Sr. Content Developer at Microsoft, working remotely in PA, TechBash conference organizer, former Microsoft MVP, Husband, Dad and Geek.
159855 stories
·
33 followers

The New MCP Roadmap

1 Share

Today we’re excited to publish an updated roadmap for the Model Context Protocol (MCP), covering the next specification release and beyond.

It sets the direction for protocol work over the coming months and was developed by the Core Maintainers together with our community of maintainers and Working Groups.

Explore the roadmap

Priority areas

The roadmap is organized into five priority areas. Several of them pick up work that the previous roadmap listed as on the horizon, including server-initiated events, result type improvements, and agent identity, which have since matured enough to become priorities in their own right. Each area has a set of Core Maintainers responsible for it and one or more Working Groups.

MCP Roadmap: five priority areas, agentic messaging primitives, HTTP-native transport unification and hardening, agent identity and enterprise-ready security, improved primitives, and improved SDK developer experience.

Agentic messaging primitives

Modern agentic workloads no longer fit the standard request-and-response pattern. Loops can run for longer, servers can push streamed results, and there is a clear need to steer work mid-flight. MCP has been growing to meet these requirements, introducing Tasks, subscriptions/listen, and progress notifications. We want to make sure that we not only offer the right primitives for the job, but also that they work well together. The work here spans server-initiated events (webhooks and channels, so clients aren’t left polling for results), a composition review across the Agents, Transports, and Triggers & Events Working Groups, and maturing the Tasks extension (SEP-2663) so it can move into the specification.

HTTP-native transport unification and hardening

With the 2026-07-28 release, a remote MCP server is now no different from any other HTTP workload, making it easy to host and operate one on any infrastructure that developers and organizations already use for their APIs and services. This approach has proven to scale, and we want to stretch it to cover other deployment modes as well, including local servers speaking Streamable HTTP over stdio. Unifying on one transport lets us simplify MCP server and client development even further.

Agent identity and enterprise-ready security

MCP authorization today is built around a person approving access in a browser. That works well for interactive clients, but more and more of the callers are agents running as cloud workloads with their own identity, acting on behalf of a user who isn’t present, or delegating narrower authority to sub-agents. We want MCP servers to have a standardized way to recognize and trust those agent identities, built on existing standards rather than pasted API keys and long-lived tokens.

The work here covers finalizing Demonstrating Proof of Possession (DPoP) and driving its adoption, and defining an opinionated path for agent identity and delegation through Workload Identity Federation, the ID-JAG grant behind Enterprise-Managed Authorization, and standard token exchange. We will also continue to grow our engagement with the OAuth standards bodies, including the IETF OAuth and WIMSE working groups, to help the underlying standards evolve with the building blocks that agent identity needs.

Improved primitives

Tool calling is the part of MCP most developers touch first, and it has held up well over the lifetime of the protocol. Where it falls a bit short, however, is in the result handling. A tools/call response can carry the same output in more than one form, and a server developer today has no way to know which form a given client will put in front of the model. We aim to make this easier by standardizing on one clear contract.

The other challenge we need to address for primitives is their ever-growing scale. Connecting to a server with a hundred tools means the model pays for that entire surface before the user has asked a single question, and tool selection tends to get worse as the list grows. We’re starting a progressive discovery effort so a server can offer a small entry point and reveal more of its catalog as the conversation narrows.

Improved SDK developer experience

Our SDKs are how developers experience MCP. We are investing in their ergonomics and their conformance with the specification, and in making them intuitive and well-documented across every platform and language we support. This is even more important now that many developers build MCP clients and servers by pointing an agent at our libraries, where clear APIs and accurate docs decide whether the code will work with minimal friction.

Proposal prioritization

Specification Enhancement Proposals (SEPs) that fall within these priority areas get expedited review and have the best chance of acceptance. Proposals outside them aren’t rejected automatically, but maintainer review time is scarce and goes to these areas first.

If you’re considering a SEP, identify the priority area it belongs to, raise it with the relevant Working Group, and work with its members to shape your proposal. Each area on the roadmap names the Core Maintainers responsible for it, and anyone interested in contributing can reach them on Discord. We’re excited to work with the community to review and build on the proposals that support this roadmap.

Get involved

Every priority area above has a Working Group behind it or forming around it, and all of them have room for more contributors. There are several ways to participate:

We look forward to growing and evolving MCP together!

