How to build an MCP app on the 2026-07-28 spec with WorkOS AuthKit
Blog post from WorkOS
On July 28, 2026, the MCP protocol was finalized, transitioning to a stateless core, which enhances authorization to align with OAuth 2.1 and OIDC standards and officially introduces MCP Apps and Tasks as part of a versioned extensions framework. These changes eliminate the need for session-based transport, allowing any server instance to handle requests efficiently without session persistence. This update emphasizes a closer alignment with real OAuth practices, requiring MCP servers to implement OAuth 2.1 features like Protected Resource Metadata and Resource Indicators to ensure secure and specific token usage. A small internal tool example, an expense approval board, demonstrates the practical application of these principles by enabling stateless deployment, enforcing permissions per tool with WorkOS AuthKit, and ensuring secure authorization at the handler level rather than the UI. This approach highlights the significance of integrating both UI and authorization measures in a stateless environment, providing a comprehensive model that stands apart from previous session-based methods.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 19 | 7,781 | 805 | 204 | +0% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.