MCP's New 2026 Roadmap: What AI Agencies Need to Know
Model Context Protocol's maintainers published a new roadmap covering agent identity, transport, and tool design. Here's what it means for AI builders.
If your team connects Claude, ChatGPT, or any coding agent to external tools, databases, or APIs, there's a good chance Model Context Protocol (MCP) is quietly doing the wiring. On August 22, MCP's Lead Maintainers, David Soria Parra and Den Delimarsky, published an updated roadmap setting direction for the protocol's next specification release and beyond. It landed on Hacker News' front page the same day with over 170 points and more than 120 comments — a strong signal that the developers building on top of MCP are paying close attention to where it's headed.
MCP's governance has shifted toward Working Groups and Interest Groups as the primary way the protocol evolves, and this roadmap is the Core Maintainers' attempt to give that community a clear, shared set of priorities. It's organized around five focus areas, several of which graduated from "on the horizon" items in the previous roadmap into full priorities now that the underlying work has matured.
Agentic messaging primitives address a real limitation: agent workloads don't fit the simple request-and-response pattern anymore. Work can run long, servers need to push results back mid-task, and clients shouldn't have to keep polling to find out what happened. MCP has already introduced Tasks, subscription-based listening, and progress notifications to handle this, and the roadmap commits to server-initiated events (webhooks and channels) and maturing the Tasks extension toward full inclusion in the spec.
HTTP-native transport unification builds on MCP's 2026-07-28 release, which made a remote MCP server indistinguishable from any other HTTP workload — meaning it can run on whatever infrastructure a team already uses for its APIs. The next step is extending that same simplicity to local servers, unifying how local and remote deployments speak to clients.
Agent identity and enterprise-ready security is arguably the most consequential item for teams operating at scale. Today's MCP authorization model assumes a human is in the browser approving access. But a growing share of MCP callers are agents running as unattended cloud workloads, acting on a user's behalf, or delegating to sub-agents. The roadmap commits to finalizing Demonstrating Proof of Possession (DPoP) and building a standardized path for agent identity and delegation through Workload Identity Federation — replacing pasted API keys and long-lived tokens with something an enterprise security team can actually audit.
Improved primitives tackles a subtler but common pain point: a tool call's response can come back in more than one shape, and server developers currently have no reliable way to know which shape a given client expects. The roadmap also addresses a scaling problem — connecting to a server with a hundred tools means a model pays the token cost of that entire tool surface before a user asks anything, which degrades tool selection. A "progressive discovery" effort aims to let servers expose a small entry point and reveal more of their catalog as a conversation narrows.
Improved SDK developer experience rounds out the list, focused on conformance testing and documentation quality — increasingly important now that many developers are building MCP clients and servers by pointing a coding agent at the SDKs directly, rather than reading docs themselves.
For teams building client work or internal tooling on top of MCP servers, this roadmap is a preview of what to plan around over the next several months. The identity and authorization work in particular is worth flagging early to any client asking about running unattended agents against sensitive systems — the current browser-approval model wasn't built for that, and the fix is now an explicit, funded priority rather than a wishlist item. The transport and tool-surface work is more immediately practical: if you're building or maintaining MCP servers with large tool catalogs, progressive discovery is a direct answer to the "too many tools confuse the model" problem agencies run into constantly.
MCP's governance is genuinely open. Anyone can join a relevant Working Group, propose or comment on a Specification Enhancement Proposal (SEP), or start an experimental extension without waiting for a formal SEP to land. Proposals that fall within one of the five roadmap areas get expedited review, so teams with a specific pain point are better served aligning their proposal to the roadmap than submitting something adjacent to it.
MCP's Core Maintainers published a new roadmap on August 22, organized around five priorities: agentic messaging, HTTP-native transport, agent identity and security, improved tool primitives, and SDK developer experience.
Agent identity and enterprise-ready authorization is the area most likely to affect agencies running unattended agents against client systems — it's moving from ad hoc API keys toward standardized, auditable delegation.
A "progressive tool discovery" effort directly targets the practical problem of large MCP tool catalogs degrading model performance.
The roadmap process is genuinely open to outside contributors, and proposals aligned to one of the five stated priorities get faster review.
Our cutting-edge features simplify collaboration and creativity, making your workflow intuitive and efficient. Transform your vision into reality effortlessly with Hadidiz Flow.



