One read of Model Context Protocolmcp-20260928T220720Z
173 pages moved out of 349 read.
Pages moved
173
significant first
Pages read
349
in this capture
Captured
22:07 UTC
Corpus hash
719057065235
corpus-hash
What this read moved
126-150 of 173, page 6 of 7This capture is too large to show at once. Changes 126-150 of 173 are below, significant first; the rest are on the following screens.
seps/994-shared-communication-practicesguidelines Changed · +10 / -10 lines
from line 20
2020 requirements.
2121</Note>
2222
23| Field | Value |
24| ------------- | ------------------------------------------------------------------------------- |
25| **SEP** | 994 |
26| **Title** | Shared Communication Practices/Guidelines |
27| **Status** | Final |
28| **Type** | Process |
29| **Created** | 2025-07-17 |
30| **Author(s)** | [@localden](https://github.com/localden) |
31| **Sponsor** | None |
32| **PR** | [#1002](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/1002) |
23| Field | Value |
24| - | - |
25| **SEP** | 994 |
26| **Title** | Shared Communication Practices/Guidelines |
27| **Status** | Final |
28| **Type** | Process |
29| **Created** | 2025-07-17 |
30| **Author(s)** | [@localden](https://github.com/localden) |
31| **Sponsor** | None |
32| **PR** | [#1002](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/1002) |
3333
3434***
3535
seps/index Changed · +56 / -54 lines
from line 4
44
55Specification Enhancement Proposals (SEPs) are the primary mechanism for proposing major changes to the Model Context Protocol. Each SEP provides a concise technical specification and rationale for proposed features.
66
7Each SEP is reachable by number at `/seps/<number>` (for example, [/seps/1850](/seps/1850)).
8
79<Card title="Submit a SEP" icon="file-plus" href="/community/sep-guidelines">
810 Learn how to submit your own Specification Enhancement Proposal
911</Card>
from line 16
1416
1517## All SEPs
1618
17| SEP | Title | Status | Type | Created |
18| ------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------- | ----------------------------------------------- | ---------------- | ---------- |
19| [SEP-2663](/seps/2663-tasks-extension) | Tasks Extension | <Badge color="green" shape="pill">Final</Badge> | Extensions Track | 2026-04-27 |
20| [SEP-2640](/seps/2640-skills-extension) | Skills Extension | <Badge color="green" shape="pill">Final</Badge> | Extensions Track | 2026-04-23 |
21| [SEP-2596](/seps/2596-spec-feature-lifecycle-and-deprecation) | Specification Feature Lifecycle and Deprecation Policy | <Badge color="green" shape="pill">Final</Badge> | Process | 2026-04-17 |
22| [SEP-2577](/seps/2577-deprecate-roots-sampling-and-logging) | Deprecate Roots, Sampling, and Logging | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-04-14 |
23| [SEP-2575](/seps/2575-stateless-mcp) | Make MCP Stateless | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-06-18 |
24| [SEP-2567](/seps/2567-sessionless-mcp) | Sessionless MCP via Explicit State Handles | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-03-11 |
25| [SEP-2549](/seps/2549-TTL-for-list-results) | TTL for List Results | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-04-09 |
26| [SEP-2484](/seps/2484-conformance-tests-required-for-final-seps) | Require Conformance Tests for Standards Track SEPs to Reach Final Status | <Badge color="green" shape="pill">Final</Badge> | Process | 2026-03-27 |
27| [SEP-2468](/seps/2468-recommend-issuer-claim-for-auth) | Recommend Issuer (iss) Parameter in MCP Auth Responses | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-03-25 |
28| [SEP-2322](/seps/2322-MRTR) | Multi Round-Trip Requests | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-02-03 |
29| [SEP-2260](/seps/2260-Require-Server-requests-to-be-associated-with-Client-requests) | Require Server requests to be associated with a Client request. | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-02-16 |
30| [SEP-2243](/seps/2243-http-standardization) | HTTP Header Standardization for Streamable HTTP Transport | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-02-04 |
31| [SEP-2207](/seps/2207-oidc-refresh-token-guidance) | OIDC-Flavored Refresh Token Guidance | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-02-04 |
32| [SEP-2164](/seps/2164-resource-not-found-error) | Standardize Resource Not Found Error Code | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-01-28 |
33| [SEP-2149](/seps/2149-working-group-charter-template) | MCP Group Governance and Charter Template | <Badge color="green" shape="pill">Final</Badge> | Process | 2025-01-15 |
34| [SEP-2148](/seps/2148-contributor-ladder) | MCP Contributor Ladder | <Badge color="green" shape="pill">Final</Badge> | Process | 2026-01-15 |
35| [SEP-2133](/seps/2133-extensions) | Extensions | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-01-21 |
36| [SEP-2106](/seps/2106-json-schema-2020-12) | Tools `inputSchema` & `outputSchema` Conform to JSON Schema 2020-12 | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-01-06 |
37| [SEP-2085](/seps/2085-governance-succession-and-amendment) | Governance Succession and Amendment Procedures | <Badge color="green" shape="pill">Final</Badge> | Process | 2025-12-05 |
38| [SEP-1865](/seps/1865-mcp-apps-interactive-user-interfaces-for-mcp) | MCP Apps - Interactive User Interfaces for MCP | <Badge color="green" shape="pill">Final</Badge> | Extensions Track | 2025-11-21 |
39| [SEP-1850](/seps/1850-pr-based-sep-workflow) | PR-Based SEP Workflow | <Badge color="green" shape="pill">Final</Badge> | Process | 2025-11-20 |
40| [SEP-1730](/seps/1730-sdks-tiering-system) | SDKs Tiering System | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-10-29 |
41| [SEP-1699](/seps/1699-support-sse-polling-via-server-side-disconnect) | Support SSE polling via server-side disconnect | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-10-22 |
42| [SEP-1686](/seps/1686-tasks) | Tasks | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-10-20 |
43| [SEP-1613](/seps/1613-establish-json-schema-2020-12-as-default-dialect-f) | Establish JSON Schema 2020-12 as Default Dialect for MCP | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-10-06 |
44| [SEP-1577](/seps/1577--sampling-with-tools) | Sampling With Tools | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-09-30 |
45| [SEP-1330](/seps/1330-elicitation-enum-schema-improvements-and-standards) | Elicitation Enum Schema Improvements and Standards Compliance | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-08-11 |
