MCPNews

The Model Context Protocol ecosystem, verified

Current spec 2026-07-28

MCP 2025-06-18 hardens authorization and adds elicitation

The third specification revision classified MCP servers as OAuth resource servers, required RFC 8707 resource indicators against malicious-server token capture, added elicitation and structured tool output, and removed JSON-RPC batching.

The 2025-06-18 revision focused on security and interactivity. On the security side, MCP servers were formally classified as OAuth resource servers with protected resource metadata, and clients were required to implement RFC 8707 resource indicators to prevent malicious servers from obtaining access tokens; the revision also added a dedicated security best practices page to the specification.

On the interactivity side, the revision introduced elicitation (servers requesting additional information from users mid-interaction), structured tool output, and resource links in tool results. JSON-RPC batching, added in the previous revision, was removed. The negotiated protocol version became mandatory on subsequent HTTP requests via the MCP-Protocol-Version header. The full change list is recorded on the MCP 2025-06-18 revision page.

Related spec revisions

How was this verified, and what are the sources?

Published · last verified · confidence 1.00.

  1. Official 2025-06-18 changelog - batching removal, structured tool output, OAuth resource-server classification, RFC 8707 resource indicators, elicitation, resource links, MCP-Protocol-Version header requirement - accessed
  2. Official specification text for the 2025-06-18 revision - accessed

← All news