Home / Companies / Prefect / Blog / August 2026

August 2026 Summaries

2 posts from Prefect

Filter
Month: Year:
Post Summaries Back to Blog
FastMCP 4 is now generally available, adding support for the MCP 2026-07-28 protocol revision while preserving compatibility with older clients and allowing most FastMCP 3 applications to upgrade without code changes. The new protocol replaces connection-bound sessions with independent requests that can be handled by any server replica, while FastMCP offers configurable user- and session-based storage for applications that need persistent state. Major additions include interactive tools for collecting follow-up input, background tasks for long-running work, a negotiated extension system, argument completion, expanded authentication and authorization options, and infrastructure features such as cache hints and routing headers. The release also introduces dependency injection for tool arguments, ClientGroup for combining and routing tools across multiple MCP servers running different protocol versions, typed-output and schema improvements, faster startup, and Python 3.14 compatibility. FastMCP 4 removes server-initiated sampling and roots for the new protocol, relocates background tasks to an optional package, deprecates some older APIs and string-based local stdio client detection, and incorporates security, durability, and compatibility fixes contributed through an extended beta period.
Aug 31, 2026 1,358 words in the original blog post.
MCP authentication has evolved rapidly as the protocol expanded from trusted local servers, which generally need no authentication, to remote HTTP-based servers that require users or clients to prove their identities. The discussion distinguishes authentication, which establishes identity, from authorization, which controls permitted actions, noting that MCP focuses primarily on authentication while frameworks such as FastMCP help implement authorization policies. Early MCP guidance required server developers to operate full OAuth authorization servers, but later revisions repositioned MCP servers as protected resources that can delegate identity verification to external providers such as Okta, Google, GitHub, or self-hosted systems. Dynamic Client Registration was introduced to support agents operating from unpredictable locations but raised security and compatibility concerns, leading toward Client ID Metadata Documents, which bind client metadata to a declared URL and can restrict credential return locations. Newer work such as SEP-990 aims to support centrally managed enterprise identities and reduce repeated user sign-ins across tools. FastMCP provides OAuth proxying to connect MCP-compatible flows with conventional identity providers, issues its own tokens rather than exposing provider credentials, and can use trusted token roles and claims to hide or gate tools based on permissions. Horizon extends this model by federating identities across multiple MCP servers through a gateway, while the unresolved challenge remains defining secure identities and permissions for autonomous agents that should not necessarily inherit all of a human user’s access.
Aug 20, 2026 3,469 words in the original blog post.