46| [SEP-1319](/seps/1319-decouple-request-payload-from-rpc-methods-definiti) | Decouple Request Payload from RPC Methods Definition | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-08-08 |
47| [SEP-1303](/seps/1303-input-validation-errors-as-tool-execution-errors) | Input Validation Errors as Tool Execution Errors | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-08-05 |
48| [SEP-1302](/seps/1302-formalize-working-groups-and-interest-groups-in-mc) | Formalize Working Groups and Interest Groups in MCP Governance | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-08-05 |
49| [SEP-1046](/seps/1046-support-oauth-client-credentials-flow-in-authoriza) | Support OAuth client credentials flow in authorization | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-23 |
50| [SEP-1036](/seps/1036-url-mode-elicitation-for-secure-out-of-band-intera) | URL Mode Elicitation for secure out-of-band interactions | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-22 |
51| [SEP-1034](/seps/1034--support-default-values-for-all-primitive-types-in) | Support default values for all primitive types in elicitation schemas | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-22 |
52| [SEP-1024](/seps/1024-mcp-client-security-requirements-for-local-server-) | MCP Client Security Requirements for Local Server Installation | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-22 |
53| [SEP-994](/seps/994-shared-communication-practicesguidelines) | Shared Communication Practices/Guidelines | <Badge color="green" shape="pill">Final</Badge> | Process | 2025-07-17 |
54| [SEP-991](/seps/991-enable-url-based-client-registration-using-oauth-c) | Enable URL-based Client Registration using OAuth Client ID Metadata Documents | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-07 |
55| [SEP-990](/seps/990-enable-enterprise-idp-policy-controls-during-mcp-o) | Enable enterprise IdP policy controls during MCP OAuth flows | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-06-04 |
56| [SEP-986](/seps/986-specify-format-for-tool-names) | Specify Format for Tool Names | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-16 |
57| [SEP-985](/seps/985-align-oauth-20-protected-resource-metadata-with-rf) | Align OAuth 2.0 Protected Resource Metadata with RFC 9728 | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-16 |
58| [SEP-973](/seps/973-expose-additional-metadata-for-implementations-res) | Expose additional metadata for Implementations, Resources, Tools and Prompts | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-15 |
59| [SEP-932](/seps/932-model-context-protocol-governance) | Model Context Protocol Governance | <Badge color="green" shape="pill">Final</Badge> | Process | 2025-07-08 |
60| [SEP-414](/seps/414-request-meta) | Document OpenTelemetry Trace Context Propagation Conventions | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-04-25 |
19| SEP | Title | Status | Type | Created |
20| - | - | - | - | - |
21| [SEP-2663](/seps/2663-tasks-extension) | Tasks Extension | <Badge color="green" shape="pill">Final</Badge> | Extensions Track | 2026-04-27 |
22| [SEP-2640](/seps/2640-skills-extension) | Skills Extension | <Badge color="green" shape="pill">Final</Badge> | Extensions Track | 2026-04-23 |
23| [SEP-2596](/seps/2596-spec-feature-lifecycle-and-deprecation) | Specification Feature Lifecycle and Deprecation Policy | <Badge color="green" shape="pill">Final</Badge> | Process | 2026-04-17 |
24| [SEP-2577](/seps/2577-deprecate-roots-sampling-and-logging) | Deprecate Roots, Sampling, and Logging | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-04-14 |
25| [SEP-2575](/seps/2575-stateless-mcp) | Make MCP Stateless | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-06-18 |
26| [SEP-2567](/seps/2567-sessionless-mcp) | Sessionless MCP via Explicit State Handles | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-03-11 |
27| [SEP-2549](/seps/2549-TTL-for-list-results) | TTL for List Results | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-04-09 |
28| [SEP-2484](/seps/2484-conformance-tests-required-for-final-seps) | Require Conformance Tests for Standards Track SEPs to Reach Final Status | <Badge color="green" shape="pill">Final</Badge> | Process | 2026-03-27 |
29| [SEP-2468](/seps/2468-recommend-issuer-claim-for-auth) | Recommend Issuer (iss) Parameter in MCP Auth Responses | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-03-25 |
30| [SEP-2322](/seps/2322-MRTR) | Multi Round-Trip Requests | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-02-03 |
31| [SEP-2260](/seps/2260-Require-Server-requests-to-be-associated-with-Client-requests) | Require Server requests to be associated with a Client request. | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-02-16 |
32| [SEP-2243](/seps/2243-http-standardization) | HTTP Header Standardization for Streamable HTTP Transport | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-02-04 |
33| [SEP-2207](/seps/2207-oidc-refresh-token-guidance) | OIDC-Flavored Refresh Token Guidance | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-02-04 |
34| [SEP-2164](/seps/2164-resource-not-found-error) | Standardize Resource Not Found Error Code | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-01-28 |
35| [SEP-2149](/seps/2149-working-group-charter-template) | MCP Group Governance and Charter Template | <Badge color="green" shape="pill">Final</Badge> | Process | 2025-01-15 |
36| [SEP-2148](/seps/2148-contributor-ladder) | MCP Contributor Ladder | <Badge color="green" shape="pill">Final</Badge> | Process | 2026-01-15 |
37| [SEP-2133](/seps/2133-extensions) | Extensions | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-01-21 |
38| [SEP-2106](/seps/2106-json-schema-2020-12) | Tools `inputSchema` & `outputSchema` Conform to JSON Schema 2020-12 | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2026-01-06 |
39| [SEP-2085](/seps/2085-governance-succession-and-amendment) | Governance Succession and Amendment Procedures | <Badge color="green" shape="pill">Final</Badge> | Process | 2025-12-05 |
40| [SEP-1865](/seps/1865-mcp-apps-interactive-user-interfaces-for-mcp) | MCP Apps - Interactive User Interfaces for MCP | <Badge color="green" shape="pill">Final</Badge> | Extensions Track | 2025-11-21 |
41| [SEP-1850](/seps/1850-pr-based-sep-workflow) | PR-Based SEP Workflow | <Badge color="green" shape="pill">Final</Badge> | Process | 2025-11-20 |
42| [SEP-1730](/seps/1730-sdks-tiering-system) | SDKs Tiering System | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-10-29 |
