The July MCP revision went stateless and adopted OAuth 2.0 and OpenID Connect, so servers can now run serverless. It reads like a boring spec note, but I think it matters more than it sounds.
Why stateless matters
Stateless servers plus standard auth are what separate a protocol you demo on a laptop from one you can put behind a load balancer at work.
When a server keeps per-session state in memory, every request from a client has to reach the same instance. Most production infrastructure works against that. Load balancers spread traffic, serverless functions come and go, and deploys replace instances. A stateless server can handle any request on any instance.
Why standard auth matters
OAuth 2.0 and OpenID Connect are what identity infrastructure already speaks. With them, an MCP server can plug into the same auth setup as everything else instead of needing its own.
One less excuse
Most integration standards die because nobody can deploy them the way their infrastructure already works. MCP just removed that excuse.
Building something like this?
I'm Ahmed Mamdouh, a senior full-stack and AI engineer. I reply within one working day.

The systems I am proud of are built from boring parts
The systems I'm proudest of use Postgres, a queue and a cache with a written invalidation rule. The real engineering was in the failure handling.

What actually breaks when AI agents go to production
Production agents fail on state, partial failure and knowing when to stop. Those are distributed systems problems, and prompts won't fix them.

Claude output is now watermarked
Claude output now carries watermarks and signed provenance by default. Tell your users, and never treat a missing watermark as proof.
