DEV Community

Cover image for The MCP Ecosystem Is Speaking Five Revisions at Once. Here Is the Dated Count.
Pennyforge
Pennyforge

Posted on

The MCP Ecosystem Is Speaking Five Revisions at Once. Here Is the Dated Count.

Dated: 2026-10-02. Data from two same-cohort probes (2026-10-01 and 2026-10-02) plus a 10-server stdio probe. Pennyforge research, $0 (public registry + public endpoints). Per-URL data and method are linked at the end.

Model Context Protocol clients already ship the 2026-07-28 revision — a stateless rewrite that deletes the initialize handshake, drops the Mcp-Session-Id header, replaces session discovery with a server/discover RPC, and adds UnsupportedProtocolVersionError for version mismatches. The server side of the ecosystem, though, is not one population. It is five, one per spec revision, and most of them are invisible to each other without an error.

We counted what the live endpoints actually speak, twice on the same cohort, plus what the prominent local (stdio) servers speak.

What the 2026-07-28 revision changed (primary changelog)

  1. Protocol-level sessions and Mcp-Session-Id removed from Streamable HTTP.
  2. initialize / notifications.initialized removed; clients send protocolVersion + capabilities per request in _meta; new server/discover RPC.
  3. subscriptions/listen replaces HTTP GET + resources/subscribe.
  4. ping, logging/setLevel, roots/list_changed removed.
  5. Tasks promoted to the official io.modelcontextprotocol/tasks extension.
  6. MRTR (multi-request/multi-response) replaces server-initiated requests.
  7. Error-code allocation policy updated (−32020…−32099 reserved).

Source: modelcontextprotocol.io/specification/2026-07-28/changelog (accessed 2026-10-01).

Point 1 — 186 remote endpoints, wire census (2026-10-01 05:27Z, re-probed 06:06Z)

Cohort: the official MCP registry's v0 REST API, first 900 listings, deduplicated by endpoint URL, then the contiguous slice of hostnames beginning a–b = 186 unique endpoints (a slice, not a random sample — see caveats). Probe: POST initialize offering protocolVersion: "2026-07-28", browser User-Agent, classified by the negotiated response version and session header.

Class n Share of 186
Auth-gated (HTTP 401) — invisible to anonymous probes 86 46%
Answered old wire: 2025-11-25 36 19%
Answered old wire: 2025-06-18 21 11%
Answered old wire: 2025-03-26 5 3%
Answered old wire: 2024-11-05 3 2%
Answered new wire: 2026-07-28 7 4%
Transient/errors 28 15%

Of the 72 endpoints that returned any protocol version, 7 (9.7%) spoke the new wire — and the two-probe decomposition matters: 6 of the 7 were provably negotiating (they upgraded when offered 2026-07-28 and answered old when offered old), 1 was pinned. A re-probe 39 minutes later returned the identical class shape.

The 7 are public registry entries and three of them share one operator — an operator-cluster, not seven independent early adopters: mcp.getle.ad/mcp, www.hood.ag/api/mcp, mcp.bev-buyer.ai/mcp, api.aislabs.ai/{,cve/,recorder/}mcp, bankrolled.ai/mcp.

Point 2 — the prominent local servers (stdio, 2026-10-01)

Ten prominent npm MCP servers, spawned via npx -y, probed twice: initialize (legacy handshake) and server/discover (the new-revision call).

Server initialize server/discover
official server-filesystem (0.2.0, 2026-08-31) 2025-06-18 −32601 Method not found
official server-everything (2.0.0) 2025-06-18 −32601 Method not found
@upstash/context7-mcp 2025-06-18 −32601 Method not found
tavily-mcp 2025-06-18 −32601 Method not found
playwright-mcp (microsoft) 2025-06-18 −32601 Method not found
@modelcontextprotocol/server no executable to run —
mcp-remote OAuth-discovery hang (45s) —

All five answering servers speak only the 2025-06-18 wire and reject the new call. The flagship npm packages are the oldest wire in the ecosystem — and the reference @modelcontextprotocol/server package currently doesn't even ship a default executable (npm error could not determine executable to run).

Point 3 — the same 186 endpoints, one week later, tested for the new call (2026-10-02 00:45Z)

Same cohort, new probe design: initialize requesting the floor version (2025-06-18), then server/discover.

Class count
AUTH-401/403 88 (47%)
Answered, no server/discover 96
Answered, accepts server/discover 3
DNS/5xx/redirects 19

The 3 acceptors (mcp.getle.ad/mcp, analyticslegends.ai/mcp, api.askmiles.ai/mcp) all return the new-era discover payload. Combined across both cohorts: 8 of 109 answering endpoints (7.3%) accept the new-revision call while major clients already ship it.

The version-echo lesson (the methodology finding that will outlive the numbers)

Our 10-01 census reported 43 servers "speaking" 2025-11-25 or 2026-07-28. On 10-02 we requested the floor version and all 43 echoed the floor back — none "regressed". The servers negotiate: they echo any requested version within their supported range and report their maximum for requests above it. Verified on four servers that day:

  • api.aislabs.ai/mcp, bankrolled.ai/mcp — permissive: accept every version 2024-11-05 → 2026-07-28
  • mcp.getle.ad/mcp — floor 2025-03-26
  • advisorsai.ai/mcp — capped at 2025-11-25 (a 2026-07-28 offer gets a 2025-11-25 answer)

So a server's "reported protocolVersion" is only a capability test when you request the highest version you care about and read the answer: echo = speaks it; lower echo = caps below; UnsupportedProtocolVersionError = hard floor above you.

The failure mode

A reader hard-coded to one era sees half the population as missing — and nothing errors. The identical lesson landed on the x402 side this week (payment requirements in the 402 body in v1, base64 in the PAYMENT-REQUIRED header in v2: one operator's body-only parser marked 87 of 183 doors "no payTo" when all 87 had one). Across both protocols the same shape: the migration changes where the data lives, not whether it lives, and only the reader's vantage point decides what is invisible.

Caveats (honest)

  1. The 186-URL cohort is a hostname slice of the registry's default ordering, not a random sample.
  2. ~47% of the cohort is auth-gated — the public surface is the visible half.
  3. server/discover is defined in the 2026-07-28 Final spec; the project blog and spec disagree on its optionality, so the 3 acceptors might be 2025-11-25 servers.
  4. Pinned ≠ behaviorally old: a pinned 2025-11-25 server may still accept 2026 clients.
  5. Two dated points, one week apart — a direction, not a trend.

Next

The weekly re-probe of this exact cohort now requests 2026-07-28 and reads echo/cap/error, which finally separates "pure new wire" from "old handshake, new version" and gives the series its first real migration curve. Next point: 2026-10-08.


Pennyforge (one-person studio). Method: mcp_census.py + probe-remote.py; per-URL classes and the dated probe notes (10-01 wire census, 10-02 remote probe) are kept as research artifacts next to the method scripts. Data: public registry + public endpoints, $0.

Top comments (0)