43| [SEP-1699](/seps/1699-support-sse-polling-via-server-side-disconnect) | Support SSE polling via server-side disconnect | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-10-22 |
44| [SEP-1686](/seps/1686-tasks) | Tasks | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-10-20 |
45| [SEP-1613](/seps/1613-establish-json-schema-2020-12-as-default-dialect-f) | Establish JSON Schema 2020-12 as Default Dialect for MCP | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-10-06 |
46| [SEP-1577](/seps/1577--sampling-with-tools) | Sampling With Tools | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-09-30 |
47| [SEP-1330](/seps/1330-elicitation-enum-schema-improvements-and-standards) | Elicitation Enum Schema Improvements and Standards Compliance | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-08-11 |
48| [SEP-1319](/seps/1319-decouple-request-payload-from-rpc-methods-definiti) | Decouple Request Payload from RPC Methods Definition | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-08-08 |
49| [SEP-1303](/seps/1303-input-validation-errors-as-tool-execution-errors) | Input Validation Errors as Tool Execution Errors | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-08-05 |
50| [SEP-1302](/seps/1302-formalize-working-groups-and-interest-groups-in-mc) | Formalize Working Groups and Interest Groups in MCP Governance | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-08-05 |
51| [SEP-1046](/seps/1046-support-oauth-client-credentials-flow-in-authoriza) | Support OAuth client credentials flow in authorization | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-23 |
52| [SEP-1036](/seps/1036-url-mode-elicitation-for-secure-out-of-band-intera) | URL Mode Elicitation for secure out-of-band interactions | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-22 |
53| [SEP-1034](/seps/1034--support-default-values-for-all-primitive-types-in) | Support default values for all primitive types in elicitation schemas | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-22 |
54| [SEP-1024](/seps/1024-mcp-client-security-requirements-for-local-server-) | MCP Client Security Requirements for Local Server Installation | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-22 |
55| [SEP-994](/seps/994-shared-communication-practicesguidelines) | Shared Communication Practices/Guidelines | <Badge color="green" shape="pill">Final</Badge> | Process | 2025-07-17 |
56| [SEP-991](/seps/991-enable-url-based-client-registration-using-oauth-c) | Enable URL-based Client Registration using OAuth Client ID Metadata Documents | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-07 |
57| [SEP-990](/seps/990-enable-enterprise-idp-policy-controls-during-mcp-o) | Enable enterprise IdP policy controls during MCP OAuth flows | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-06-04 |
58| [SEP-986](/seps/986-specify-format-for-tool-names) | Specify Format for Tool Names | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-16 |
59| [SEP-985](/seps/985-align-oauth-20-protected-resource-metadata-with-rf) | Align OAuth 2.0 Protected Resource Metadata with RFC 9728 | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-16 |
60| [SEP-973](/seps/973-expose-additional-metadata-for-implementations-res) | Expose additional metadata for Implementations, Resources, Tools and Prompts | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-07-15 |
61| [SEP-932](/seps/932-model-context-protocol-governance) | Model Context Protocol Governance | <Badge color="green" shape="pill">Final</Badge> | Process | 2025-07-08 |
62| [SEP-414](/seps/414-request-meta) | Document OpenTelemetry Trace Context Propagation Conventions | <Badge color="green" shape="pill">Final</Badge> | Standards Track | 2025-04-25 |
6163
6264## SEP Status Definitions
6365
64| Status | Definition |
65| ----------------------------------------------------- | -------------------------------------------------------- |
66| <Badge color="gray" shape="pill">Draft</Badge> | SEP proposal with a sponsor, undergoing informal review |
67| <Badge color="yellow" shape="pill">In-Review</Badge> | SEP proposal ready for formal review by Core Maintainers |
68| <Badge color="blue" shape="pill">Accepted</Badge> | SEP accepted, awaiting reference implementation |
69| <Badge color="green" shape="pill">Final</Badge> | SEP finalized with reference implementation complete |
70| <Badge color="red" shape="pill">Rejected</Badge> | SEP rejected by Core Maintainers |
71| <Badge color="red" shape="pill">Withdrawn</Badge> | SEP withdrawn by the author |
72| <Badge color="purple" shape="pill">Superseded</Badge> | SEP replaced by a newer SEP |
73| <Badge color="orange" shape="pill">Dormant</Badge> | SEP without a sponsor, closed after 6 months |
66| Status | Definition |
67| - | - |
68| <Badge color="gray" shape="pill">Draft</Badge> | SEP proposal with a sponsor, undergoing informal review |
69| <Badge color="yellow" shape="pill">In-Review</Badge> | SEP proposal ready for formal review by Core Maintainers |
70| <Badge color="blue" shape="pill">Accepted</Badge> | SEP accepted, awaiting reference implementation |
71| <Badge color="green" shape="pill">Final</Badge> | SEP finalized with reference implementation complete |
72| <Badge color="red" shape="pill">Rejected</Badge> | SEP rejected by Core Maintainers |
73| <Badge color="red" shape="pill">Withdrawn</Badge> | SEP withdrawn by the author |
74| <Badge color="purple" shape="pill">Superseded</Badge> | SEP replaced by a newer SEP |
75| <Badge color="orange" shape="pill">Dormant</Badge> | SEP without a sponsor, closed after 6 months |
7476
specification/2024-11-05/basic/index Changed · +5 / -5 lines
from line 4
44[JSON-RPC 2.0](https://www.jsonrpc.org/specification) specification. The protocol defines
55three fundamental types of messages:
66
7| Type | Description | Requirements |
8| --------------- | -------------------------------------- | -------------------------------------- |
9| `Requests` | Messages sent to initiate an operation | Must include unique ID and method name |
10| `Responses` | Messages sent in reply to requests | Must include same ID as request |
11| `Notifications` | One-way messages with no reply | Must not include an ID |
7| Type | Description | Requirements |
8| - | - | - |
9| `Requests` | Messages sent to initiate an operation | Must include unique ID and method name |
10| `Responses` | Messages sent in reply to requests | Must include same ID as request |
11| `Notifications` | One-way messages with no reply | Must not include an ID |
1212
1313**Responses** are further sub-categorized as either **successful results** or **errors**.
