MCP Authorization Spec 2026-07-28: What Changed and What Breaks
Blog post from SSOJet
MCP revision 2026-07-28 updates authorization by deprecating OAuth Dynamic Client Registration (DCR) in favor of Client ID Metadata Documents, requiring clients to validate any present authorization-response issuer (`iss`) against the recorded issuer before code redemption, and requiring stored credentials to be bound to the authorization server issuer. DCR remains supported for backward compatibility under a minimum 12-month deprecation period, but clients using it must explicitly set an appropriate `application_type`, while Client ID Metadata Documents offer portable client identities that do not require re-registration across authorization servers. The revision also removes protocol-level sessions, the `Mcp-Session-Id` header, initialization handshakes, and stream resumability, making MCP stateless and requiring each request to supply version and capability metadata as well as authorization. Servers must implement `server/discover` to advertise supported protocol versions, capabilities, and identity, while clients should account for per-request version negotiation and retry requests with new identifiers after interrupted streams. The guide recommends prioritizing exact `iss` validation, issuer-based credential storage, DCR configuration fixes, and adaptation to stateless operation before transitioning registration flows to Client ID Metadata Documents.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 35 | 5,396 | 444 | 162 | +6% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.