Home / Companies / WorkOS / Blog / Post Details
Content Deep Dive

How to build a stateless MCP server on 2026-07-28, secured with AuthKit

Blog post from WorkOS

Post Details
Company
Date Published
Author
Maria Paktiti
Word Count
1,174
Company Posts That Month
44
Language
English
Hacker News Points
-
Post removed?
No
Summary

MCP 2026-07-28 introduces significant changes to the protocol, emphasizing a stateless server design with enhanced security features through the integration of OAuth 2.1 and AuthKit as the authorization server. This update separates the roles of the MCP server as the resource server responsible for verifying bearer tokens, and AuthKit, which handles login, consent, token issuance, and the JWKS endpoint. The protocol allows for stateless transport, eliminating the need for sticky sessions and enabling server deployment behind load balancers or on serverless architectures. To comply with the new specifications, servers must publish resource metadata and verify tokens on every request, moving away from session-dependent state management to explicit handles. The shift from Dynamic Client Registration to Client ID Metadata Document ensures streamlined client identification, while maintaining backward compatibility. These changes aim to improve scalability and security by removing session dependencies and ensuring precise token verification.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 29 7,781 805 204 +0%
Serverless 1 747 240 95 -27%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.