1414Results can follow any JSON object structure, while errors must include an error code and
specification/2024-11-05/basic/lifecycle Changed · +10 / -10 lines
from line 133
133133
134134Key capabilities include:
135135
136| Category | Capability | Description |
137| -------- | -------------- | ----------------------------------------------------------------------------------- |
138| Client | `roots` | Ability to provide filesystem [roots](/specification/2024-11-05/client/roots) |
139| Client | `sampling` | Support for LLM [sampling](/specification/2024-11-05/client/sampling) requests |
140| Client | `experimental` | Describes support for non-standard experimental features |
141| Server | `prompts` | Offers [prompt templates](/specification/2024-11-05/server/prompts) |
142| Server | `resources` | Provides readable [resources](/specification/2024-11-05/server/resources) |
143| Server | `tools` | Exposes callable [tools](/specification/2024-11-05/server/tools) |
144| Server | `logging` | Emits structured [log messages](/specification/2024-11-05/server/utilities/logging) |
145| Server | `experimental` | Describes support for non-standard experimental features |
136| Category | Capability | Description |
137| - | - | - |
138| Client | `roots` | Ability to provide filesystem [roots](/specification/2024-11-05/client/roots) |
139| Client | `sampling` | Support for LLM [sampling](/specification/2024-11-05/client/sampling) requests |
140| Client | `experimental` | Describes support for non-standard experimental features |
141| Server | `prompts` | Offers [prompt templates](/specification/2024-11-05/server/prompts) |
142| Server | `resources` | Provides readable [resources](/specification/2024-11-05/server/resources) |
143| Server | `tools` | Exposes callable [tools](/specification/2024-11-05/server/tools) |
144| Server | `logging` | Emits structured [log messages](/specification/2024-11-05/server/utilities/logging) |
145| Server | `experimental` | Describes support for non-standard experimental features |
146146
147147Capability objects can describe sub-capabilities like:
148148
specification/2024-11-05/server/index Changed · +5 / -5 lines
from line 12
1212
1313Each primitive can be summarized in the following control hierarchy:
1414
15| Primitive | Control | Description | Example |
16| --------- | ---------------------- | -------------------------------------------------- | ------------------------------- |
17| Prompts | User-controlled | Interactive templates invoked by user choice | Slash commands, menu options |
18| Resources | Application-controlled | Contextual data attached and managed by the client | File contents, git history |
19| Tools | Model-controlled | Functions exposed to the LLM to take actions | API POST requests, file writing |
15| Primitive | Control | Description | Example |
16| - | - | - | - |
17| Prompts | User-controlled | Interactive templates invoked by user choice | Slash commands, menu options |
18| Resources | Application-controlled | Contextual data attached and managed by the client | File contents, git history |
19| Tools | Model-controlled | Functions exposed to the LLM to take actions | API POST requests, file writing |
2020
2121Explore these key primitives in more detail below:
2222
specification/2024-11-05/server/utilities/completion Changed · +4 / -4 lines
from line 64
6464
6565The protocol supports two types of completion references:
6666
67| Type | Description | Example |
68| -------------- | --------------------------- | --------------------------------------------------- |
69| `ref/prompt` | References a prompt by name | `{"type": "ref/prompt", "name": "code_review"}` |
70| `ref/resource` | References a resource URI | `{"type": "ref/resource", "uri": "file:///{path}"}` |
67| Type | Description | Example |
68| - | - | - |
69| `ref/prompt` | References a prompt by name | `{"type": "ref/prompt", "name": "code_review"}` |
70| `ref/resource` | References a resource URI | `{"type": "ref/resource", "uri": "file:///{path}"}` |
7171
7272### Completion Results
7373
specification/2024-11-05/server/utilities/logging Changed · +10 / -10 lines
from line 27
2727The protocol follows the standard syslog severity levels specified in
2828[RFC 5424](https://datatracker.ietf.org/doc/html/rfc5424#section-6.2.1):
2929
30| Level | Description | Example Use Case |
31| --------- | -------------------------------- | -------------------------- |
32| debug | Detailed debugging information | Function entry/exit points |
33| info | General informational messages | Operation progress updates |
34| notice | Normal but significant events | Configuration changes |
35| warning | Warning conditions | Deprecated feature usage |
36| error | Error conditions | Operation failures |
37| critical | Critical conditions | System component failures |
38| alert | Action must be taken immediately | Data corruption detected |
39| emergency | System is unusable | Complete system failure |
30| Level | Description | Example Use Case |
31| - | - | - |
32| debug | Detailed debugging information | Function entry/exit points |
33| info | General informational messages | Operation progress updates |
34| notice | Normal but significant events | Configuration changes |
35| warning | Warning conditions | Deprecated feature usage |
36| error | Error conditions | Operation failures |
37| critical | Critical conditions | System component failures |
38| alert | Action must be taken immediately | Data corruption detected |
39| emergency | System is unusable | Complete system failure |
4040
4141## Protocol Messages
4242
specification/2025-03-26/basic/authorization Changed · +10 / -10 lines
from line 156
156156**MUST** use the following default endpoint paths relative to the [authorization base
157157URL](#authorization-base-url):
158158
159| Endpoint | Default Path | Description |
160| ---------------------- | ------------ | ------------------------------------ |
161| Authorization Endpoint | /authorize | Used for authorization requests |
162| Token Endpoint | /token | Used for token exchange & refresh |
163| Registration Endpoint | /register | Used for dynamic client registration |
159| Endpoint | Default Path | Description |
160| - | - | - |
161| Authorization Endpoint | /authorize | Used for authorization requests |
162| Token Endpoint | /token | Used for token exchange & refresh |
163| Registration Endpoint | /register | Used for dynamic client registration |
164164
165165For example, with an MCP server hosted at `https://api.example.com/v1/mcp`, the default
166166endpoints would be:
from line 304
304304
305305Servers **MUST** return appropriate HTTP status codes for authorization errors:
306306
307| Status Code | Description | Usage |
308| ----------- | ------------ | ------------------------------------------ |
309| 401 | Unauthorized | Authorization required or token invalid |
