Skip to content
Star17Hire me
01 / StartXP 0%
Sep 11, 2026 · 1 min · by Ahmed Mamdouh

MCP went stateless, and that matters

#mcp#ai#architecture

The July MCP revision went stateless and adopted OAuth 2.0 and OpenID Connect, so servers can now run serverless. It reads like a boring spec note, but I think it matters more than it sounds.

Why stateless matters

Stateless servers plus standard auth are what separate a protocol you demo on a laptop from one you can put behind a load balancer at work.

When a server keeps per-session state in memory, every request from a client has to reach the same instance. Most production infrastructure works against that. Load balancers spread traffic, serverless functions come and go, and deploys replace instances. A stateless server can handle any request on any instance.

Why standard auth matters

OAuth 2.0 and OpenID Connect are what identity infrastructure already speaks. With them, an MCP server can plug into the same auth setup as everything else instead of needing its own.

One less excuse

Most integration standards die because nobody can deploy them the way their infrastructure already works. MCP just removed that excuse.

Building something like this?

I'm Ahmed Mamdouh, a senior full-stack and AI engineer. I reply within one working day.

More posts