← All posts / Tools

MCP at 400 Million Monthly Downloads: How Anthropic's Agent Standard Became the Internet's Plumbing

The Model Context Protocol now pulls 400 million SDK downloads a month — 4x growth this year — as the stateless 2026-07-28 spec lands MCP on serverless and edge infrastructure and locks in its status as the default way AI agents touch the outside world.

MCP at 400 Million Monthly Downloads: How Anthropic's Agent Standard Became the Internet's Plumbing

Somewhere between the model releases and the chip deals, the least glamorous story in AI quietly became one of the most important. The Model Context Protocol — MCP, the open standard that lets AI models connect to tools, data sources, and each other — has passed 400 million monthly software downloads across its Tier 1 SDKs, a fourfold increase since the start of the year. Both the TypeScript and Python SDKs have crossed the 1 billion cumulative downloads threshold.

The number deserves a moment of unpacking, because download counts are usually vanity metrics. In MCP’s case they are a rough but honest proxy for something real: how many developers are actively wiring AI agents into the outside world through this one protocol. A year ago, MCP was an Anthropic-side project with a growing following. Today it is the connective tissue of the agentic ecosystem — supported natively by OpenAI, Google, and Microsoft, baked into coding agents like Claude Code, Cursor, and Codex, and deployed across thousands of production servers.

From “USB port for AI” to industry default

MCP launched in November 2024 as Anthropic’s answer to a fragmentation problem. Every AI application was inventing its own bespoke way to plug models into external systems — content repositories, business tools, APIs — and the duplication was slowing everyone down. MCP standardized that interface as a client-server protocol: a host application connects to servers that expose tools, resources, and prompts through a common contract.

Adoption compounded fast. By March 2026, the protocol’s SDKs were being downloaded 97 million times a month with more than 10,000 public servers in production. Six months later, that monthly figure has quadrupled. When competitors including OpenAI and Google build support for a protocol their rival created — rather than pushing their own alternative — that is the closest thing the platform world has to a conceded argument. The “protocol war” that looked plausible in 2025 is over, and MCP won.

Crucially, Anthropic did not keep its winnings. In December 2025, the company donated MCP to the Agentic AI Foundation, a directed fund under the Linux Foundation, moving the spec to neutral governance with open working groups and a formal proposal process. The 400-million milestone belongs as much to that community as to Anthropic.

The stateless rewrite that made it scale

The download number arrived alongside one of the most significant specification updates in the protocol’s history: the 2026-07-28 spec, now final and shipping in all four Tier 1 SDKs (TypeScript, Python, Go, C#, with Rust in beta).

The headline change is a stateless protocol core. MCP began life as a bidirectional, stateful protocol — clients and servers held open sessions, exchanged an initialize handshake, and kept a session identifier alive across calls. That design made sense for interactive desktop apps. It made much less sense for agents running as cloud workloads, where every long-lived connection is a scalability tax.

The new spec transforms MCP into a request/response protocol. Every request is self-describing, carrying its protocol version, client identity, and capabilities in _meta. The initialize/initialized handshake and Mcp-Session-Id header are retired. A new optional server/discover RPC exists for clients that want capabilities up front, but any request can now land on any server instance behind a plain round-robin load balancer — no shared storage required.

The practical consequence: MCP servers can now run on serverless and edge infrastructure. You no longer need a machine that stays online around the clock to expose a tool to an agent. That single architectural change removes one of the biggest cost and operational barriers for the long tail of MCP server authors.

The rest of the release reads like a checklist of everything operators complained about:

  • Multi Round-Trip Requests (MRTR) replace server-initiated sampling, elicitation, and roots requests that previously required held-open streams. A tool that needs user confirmation mid-call now returns input_required and the client retries with answers attached.
  • Header-based routing. Method and tool names travel in Mcp-Method and Mcp-Name HTTP headers, so gateways, rate limiters, and WAFs can route and meter without parsing JSON bodies.
  • Cacheable list results. tools/list, prompts/list, and resources/read responses now carry ttlMs and cacheScope hints, cutting redundant refetching and keeping prompt caches stable across reconnects.
  • Authorization hardening. RFC 9207 issuer validation closes an authorization-server mix-up hole; client credentials are bound to the issuer that minted them; and Dynamic Client Registration is formally deprecated in favor of Client ID Metadata Documents.
  • Tasks moves into a formal extension (io.modelcontextprotocol/tasks) with poll-based tasks/get and a new tasks/update — the protocol’s answer to long-running agent jobs.
  • A formal deprecation policy with a twelve-month minimum window, so teams can plan upgrades instead of reacting to breakage.

Why this matters more than another model release

Model releases dominate headlines, but models are converging on similar capability ceilings while the real differentiation migrates to what agents can do — which is a function of what they can reach. MCP defines that reach. When the protocol’s maintainers change its architecture, thousands of downstream vendors move with it, and when adoption quadruples in a year, the industry’s agent stack is being built on this substrate at a pace few internal standards ever achieve.

The ecosystem response to the stateless rewrite is the strongest signal. AWS shipped it inside Amazon Bedrock AgentCore and contributed the Tasks extension. Cloudflare’s Agents SDK supported the spec from day zero, letting developers run MCP servers directly in Workers — with customers like Sentry and Linear adopting on day one. Google Cloud, Figma, and others lined up behind the release with production integrations. These are not pilot programs; they are infrastructure commitments.

There are honest caveats. The 400-million figure counts SDK downloads, which includes CI pipelines and dependency resolution, not distinct developers. The stateless core introduces real migration cost for implementations that depended on session identifiers. And the spec still has open problems — the just-published maintainer roadmap names agent identity, progressive tool discovery, and unified HTTP transport as unfinished business, acknowledging that authorization “is where implementers spend most of their integration time.”

But the trajectory is unambiguous. Eighteen months after a scrappy open-standard proposal from Anthropic, MCP has become the default way the agentic world connects to everything else — governed neutrally, downloaded 400 million times a month, and now architected to run anywhere HTTP runs. The plumbing usually outlives the products built on it. By that measure, MCP just had its coming-of-age moment.

(The spec work happens in the open: SEPs are open for comment, working groups are recruiting, and the 2026-07-28 SDKs are available today across TypeScript, Python, Go, and C#.)