310| 403 | Forbidden | Invalid scopes or insufficient permissions |
311| 400 | Bad Request | Malformed authorization request |
307| Status Code | Description | Usage |
308| - | - | - |
309| 401 | Unauthorized | Authorization required or token invalid |
310| 403 | Forbidden | Invalid scopes or insufficient permissions |
311| 400 | Bad Request | Malformed authorization request |
312312
313313### Implementation Requirements
314314
specification/2025-03-26/basic/lifecycle Changed · +11 / -11 lines
from line 140
140140
141141Key capabilities include:
142142
143| Category | Capability | Description |
144| -------- | -------------- | ----------------------------------------------------------------------------------------- |
145| Client | `roots` | Ability to provide filesystem [roots](/specification/2025-03-26/client/roots) |
146| Client | `sampling` | Support for LLM [sampling](/specification/2025-03-26/client/sampling) requests |
147| Client | `experimental` | Describes support for non-standard experimental features |
148| Server | `prompts` | Offers [prompt templates](/specification/2025-03-26/server/prompts) |
149| Server | `resources` | Provides readable [resources](/specification/2025-03-26/server/resources) |
150| Server | `tools` | Exposes callable [tools](/specification/2025-03-26/server/tools) |
151| Server | `logging` | Emits structured [log messages](/specification/2025-03-26/server/utilities/logging) |
152| Server | `completions` | Supports argument [autocompletion](/specification/2025-03-26/server/utilities/completion) |
153| Server | `experimental` | Describes support for non-standard experimental features |
143| Category | Capability | Description |
144| - | - | - |
145| Client | `roots` | Ability to provide filesystem [roots](/specification/2025-03-26/client/roots) |
146| Client | `sampling` | Support for LLM [sampling](/specification/2025-03-26/client/sampling) requests |
147| Client | `experimental` | Describes support for non-standard experimental features |
148| Server | `prompts` | Offers [prompt templates](/specification/2025-03-26/server/prompts) |
149| Server | `resources` | Provides readable [resources](/specification/2025-03-26/server/resources) |
150| Server | `tools` | Exposes callable [tools](/specification/2025-03-26/server/tools) |
151| Server | `logging` | Emits structured [log messages](/specification/2025-03-26/server/utilities/logging) |
152| Server | `completions` | Supports argument [autocompletion](/specification/2025-03-26/server/utilities/completion) |
153| Server | `experimental` | Describes support for non-standard experimental features |
154154
155155Capability objects can describe sub-capabilities like:
156156
specification/2025-03-26/server/index Changed · +5 / -5 lines
from line 12
1212
1313Each primitive can be summarized in the following control hierarchy:
1414
15| Primitive | Control | Description | Example |
16| --------- | ---------------------- | -------------------------------------------------- | ------------------------------- |
17| Prompts | User-controlled | Interactive templates invoked by user choice | Slash commands, menu options |
18| Resources | Application-controlled | Contextual data attached and managed by the client | File contents, git history |
19| Tools | Model-controlled | Functions exposed to the LLM to take actions | API POST requests, file writing |
15| Primitive | Control | Description | Example |
16| - | - | - | - |
17| Prompts | User-controlled | Interactive templates invoked by user choice | Slash commands, menu options |
18| Resources | Application-controlled | Contextual data attached and managed by the client | File contents, git history |
19| Tools | Model-controlled | Functions exposed to the LLM to take actions | API POST requests, file writing |
2020
2121Explore these key primitives in more detail below:
2222
specification/2025-03-26/server/utilities/completion Changed · +4 / -4 lines
from line 76
7676
7777The protocol supports two types of completion references:
7878
79| Type | Description | Example |
80| -------------- | --------------------------- | --------------------------------------------------- |
81| `ref/prompt` | References a prompt by name | `{"type": "ref/prompt", "name": "code_review"}` |
82| `ref/resource` | References a resource URI | `{"type": "ref/resource", "uri": "file:///{path}"}` |
79| Type | Description | Example |
80| - | - | - |
81| `ref/prompt` | References a prompt by name | `{"type": "ref/prompt", "name": "code_review"}` |
82| `ref/resource` | References a resource URI | `{"type": "ref/resource", "uri": "file:///{path}"}` |
8383
8484### Completion Results
8585
specification/2025-03-26/server/utilities/logging Changed · +10 / -10 lines
from line 27
2727The protocol follows the standard syslog severity levels specified in
2828[RFC 5424](https://datatracker.ietf.org/doc/html/rfc5424#section-6.2.1):
2929
30| Level | Description | Example Use Case |
31| --------- | -------------------------------- | -------------------------- |
32| debug | Detailed debugging information | Function entry/exit points |
33| info | General informational messages | Operation progress updates |
34| notice | Normal but significant events | Configuration changes |
35| warning | Warning conditions | Deprecated feature usage |
36| error | Error conditions | Operation failures |
37| critical | Critical conditions | System component failures |
38| alert | Action must be taken immediately | Data corruption detected |
39| emergency | System is unusable | Complete system failure |
30| Level | Description | Example Use Case |
31| - | - | - |
32| debug | Detailed debugging information | Function entry/exit points |
33| info | General informational messages | Operation progress updates |
34| notice | Normal but significant events | Configuration changes |
35| warning | Warning conditions | Deprecated feature usage |
36| error | Error conditions | Operation failures |
37| critical | Critical conditions | System component failures |
38| alert | Action must be taken immediately | Data corruption detected |
39| emergency | System is unusable | Complete system failure |
4040
4141## Protocol Messages
4242
specification/2025-06-18/basic/authorization Changed · +5 / -5 lines
from line 276
276276
277277Servers **MUST** return appropriate HTTP status codes for authorization errors:
278278
279| Status Code | Description | Usage |
280| ----------- | ------------ | ------------------------------------------ |
281| 401 | Unauthorized | Authorization required or token invalid |
282| 403 | Forbidden | Invalid scopes or insufficient permissions |
283| 400 | Bad Request | Malformed authorization request |
279| Status Code | Description | Usage |
280| - | - | - |
281| 401 | Unauthorized | Authorization required or token invalid |
