The session is gone; the request describes itself
In the new MCP release the initialize handshake and the Mcp-Session-Id header leave the core request path. Each request carries the protocol version, client identity and capabilities it needs, so any request can land on any instance. In the older arrangement InfoQ describes, every request had to locate the state tied to it, autoscaling had to preserve sessions, deployments had to drain or migrate them, and load balancing was impractical.[1]
For a developer that ends the problem of sticky routing on the server side. The state does not disappear, though; it changes address. The context a server used to hold becomes a load the client or the application has to carry. This reading should not be taken as settled: the release's stated purpose is scaling, and where the context ends up will be decided by each team's own architecture rather than by the protocol.[1]
The change that matters sits in two headers
The same release makes Mcp-Method and Mcp-Name mandatory on Streamable HTTP requests. A tool call arrives as Mcp-Method tools/call with Mcp-Name search, and as Cloudflare's Matt Carey told InfoQ, a gateway, rate limiter or firewall can act per method or per tool without ever opening the JSON body.[1]
Put it on a layer map and the location of the change is clear: agent control moves out of a separate governance product and settles into the transport. What that gives a developer is concrete. A team writes rules with the tooling it already operates and can change those rules without depending on one vendor. The cost sits in the same place: whoever runs the gateway becomes the party that can see and shape what agent traffic does.[1]
Human approval pays the bill
Elicitation absorbs the cost of this simplification. Server-initiated requests used to need an open stream; they now use Multi Round-Trip Requests. The server returns input_required, the client collects the answer, and the call is retried. As InfoQ puts it, this is simpler to deploy, but waiting for a person no longer sits inside a single invocation.[1]
Once approval splits into two separate requests, holding the wait between them becomes the developer's responsibility: which call is waiting for which answer now has to live in the application's own bookkeeping. I think the observable signal for whether this change really takes hold is whether gateway products start documenting per-tool rules keyed on Mcp-Name. Since the removal of Dynamic Client Registration is set for after summer 2027, such documentation appearing before then would show that the transport has become the default place rules get written, and its absence would show that agent control stays in separate products.[1]