request metadata, allowing calls to connect with OpenTelemetry-compatible systems. End-to-end traces are crucial when an agent crosses a gateway, tool server, database and external API. Teams should avoid placing secrets or raw sensitive prompts into trace attributes. Better correlation does not require collecting every piece of content.

Migration cannot happen as one deletion. The specification preserves a compatibility lane for clients using the 2025 protocol, and those clients still need session infrastructure. Operators should log protocol version, publish a sunset date and remove sticky routing only after old traffic reaches zero. A premature cleanup will create failures that look intermittent because only some clients depend on the retired path.

Several features now carry a deprecation clock. Roots, Sampling, protocol Logging and HTTP plus SSE have at least a 12-month floor before removal, with July 2027 as the earliest date. Teams should move directories into tool parameters or resource URIs, call model providers directly instead of Sampling, use standard logging and migrate transport to Streamable HTTP.

Security reviews should revisit assumptions built around session identifiers. Some gateways used the session as a convenient boundary for rate limits, audit grouping or revocation. Removing the protocol session does not remove those business requirements. They need explicit replacements based on user, client, operation or application state. A stateless transport should improve architecture, not erase controls that happened to attach to the old mechanism.

Caching introduces similar nuance. The new freshness fields allow servers to declare a time to live and cache scope, reducing repeated tool-list or resource calls. A response that is safe to share across one user's session may not be safe across an organization. Servers must define scope conservatively and include authorization in cache keys. Performance gains are not worth returning one customer's tool metadata or data to another.

Managed gateways can hide part of the migration. AWS says Bedrock AgentCore Gateway handles protocol management and backward compatibility for customers using the service. That convenience shifts implementation responsibility to the provider but not accountability. Operators still need to know which versions their clients use, how the gateway retries side effects and what telemetry is available when a call fails.

Conformance testing should become part of deployment. A server may appear to work with one host while mishandling discovery, continuation or errors under another. The official test suite can catch protocol violations, but teams should add application cases for authorization, duplicate requests and interrupted workflows. Interoperability is the reason to use a standard; testing only the happy path gives that benefit away.

The revision may accelerate a larger market of small, specialized remote tools because developers can deploy them without managing session infrastructure. That lowers the cost of integration and expands the supply chain an enterprise must assess. Registries, signing, provenance and permission review become more important as a single agent composes tools from many operators. Easier hosting should not mean automatic trust.

The stateless revision makes MCP less special in a useful way. Remote agent tools now fit familiar load balancing, serverless, tracing and retry patterns. That familiarity lowers deployment cost, but it also removes excuses for weak engineering. Once sessions stop hiding continuity, state, authorization and idempotency have to be designed explicitly. The protocol is simpler; the responsibility of every tool remains exactly as serious.

Topics: Model Context Protocol, MCP, AWS, AI agents, serverless