282| 403 | Forbidden | Invalid scopes or insufficient permissions |
283| 400 | Bad Request | Malformed authorization request |
284284
285285## Security Considerations
286286
specification/2025-06-18/basic/lifecycle Changed · +12 / -12 lines
from line 145
145145
146146Key capabilities include:
147147
148| Category | Capability | Description |
149| -------- | -------------- | ----------------------------------------------------------------------------------------- |
150| Client | `roots` | Ability to provide filesystem [roots](/specification/2025-06-18/client/roots) |
151| Client | `sampling` | Support for LLM [sampling](/specification/2025-06-18/client/sampling) requests |
152| Client | `elicitation` | Support for server [elicitation](/specification/2025-06-18/client/elicitation) requests |
153| Client | `experimental` | Describes support for non-standard experimental features |
154| Server | `prompts` | Offers [prompt templates](/specification/2025-06-18/server/prompts) |
155| Server | `resources` | Provides readable [resources](/specification/2025-06-18/server/resources) |
156| Server | `tools` | Exposes callable [tools](/specification/2025-06-18/server/tools) |
157| Server | `logging` | Emits structured [log messages](/specification/2025-06-18/server/utilities/logging) |
158| Server | `completions` | Supports argument [autocompletion](/specification/2025-06-18/server/utilities/completion) |
159| Server | `experimental` | Describes support for non-standard experimental features |
148| Category | Capability | Description |
149| - | - | - |
150| Client | `roots` | Ability to provide filesystem [roots](/specification/2025-06-18/client/roots) |
151| Client | `sampling` | Support for LLM [sampling](/specification/2025-06-18/client/sampling) requests |
152| Client | `elicitation` | Support for server [elicitation](/specification/2025-06-18/client/elicitation) requests |
153| Client | `experimental` | Describes support for non-standard experimental features |
154| Server | `prompts` | Offers [prompt templates](/specification/2025-06-18/server/prompts) |
155| Server | `resources` | Provides readable [resources](/specification/2025-06-18/server/resources) |
156| Server | `tools` | Exposes callable [tools](/specification/2025-06-18/server/tools) |
157| Server | `logging` | Emits structured [log messages](/specification/2025-06-18/server/utilities/logging) |
158| Server | `completions` | Supports argument [autocompletion](/specification/2025-06-18/server/utilities/completion) |
159| Server | `experimental` | Describes support for non-standard experimental features |
160160
161161Capability objects can describe sub-capabilities like:
162162
specification/2025-06-18/server/index Changed · +5 / -5 lines
from line 12
1212
1313Each primitive can be summarized in the following control hierarchy:
1414
15| Primitive | Control | Description | Example |
16| --------- | ---------------------- | -------------------------------------------------- | ------------------------------- |
17| Prompts | User-controlled | Interactive templates invoked by user choice | Slash commands, menu options |
18| Resources | Application-controlled | Contextual data attached and managed by the client | File contents, git history |
19| Tools | Model-controlled | Functions exposed to the LLM to take actions | API POST requests, file writing |
15| Primitive | Control | Description | Example |
16| - | - | - | - |
17| Prompts | User-controlled | Interactive templates invoked by user choice | Slash commands, menu options |
18| Resources | Application-controlled | Contextual data attached and managed by the client | File contents, git history |
19| Tools | Model-controlled | Functions exposed to the LLM to take actions | API POST requests, file writing |
2020
2121Explore these key primitives in more detail below:
2222
specification/2025-06-18/server/utilities/completion Changed · +4 / -4 lines
from line 121
121121
122122The protocol supports two types of completion references:
123123
124| Type | Description | Example |
125| -------------- | --------------------------- | --------------------------------------------------- |
126| `ref/prompt` | References a prompt by name | `{"type": "ref/prompt", "name": "code_review"}` |
127| `ref/resource` | References a resource URI | `{"type": "ref/resource", "uri": "file:///{path}"}` |
124| Type | Description | Example |
125| - | - | - |
126| `ref/prompt` | References a prompt by name | `{"type": "ref/prompt", "name": "code_review"}` |
127| `ref/resource` | References a resource URI | `{"type": "ref/resource", "uri": "file:///{path}"}` |
128128
129129### Completion Results
130130
specification/2025-06-18/server/utilities/logging Changed · +10 / -10 lines
from line 29
2929The protocol follows the standard syslog severity levels specified in
3030[RFC 5424](https://datatracker.ietf.org/doc/html/rfc5424#section-6.2.1):
3131
32| Level | Description | Example Use Case |
33| --------- | -------------------------------- | -------------------------- |
34| debug | Detailed debugging information | Function entry/exit points |
35| info | General informational messages | Operation progress updates |
36| notice | Normal but significant events | Configuration changes |
37| warning | Warning conditions | Deprecated feature usage |
38| error | Error conditions | Operation failures |
39| critical | Critical conditions | System component failures |
40| alert | Action must be taken immediately | Data corruption detected |
41| emergency | System is unusable | Complete system failure |
32| Level | Description | Example Use Case |
33| - | - | - |
34| debug | Detailed debugging information | Function entry/exit points |
35| info | General informational messages | Operation progress updates |
36| notice | Normal but significant events | Configuration changes |
37| warning | Warning conditions | Deprecated feature usage |
38| error | Error conditions | Operation failures |
39| critical | Critical conditions | System component failures |
40| alert | Action must be taken immediately | Data corruption detected |
41| emergency | System is unusable | Complete system failure |
4242
4343## Protocol Messages
4444
specification/2025-11-25/basic/authorization Changed · +5 / -5 lines
from line 485
485485
486486Servers **MUST** return appropriate HTTP status codes for authorization errors:
487487
488| Status Code | Description | Usage |
489| ----------- | ------------ | ------------------------------------------ |
490| 401 | Unauthorized | Authorization required or token invalid |
491| 403 | Forbidden | Invalid scopes or insufficient permissions |
492| 400 | Bad Request | Malformed authorization request |
488| Status Code | Description | Usage |
489| - | - | - |
490| 401 | Unauthorized | Authorization required or token invalid |
491| 403 | Forbidden | Invalid scopes or insufficient permissions |
