Model Context Protocol · specification revision 2026-07-28 · MCPA prep
Learn MCP the way you'll use it
Two tracks, one lesson per page. Every lesson starts with a real incident, shows the messages on the wire, and ends with tests you can run and questions that catch the classic mistakes.
Start: Core MCP & Security →Then: what changed in July →
Recommended order: Track 1 teaches MCP as it is today, with no legacy content. Track 2 then shows each July 2026 change with the current behaviour first and the old version folded away, so you replace old habits instead of reinforcing them.
node reference-server.mjsTrack 1
Core MCP & Security
Start here. How MCP works today, with no legacy content: hosts, clients and servers, the primitives, a tool call end to end, transports, authorization, the named attacks, consent, and the ecosystem.
- 00Core conceptHosts, clients, servers 🎧Every MCP question gets easier once you know which of the three parts is responsible. The host is in charge, each client talks to exactly one server, and a server sees only what it is given.
- 01Core conceptTools, resources, prompts 🎧Tools, resources and prompts differ less in shape than in who decides when they are used: the model, the application, or the user.
- 02Common source of bugsA tool call, end to end 🎧A tool can fail in two very different ways. Get the difference right and the model can fix its own mistakes; get it wrong and it just gives up.
- 03Security-criticalElicitation & sampling 🎧Servers can ask for three things through input_required: information from the user (elicitation), a model completion (sampling), or the user's folders (roots). Only one of them is not deprecated, and it has a strict rule about secrets.
- 04Common source of bugsTransports, progress, cancel 🎧Two transports. stdio is a subprocess talking newline-delimited JSON; Streamable HTTP is one POST endpoint. Each has a handful of rules that cause most real-world breakage.
- 05Security-criticalAuthorization flow 🎧For HTTP servers, MCP uses OAuth 2.1: the MCP server is a resource server, and every token must be minted for it and checked by it. Learn the flow once and a quarter of the exam gets easier.
- 06Security-criticalThe named attacks 🎧The official security best practices name specific attacks, each with conditions that make it possible and a rule that stops it. Learn them as pairs: the setup, and the one control that breaks it.
- 07Security-criticalConsent, injection, audit 🎧Tools are arbitrary code execution, and their descriptions are written by whoever runs the server. A human in the loop, untrusted annotations and good audit logs are what stand between a model and a bad day.
- 08EcosystemRegistry, extensions, A2A 🎧Servers are found through a registry, built with SDKs, extended with opt-in extensions, and changed through SEPs. And MCP is not the only protocol: it pairs with A2A.
Track 2
What changed in 2026-07-28
Then this. Each lesson takes one July 2026 change, shows the 2026-07-28 behaviour first, and keeps the old version folded away, so habits from earlier versions get replaced, not reinforced.
- 00OrientationStart here 🎧Revision 2026-07-28 makes one decision, and almost every other change follows from it: each MCP request now has to stand on its own.
- 01Breaks immediatelyThe handshake is gone 🎧initialize and notifications/initialized are removed. The version, capabilities and client identity now ride in _meta on every single request.
- 02New, mandatoryserver/discover 🎧With no handshake, the server needs somewhere else to announce itself. Every server MUST now implement server/discover.
- 03Fails quietlyHTTP headers 🎧Every POST mirrors key body fields into headers, so load balancers, gateways and firewalls can route and rate-limit without parsing JSON. If a header disagrees with the body, the request is rejected.
- 04Breaks immediatelySessions become handles 🎧The Mcp-Session-Id header and protocol-level sessions are removed. If a tool needs to remember something between calls, it hands the client an explicit ID.
- 05Breaks immediatelyMulti Round-Trip Requests 🎧This is the biggest change, and the most tested. Servers no longer send elicitation, sampling or roots requests mid-call. They return input_required, and the client re-sends the original request with the answers.
- 06Fails quietlyTyped, cacheable results 🎧Results must carry resultType. Lists, reads and discovery must also carry ttlMs and cacheScope, so clients and proxies know how long to cache them.
- 07Breaks immediatelysubscriptions/listen 🎧The standalone GET stream and resources/subscribe are gone. A client opens subscriptions/listen, an ordinary request whose response stays open, and opts in by notification type.
- 08Fails quietlyNo resume, close = cancel 🎧SSE resumability (Last-Event-ID) is gone. If a response stream breaks, the client re-sends the request with a new id. And on HTTP, hanging up is how a client says stop.
- 09Fails quietlyRemoved: ping, setLevel… 🎧Several utilities that depended on session state are gone, and one familiar error code moved.
- 10RedesignedTasks extension 🎧Experimental tasks moved out of the core protocol into an official extension, io.modelcontextprotocol/tasks, with a different set of methods.
- 11On a 12-month clockDeprecations & lifecycle 🎧The revision adds a formal feature lifecycle, Active → Deprecated → Removed, with at least twelve months between Deprecated and Removed, and puts several features on it.
- 12ShiftingAuth tightening 🎧Clients move from registering dynamically to identifying themselves by a URL. Several MUSTs close known OAuth attacks.
- 13ReviewWrap-up 🎧The whole revision as a to-do list, in the order you'd actually do it. If you can explain each line without scrolling back, you're ready.
Built from the public MCP specification, revision 2026-07-28. Source on GitHub. Payloads marked as verbatim come from the spec; others are labelled illustrative. Stories are hypothetical scenarios. When this site and the spec disagree, the spec wins.
Feedback or a correction? Email diego [at] diegozuluaga [dot] dev or open an issue on GitHub.