The deploy that waited for lunch
A developer tells their agent "deploy payments-service to production". The deploy tool needs a human confirmation: type the service name to confirm. The developer is already walking to lunch.
Legacy: the server sent elicitation/create on an open stream and waited. A worker and a socket were held open, and after 60 seconds the corporate proxy killed the idle stream. When the developer came back, the deploy had silently failed.
2026-07-28: the server answers input_required and forgets about it. Nothing is held open. Forty minutes later the developer types "payments-service", the client retries with a new id, and whichever instance receives it reads the signed requestState and deploys.
The security twist: a compromised client edits requestState to swap "staging" for "production". The signature check fails, and the server rejects it. That's why the spec calls requestState attacker-controlled.