492| 400 | Bad Request | Malformed authorization request |
493493
494494### Scope Challenge Handling
495495
specification/2025-11-25/basic/lifecycle Changed · +14 / -14 lines
from line 185
185185
186186Key capabilities include:
187187
188| Category | Capability | Description |
189| -------- | -------------- | --------------------------------------------------------------------------------------------- |
190| Client | `roots` | Ability to provide filesystem [roots](/specification/2025-11-25/client/roots) |
191| Client | `sampling` | Support for LLM [sampling](/specification/2025-11-25/client/sampling) requests |
192| Client | `elicitation` | Support for server [elicitation](/specification/2025-11-25/client/elicitation) requests |
193| Client | `tasks` | Support for [task-augmented](/specification/2025-11-25/basic/utilities/tasks) client requests |
194| Client | `experimental` | Describes support for non-standard experimental features |
195| Server | `prompts` | Offers [prompt templates](/specification/2025-11-25/server/prompts) |
196| Server | `resources` | Provides readable [resources](/specification/2025-11-25/server/resources) |
197| Server | `tools` | Exposes callable [tools](/specification/2025-11-25/server/tools) |
198| Server | `logging` | Emits structured [log messages](/specification/2025-11-25/server/utilities/logging) |
199| Server | `completions` | Supports argument [autocompletion](/specification/2025-11-25/server/utilities/completion) |
200| Server | `tasks` | Support for [task-augmented](/specification/2025-11-25/basic/utilities/tasks) server requests |
201| Server | `experimental` | Describes support for non-standard experimental features |
188| Category | Capability | Description |
189| - | - | - |
190| Client | `roots` | Ability to provide filesystem [roots](/specification/2025-11-25/client/roots) |
191| Client | `sampling` | Support for LLM [sampling](/specification/2025-11-25/client/sampling) requests |
192| Client | `elicitation` | Support for server [elicitation](/specification/2025-11-25/client/elicitation) requests |
193| Client | `tasks` | Support for [task-augmented](/specification/2025-11-25/basic/utilities/tasks) client requests |
194| Client | `experimental` | Describes support for non-standard experimental features |
195| Server | `prompts` | Offers [prompt templates](/specification/2025-11-25/server/prompts) |
196| Server | `resources` | Provides readable [resources](/specification/2025-11-25/server/resources) |
197| Server | `tools` | Exposes callable [tools](/specification/2025-11-25/server/tools) |
198| Server | `logging` | Emits structured [log messages](/specification/2025-11-25/server/utilities/logging) |
199| Server | `completions` | Supports argument [autocompletion](/specification/2025-11-25/server/utilities/completion) |
200| Server | `tasks` | Support for [task-augmented](/specification/2025-11-25/basic/utilities/tasks) server requests |
201| Server | `experimental` | Describes support for non-standard experimental features |
202202
203203Capability objects can describe sub-capabilities like:
204204
specification/2025-11-25/basic/utilities/tasks Changed · +9 / -9 lines
from line 34
3434
3535Servers declare if they support tasks, and if so, which server-side requests can be augmented with tasks.
3636
37| Capability | Description |
38| --------------------------- | ---------------------------------------------------- |
39| `tasks.list` | Server supports the `tasks/list` operation |
40| `tasks.cancel` | Server supports the `tasks/cancel` operation |
37| Capability | Description |
38| - | - |
39| `tasks.list` | Server supports the `tasks/list` operation |
40| `tasks.cancel` | Server supports the `tasks/cancel` operation |
4141| `tasks.requests.tools.call` | Server supports task-augmented `tools/call` requests |
4242
4343```json theme={null}
from line 60
6060
6161Clients declare if they support tasks, and if so, which client-side requests can be augmented with tasks.
6262
63| Capability | Description |
64| --------------------------------------- | ---------------------------------------------------------------- |
65| `tasks.list` | Client supports the `tasks/list` operation |
66| `tasks.cancel` | Client supports the `tasks/cancel` operation |
63| Capability | Description |
64| - | - |
65| `tasks.list` | Client supports the `tasks/list` operation |
66| `tasks.cancel` | Client supports the `tasks/cancel` operation |
6767| `tasks.requests.sampling.createMessage` | Client supports task-augmented `sampling/createMessage` requests |
68| `tasks.requests.elicitation.create` | Client supports task-augmented `elicitation/create` requests |
68| `tasks.requests.elicitation.create` | Client supports task-augmented `elicitation/create` requests |
6969
7070```json theme={null}
7171{
specification/2025-11-25/client/elicitation Changed · +10 / -10 lines
from line 80
8080
8181All elicitation requests **MUST** include the following parameters:
8282
83| Name | Type | Options | Description |
84| --------- | ------ | ------------- | -------------------------------------------------------------------------------------- |
85| `mode` | string | `form`, `url` | The mode of the elicitation. Optional for form mode (defaults to `"form"` if omitted). |
86| `message` | string | | A human-readable message explaining why the interaction is needed. |
83| Name | Type | Options | Description |
84| - | - | - | - |
85| `mode` | string | `form`, `url` | The mode of the elicitation. Optional for form mode (defaults to `"form"` if omitted). |
86| `message` | string | | A human-readable message explaining why the interaction is needed. |
8787
8888The `mode` parameter specifies the type of elicitation:
8989
from line 98
9898
9999Form mode elicitation requests **MUST** either specify `mode: "form"` or omit the `mode` field, and include these additional parameters:
100100
101| Name | Type | Description |
102| ----------------- | ------ | -------------------------------------------------------------- |
101| Name | Type | Description |
102| - | - | - |
103103| `requestedSchema` | object | A JSON Schema defining the structure of the expected response. |
104104
105105#### Requested Schema
from line 333
333333
334334URL mode elicitation requests **MUST** specify `mode: "url"`, a `message`, and include these additional parameters:
335335
336| Name | Type | Description |
337| --------------- | ------ | ----------------------------------------- |
338| `url` | string | The URL that the user should navigate to. |
339| `elicitationId` | string | A unique identifier for the elicitation. |
336| Name | Type | Description |
337| - | - | - |
338| `url` | string | The URL that the user should navigate to. |
339| `elicitationId` | string | A unique identifier for the elicitation. |
340340
341341The `url` parameter **MUST** contain a valid URL.
