Home / Companies / WorkOS / Blog / Post Details
Content Deep Dive

How to build an MCP app on the 2026-07-28 spec with WorkOS AuthKit

Blog post from WorkOS

Post Details
Company
Date Published
Author
Maria Paktiti
Word Count
1,440
Company Posts That Month
44
Language
English
Hacker News Points
-
Post removed?
No
Summary

On July 28, 2026, the MCP protocol was finalized, transitioning to a stateless core, which enhances authorization to align with OAuth 2.1 and OIDC standards and officially introduces MCP Apps and Tasks as part of a versioned extensions framework. These changes eliminate the need for session-based transport, allowing any server instance to handle requests efficiently without session persistence. This update emphasizes a closer alignment with real OAuth practices, requiring MCP servers to implement OAuth 2.1 features like Protected Resource Metadata and Resource Indicators to ensure secure and specific token usage. A small internal tool example, an expense approval board, demonstrates the practical application of these principles by enabling stateless deployment, enforcing permissions per tool with WorkOS AuthKit, and ensuring secure authorization at the handler level rather than the UI. This approach highlights the significance of integrating both UI and authorization measures in a stateless environment, providing a comprehensive model that stands apart from previous session-based methods.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 19 7,781 805 204 +0%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.