← All posts / Tools

MCP's Next Act: Agentic Messaging, Agent Identity, and One HTTP Transport

The Model Context Protocol's lead maintainers published a new roadmap on August 22, 2026, reorienting the spec around agent-native messaging, unified HTTP transport, and standardized agent identity — the plumbing the agentic web will run on.

MCP's Next Act: Agentic Messaging, Agent Identity, and One HTTP Transport

The Model Context Protocol (MCP) — the open standard that has quietly become the de facto way AI models connect to tools, data, and each other — just got its marching orders for the next phase of its life. On August 22, 2026, lead maintainers David Soria Parra and Den Delimarsky published a new roadmap for the protocol, laying out five priority areas that will shape upcoming specification releases and, by extension, the architecture of the agentic software ecosystem being built on top of it.

The timing matters. MCP has crossed the chasm from experimental spec to production infrastructure: it is supported across OpenAI, Google, and Anthropic ecosystems, baked into coding agents like Claude Code, Cursor, and Codex, and deployed by enterprises connecting AI systems to internal APIs. When the protocol’s maintainers reorganize their priorities, thousands of downstream developers and vendors follow. The discussion on Hacker News, where the roadmap hit the front page within hours, reflects how closely the developer community is watching.

Why a roadmap for a protocol?

MCP emerged in late 2024 as Anthropic’s answer to a fragmentation problem: every AI application was inventing its own way to plug models into external tools. MCP standardized that interface — a client-server protocol where a host application (an IDE, a chat client, an agent runtime) connects to servers that expose tools, resources, and prompts.

Eighteen months of explosive adoption later, the protocol is straining against workloads its designers didn’t originally anticipate. The new roadmap is explicit about this: “Modern agentic workloads no longer fit the standard request-and-response pattern. Loops can run for longer, servers can push streamed results, and there is a clear need to steer work mid-flight.”

That sentence is the thesis of the entire document. The five priority areas that follow are all downstream of one realization: MCP was designed for interactive apps, but its biggest users are now autonomous agents.

The five priority areas

1. Agentic messaging primitives

The first, and arguably most consequential, priority is rethinking the protocol’s messaging model for agents. MCP has already grown Tasks, subscriptions/listen, and progress notifications; the roadmap now commits to server-initiated events — webhooks and channels, so clients aren’t left polling for results — alongside a composition review across the Agents, Transports, and Triggers & Events Working Groups, and maturing the Tasks extension (SEP-2663) so it can move into the core specification.

In practice, this means long-running agent jobs — a research agent working for twenty minutes, a coding agent managing a build pipeline — will get first-class protocol support instead of bespoke workarounds.

2. HTTP-native transport unification

With the 2026-07-28 release, a remote MCP server became “no different from any other HTTP workload,” according to the maintainers — hostable on the same infrastructure organizations already use for their APIs. The roadmap extends that model to other deployment modes, including local servers speaking Streamable HTTP over stdio. One transport, everywhere. For operators, that means the split-brain world of stdio-based local servers versus HTTP-based remote servers converges into a single, simpler deployment story.

3. Agent identity and enterprise-ready security

Perhaps the most ambitious item: MCP’s authorization model today “is built around a person approving access in a browser.” That works for interactive clients, but as the roadmap notes, “more and more of the callers are agents running as cloud workloads with their own identity, acting on behalf of a user who isn’t present, or delegating narrower authority to sub-agents.”

The plan is to give MCP servers a standardized way to recognize and trust those agent identities — “built on existing standards rather than pasted API keys and long-lived tokens.” Concretely: finalizing Demonstrating Proof of Possession (DPoP) adoption, defining an opinionated path for agent identity and delegation through Workload Identity Federation, the ID-JAG grant behind Enterprise-Managed Authorization, and standard token exchange. The team will also keep working with IETF OAuth and WIMSE working groups so the underlying web standards evolve the building blocks agent identity needs.

This is the piece enterprise security teams have been waiting for. The gap between “an agent acting for a user” and “OAuth for humans” is where most corporate MCP deployments currently get stuck — or quietly accumulate risk with long-lived API keys.

4. Improved primitives

Tool calling — the part of MCP most developers touch first — is due for refinement. Two problems are named. First, tools/call responses can carry the same output in multiple forms, and server developers have no way to know which form a client will surface to the model; the roadmap commits to “standardizing on one clear contract.” Second, and more interesting: progressive discovery. Connecting to a server with a hundred tools means “the model pays for that entire surface before the user has asked a single question, and tool selection tends to get worse as the list grows.” The fix — a small entry point that reveals more of the catalog as the conversation narrows — directly attacks the context-window economics of large tool servers.

5. Improved SDK developer experience

The final area is unglamorous but strategic: SDK ergonomics, specification conformance, and documentation across every supported platform and language. The maintainers note this is “even more important now that many developers build MCP clients and servers by pointing an agent at our libraries” — an acknowledgment that the protocol’s own SDKs are increasingly consumed by AI coding agents, where “clear APIs and accurate docs decide whether the code will work with minimal friction.”

What this signals about the agentic stack

Read together, the five priorities describe a protocol growing from “USB port for AI tools” into something closer to nervous system for agent networks — with standardized identity, delegated authority, event-driven messaging, and scalable discovery.

Several signals stand out for anyone building in this space:

  • The enterprises get their answer. Agent identity via Workload Identity Federation and DPoP is the unlock for regulated industries that couldn’t put browser-flow OAuth in front of an unattended agent. Expect enterprise MCP adoption to accelerate once these land in the spec.
  • Context economics are now a protocol concern. Progressive discovery acknowledges that the token cost of tool surfaces is a real tax. Servers designed as narrow entry points with on-demand depth will out-compete monolithic tool dumps.
  • HTTP everywhere simplifies hosting. Unifying on Streamable HTTP — even over stdio — means infrastructure teams run MCP servers exactly like any other web service: same load balancers, same observability, same security tooling.
  • The governance model is working. The roadmap was developed by Core Maintainers with Working Groups, routes features through SEP proposals, and operates under the Linux Foundation’s LF Projects umbrella. For a protocol this load-bearing, boring, accountable governance is a feature.

The road ahead

The roadmap is careful to note what it is not: an automatic rejection of ideas outside the priority areas. But it is explicit that “maintainer review time is scarce and goes to the roadmap first.” For proposal authors, alignment with these five areas is now the fast lane.

For the broader AI industry, the document is a useful snapshot of where agentic infrastructure is heading: away from human-in-the-loop request/response patterns, toward machines that run long, delegate, stream, and identify themselves cryptographically. MCP is betting its future on being the shared substrate for that world — and based on the momentum behind this roadmap, that bet looks increasingly safe.

The spec work happens in the open: Working Groups are recruiting, SEPs are open for comment, and experimental extensions can start under SEP-2133 before formal proposals. If you’re building agents, now is the moment to shape the plumbing they’ll run on.