What came out of the protocol
The new revision deletes two things at once: protocol-level sessions and the Mcp-Session-Id header leave the Streamable HTTP transport, and the initialize plus notifications/initialized handshake leaves with them. What replaces them is this: every request carries its own protocol version and client capabilities in _meta, and servers must implement server/discover to advertise what they support. A server that needs state between calls now keeps it in explicit, server-minted handles passed as ordinary tool arguments.[1]
Two smaller changes show what the deletion buys. Results from tools/list, prompts/list and resources/list must now carry ttlMs and cacheScope, and servers are advised to return tools in a deterministic order. List endpoints no longer varying per connection is the precondition for those fields to mean anything: a list that differs per connection has no shelf life in a shared cache. Another reading is available — the caching fields could have been added while keeping sessions, and the ordering guidance is only a recommendation, so a server can satisfy the letter and still shuffle.[1]
The dependency moves rather than disappears
The same revision moves Roots, Sampling and Logging into deprecation under a minimum twelve-month window. The suggested migrations are spelled out: pass directories and files through tool parameters, resource URIs or server configuration instead of Roots; integrate directly with model provider interfaces instead of Sampling; log to stderr or OpenTelemetry instead of Logging.[1]
Of the three, Sampling carries the real weight. A server that used Sampling was borrowing the client's model access; now it is told to connect to a provider interface directly. The server author takes on their own key, their own bill and their own model choice. That is not the removal of a dependency but a relocation of it: control returns to the server author, and a new vendor relationship arrives in exchange. For a team that wants to swap components, this is good news; for a small server that reached a model by leaning on one client, it is new operating overhead.[1]
The comparison comes from the same week. Google added environment hooks to the Gemini API's managed agents: custom scripts run before and after every tool call the agent makes inside its sandbox, pre_tool_execution can block or validate a call, and post_tool_execution can lint afterwards. Both moves place an interception point around a tool call, but of different kinds: MCP's is a specification clause every implementer must satisfy, while the hooks are one vendor's runtime feature. Getting the same function at two different levels of commitment decides directly how freely a team can swap the component. A weaker reading is also available: the two changes landing in the same week may be independent schedules coinciding rather than a shared design turn.[1], [2]