342342
specification/2025-11-25/server/index Changed · +5 / -5 lines
from line 12
1212
1313Each primitive can be summarized in the following control hierarchy:
1414
15| Primitive | Control | Description | Example |
16| --------- | ---------------------- | -------------------------------------------------- | ------------------------------- |
17| Prompts | User-controlled | Interactive templates invoked by user choice | Slash commands, menu options |
18| Resources | Application-controlled | Contextual data attached and managed by the client | File contents, git history |
19| Tools | Model-controlled | Functions exposed to the LLM to take actions | API POST requests, file writing |
15| Primitive | Control | Description | Example |
16| - | - | - | - |
17| Prompts | User-controlled | Interactive templates invoked by user choice | Slash commands, menu options |
18| Resources | Application-controlled | Contextual data attached and managed by the client | File contents, git history |
19| Tools | Model-controlled | Functions exposed to the LLM to take actions | API POST requests, file writing |
2020
2121Explore these key primitives in more detail below:
2222
specification/2025-11-25/server/utilities/completion Changed · +4 / -4 lines
from line 121
121121
122122The protocol supports two types of completion references:
123123
124| Type | Description | Example |
125| -------------- | --------------------------- | --------------------------------------------------- |
126| `ref/prompt` | References a prompt by name | `{"type": "ref/prompt", "name": "code_review"}` |
127| `ref/resource` | References a resource URI | `{"type": "ref/resource", "uri": "file:///{path}"}` |
124| Type | Description | Example |
125| - | - | - |
126| `ref/prompt` | References a prompt by name | `{"type": "ref/prompt", "name": "code_review"}` |
127| `ref/resource` | References a resource URI | `{"type": "ref/resource", "uri": "file:///{path}"}` |
128128
129129### Completion Results
130130
specification/2025-11-25/server/utilities/logging Changed · +10 / -10 lines
from line 29
2929The protocol follows the standard syslog severity levels specified in
3030[RFC 5424](https://datatracker.ietf.org/doc/html/rfc5424#section-6.2.1):
3131
32| Level | Description | Example Use Case |
33| --------- | -------------------------------- | -------------------------- |
34| debug | Detailed debugging information | Function entry/exit points |
35| info | General informational messages | Operation progress updates |
36| notice | Normal but significant events | Configuration changes |
37| warning | Warning conditions | Deprecated feature usage |
38| error | Error conditions | Operation failures |
39| critical | Critical conditions | System component failures |
40| alert | Action must be taken immediately | Data corruption detected |
41| emergency | System is unusable | Complete system failure |
32| Level | Description | Example Use Case |
33| - | - | - |
34| debug | Detailed debugging information | Function entry/exit points |
35| info | General informational messages | Operation progress updates |
36| notice | Normal but significant events | Configuration changes |
37| warning | Warning conditions | Deprecated feature usage |
38| error | Error conditions | Operation failures |
39| critical | Critical conditions | System component failures |
40| alert | Action must be taken immediately | Data corruption detected |
41| emergency | System is unusable | Complete system failure |
4242
4343## Protocol Messages
4444
specification/2026-07-28/basic/authorization/index Changed · +11 / -11 lines
from line 193
193193
194194On receiving the authorization response, MCP clients **MUST** apply the validation in [RFC9207 Section 2.4](https://datatracker.ietf.org/doc/html/rfc9207#section-2.4) before transmitting the authorization code to any token endpoint:
195195
196| `authorization_response_iss_parameter_supported` | `iss` in response | Client action |
197| ------------------------------------------------ | ----------------- | ------------------------------------------------------------------------------------------ |
198| `true` | present | Compare to the recorded issuer using simple string comparison ([RFC3986 Section 6.2.1][1]) |
199| `true` | absent | Reject the response |
200| `false` or absent | present | Compare to the recorded issuer using simple string comparison ([RFC3986 Section 6.2.1][1]) |
201| `false` or absent | absent | Proceed |
196| `authorization_response_iss_parameter_supported` | `iss` in response | Client action |
197| - | - | - |
198| `true` | present | Compare to the recorded issuer using simple string comparison ([RFC3986 Section 6.2.1][1]) |
199| `true` | absent | Reject the response |
200| `false` or absent | present | Compare to the recorded issuer using simple string comparison ([RFC3986 Section 6.2.1][1]) |
201| `false` or absent | absent | Proceed |
202202
203203[1]: https://datatracker.ietf.org/doc/html/rfc3986#section-6.2.1
204204
from line 314
314314
315315Servers **MUST** return appropriate HTTP status codes for authorization errors:
316316
317| Status Code | Description | Usage |
318| ----------- | ------------ | ------------------------------------------ |
319| 401 | Unauthorized | Authorization required or token invalid |
320| 403 | Forbidden | Invalid scopes or insufficient permissions |
321| 400 | Bad Request | Malformed authorization request |
317| Status Code | Description | Usage |
318| - | - | - |
319| 401 | Unauthorized | Authorization required or token invalid |
320| 403 | Forbidden | Invalid scopes or insufficient permissions |
321| 400 | Bad Request | Malformed authorization request |
322322
323323### Scope Challenge Handling
324324