Read the whole story
alvinashcraft
41 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

The AI-Native SDLC playbook

1 Share
The AI-Native SDLC playbook
Read the whole story
alvinashcraft
49 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

Bringing the cybersecurity capabilities of Claude Mythos 5 to more defenders

1 Share
Bringing the cybersecurity capabilities of Claude Mythos 5 to more defenders
Read the whole story
alvinashcraft
52 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

dotnet-1.19.0

1 Share

What's Changed

New Contributors

Full Changelog: dotnet-1.18.0...dotnet-1.19.0

Read the whole story
alvinashcraft
1 minute ago
reply
Pennsylvania, USA
Share this story
Delete

F# Weekly #34, 2026 — Every Repo is A Software Factory Now

1 Share

Welcome to F# Weekly,

A roundup of F# content from this past week:

Microsoft New

Videos

Blogs

Highlighted projects

  • mrange/FsDistanceField2 — Computes distance field from images – Codeberg.org
  • Neftedollar/orleans-fsharp — Idiomatic F# for Microsoft Orleans: define grains with computation expressions, streaming, event sourcing, and transactions. Orleans 10.2.1 parity, 1700+ tests.
  • WillEhrendreich/SageFs — Sage Mode for F# development: REPL with solution/project loading, live testing, hot reload, and MCP server support.
  • warp-11/warp-11 — An F# HDL that runs on real FPGAs — one source drives the cycle-accurate simulator, step-through debugger, emitted Verilog, and Rust driver seam.
  • Azizs2162/fyper — Build type-safe Cypher queries in F# with plain records, query expressions, and automatic parameterization (Neo4j / Apache AGE).
  • HelgeSverre/fedit — A small terminal text editor written in F# with multi-buffer, undo/redo, find, command palette, system clipboard, and seven themes.

New Releases

Mibo Framework 4.3.0 is out!This contains general fixes and improvementsit also brings "signals" to game dev programming for heavy simulation and derived data games (e.g. RPGs, TDs)#dotnet #fsharp #monogame #raylib

Angel Munoz (@tunaxor.me) 2026-08-16T20:45:41.386Z

That’s all for now. Have a great week.

Buy Me A Coffee





Read the whole story
alvinashcraft
1 minute ago
reply
Pennsylvania, USA
Share this story
Delete

American Who Wiped His Phone With 'Duress' Password During Border Search Gets Felony Charges

1 Comment and 2 Shares
Federal prosecutors have charged activist Samuel Tunick with obstruction after he gave Customs and Border Protection officers a duress passcode that wiped his GrapheneOS-powered Pixel during a border search. "His prosecution is one of the earliest known instances of the federal authorities charging a person with destroying evidence using a program designed to wipe a device clean after a specific code is entered," reports The New York Times. From the report: "Obstructing federal law enforcement is a serious matter that has serious repercussions," Theodore Hertzberg, the U.S. attorney for the Northern District of Georgia, said in a statement. "Individuals who destroy or attempt to destroy property, including data, to prevent lawful search and seizure should expect to face prosecution and punishment for their actions." A spokeswoman for U.S. Customs and Border Protection said in a statement that the agency had the authority to search the electronic devices of anyone entering or leaving the United States, regardless of citizenship, to enforce laws addressing terrorism, child exploitation, drug- and human-smuggling, visa fraud and national security threats. "The border search will only include an examination of information that is present on the device at the time it is presented for inspection," the spokeswoman said, adding that it searched the electronic devices of fewer than 0.01 percent of all arriving international travelers in the last fiscal year. "Just the knowledge that the government is peering into your private life in this way, trying to dig up dirt on you, even though it's unsuccessful, is creepy," Tunick said, in response to a question about how the charges have affected him. His message: "The government doesn't own our communications, our relationships, as hard as they might try to. We have to defend our fundamental right to privacy; otherwise we can't say that we really live in a democracy."

Read more of this story at Slashdot.

Read the whole story
alvinashcraft
22 hours ago
reply
Pennsylvania, USA
Share this story
Delete
1 public comment
magazinemaker0823
14 hours ago
reply
This kind of daily link roundup is honestly one of the more useful subscriptions I keep for staying on top of dev news without doom-scrolling five different feeds. I ended up doing something similar for my own team a while back - every couple weeks I'd pull together the links people found interesting into an actual read, since nobody ever went back through old Slack messages otherwise. Started using https://magazinemaker.org/index.html for the layout part, since a plain doc of links never felt like something people wanted to open. Curious if you've thought about packaging any of these roundups into something more than a stream.
Next Page of Stories