MCP isn't broken. Teams are using it wrong.
Every "overhead" complaint in the last six months traces back to the same misuse: fetching tool schemas on every call instead of caching sessions once.
That's not a protocol flaw. That's treating a capability-discovery layer like a request path.
MCP was designed for tool onboarding — letting an agent figure out what a server can do, once, at session start. When teams wire it into hot paths and re-fetch the schema on every loop iteration, they're doing the agentic equivalent of running npm install before every API call.
The security side is harder to defend. 92% of exposed MCP servers have no OAuth, per recent audits. But teams are skipping auth they'd never skip on a REST endpoint. We just haven't started treating MCP servers as first-class third-party dependencies yet. That's an ops maturity problem, not a spec problem.
The July 2026 revision is forcing a real decision: adopt the stateless model correctly, or keep bolting security on after the fact.
The protocol is fine. The discipline isn't there yet.
Have you seen MCP implemented well in production — or has your team moved away from it entirely?
https://tyk.io/learning-center/is-mcp-dead-in-2026-why-enterprises-still-need-mcp/
Top comments (0)