Dated: 2026-10-02. Data from two same-cohort probes (2026-10-01 and 2026-10-02) plus a 10-server stdio probe. Pennyforge research, $0 (public registry + public endpoints). Per-URL data and method are linked at the end.
Model Context Protocol clients already ship the 2026-07-28 revision — a stateless rewrite that deletes the initialize handshake, drops the Mcp-Session-Id header, replaces session discovery with a server/discover RPC, and adds UnsupportedProtocolVersionError for version mismatches. The server side of the ecosystem, though, is not one population. It is five, one per spec revision, and most of them are invisible to each other without an error.
We counted what the live endpoints actually speak, twice on the same cohort, plus what the prominent local (stdio) servers speak.
What the 2026-07-28 revision changed (primary changelog)
- Protocol-level sessions and
Mcp-Session-Idremoved from Streamable HTTP. -
initialize/notifications.initializedremoved; clients sendprotocolVersion+ capabilities per request in_meta; newserver/discoverRPC. -
subscriptions/listenreplaces HTTP GET +resources/subscribe. -
ping,logging/setLevel,roots/list_changedremoved. - Tasks promoted to the official
io.modelcontextprotocol/tasksextension. - MRTR (multi-request/multi-response) replaces server-initiated requests.
- Error-code allocation policy updated (−32020…−32099 reserved).
Source: modelcontextprotocol.io/specification/2026-07-28/changelog (accessed 2026-10-01).
Point 1 — 186 remote endpoints, wire census (2026-10-01 05:27Z, re-probed 06:06Z)
Cohort: the official MCP registry's v0 REST API, first 900 listings, deduplicated by endpoint URL, then the contiguous slice of hostnames beginning a–b = 186 unique endpoints (a slice, not a random sample — see caveats). Probe: POST initialize offering protocolVersion: "2026-07-28", browser User-Agent, classified by the negotiated response version and session header.
| Class | n | Share of 186 |
|---|---|---|
| Auth-gated (HTTP 401) — invisible to anonymous probes | 86 | 46% |
| Answered old wire: 2025-11-25 | 36 | 19% |
| Answered old wire: 2025-06-18 | 21 | 11% |
| Answered old wire: 2025-03-26 | 5 | 3% |
| Answered old wire: 2024-11-05 | 3 | 2% |
| Answered new wire: 2026-07-28 | 7 | 4% |
| Transient/errors | 28 | 15% |
Of the 72 endpoints that returned any protocol version, 7 (9.7%) spoke the new wire — and the two-probe decomposition matters: 6 of the 7 were provably negotiating (they upgraded when offered 2026-07-28 and answered old when offered old), 1 was pinned. A re-probe 39 minutes later returned the identical class shape.
The 7 are public registry entries and three of them share one operator — an operator-cluster, not seven independent early adopters: mcp.getle.ad/mcp, www.hood.ag/api/mcp, mcp.bev-buyer.ai/mcp, api.aislabs.ai/{,cve/,recorder/}mcp, bankrolled.ai/mcp.
Point 2 — the prominent local servers (stdio, 2026-10-01)
Ten prominent npm MCP servers, spawned via npx -y, probed twice: initialize (legacy handshake) and server/discover (the new-revision call).
| Server | initialize | server/discover |
|---|---|---|
official server-filesystem (0.2.0, 2026-08-31) |
2025-06-18 | −32601 Method not found |
official server-everything (2.0.0) |
2025-06-18 | −32601 Method not found |
@upstash/context7-mcp |
2025-06-18 | −32601 Method not found |
tavily-mcp |
2025-06-18 | −32601 Method not found |
playwright-mcp (microsoft) |
2025-06-18 | −32601 Method not found |
@modelcontextprotocol/server |
no executable to run | — |
mcp-remote |
OAuth-discovery hang (45s) | — |
All five answering servers speak only the 2025-06-18 wire and reject the new call. The flagship npm packages are the oldest wire in the ecosystem — and the reference @modelcontextprotocol/server package currently doesn't even ship a default executable (npm error could not determine executable to run).
Point 3 — the same 186 endpoints, one week later, tested for the new call (2026-10-02 00:45Z)
Same cohort, new probe design: initialize requesting the floor version (2025-06-18), then server/discover.
| Class | count |
|---|---|
| AUTH-401/403 | 88 (47%) |
Answered, no server/discover
|
96 |
Answered, accepts server/discover |
3 |
| DNS/5xx/redirects | 19 |
The 3 acceptors (mcp.getle.ad/mcp, analyticslegends.ai/mcp, api.askmiles.ai/mcp) all return the new-era discover payload. Combined across both cohorts: 8 of 109 answering endpoints (7.3%) accept the new-revision call while major clients already ship it.
The version-echo lesson (the methodology finding that will outlive the numbers)
Our 10-01 census reported 43 servers "speaking" 2025-11-25 or 2026-07-28. On 10-02 we requested the floor version and all 43 echoed the floor back — none "regressed". The servers negotiate: they echo any requested version within their supported range and report their maximum for requests above it. Verified on four servers that day:
-
api.aislabs.ai/mcp,bankrolled.ai/mcp— permissive: accept every version 2024-11-05 → 2026-07-28 -
mcp.getle.ad/mcp— floor 2025-03-26 -
advisorsai.ai/mcp— capped at 2025-11-25 (a 2026-07-28 offer gets a 2025-11-25 answer)
So a server's "reported protocolVersion" is only a capability test when you request the highest version you care about and read the answer: echo = speaks it; lower echo = caps below; UnsupportedProtocolVersionError = hard floor above you.
The failure mode
A reader hard-coded to one era sees half the population as missing — and nothing errors. The identical lesson landed on the x402 side this week (payment requirements in the 402 body in v1, base64 in the PAYMENT-REQUIRED header in v2: one operator's body-only parser marked 87 of 183 doors "no payTo" when all 87 had one). Across both protocols the same shape: the migration changes where the data lives, not whether it lives, and only the reader's vantage point decides what is invisible.
Caveats (honest)
- The 186-URL cohort is a hostname slice of the registry's default ordering, not a random sample.
- ~47% of the cohort is auth-gated — the public surface is the visible half.
-
server/discoveris defined in the 2026-07-28 Final spec; the project blog and spec disagree on its optionality, so the 3 acceptors might be 2025-11-25 servers. - Pinned ≠ behaviorally old: a pinned 2025-11-25 server may still accept 2026 clients.
- Two dated points, one week apart — a direction, not a trend.
Next
The weekly re-probe of this exact cohort now requests 2026-07-28 and reads echo/cap/error, which finally separates "pure new wire" from "old handshake, new version" and gives the series its first real migration curve. Next point: 2026-10-08.
Pennyforge (one-person studio). Method: mcp_census.py + probe-remote.py; per-URL classes and the dated probe notes (10-01 wire census, 10-02 remote probe) are kept as research artifacts next to the method scripts. Data: public registry + public endpoints, $0.
Top comments (0)