MCP Protocol News - August 28, 2026
This week's MCP ecosystem activity centered on SDK releases and spec governance.
MCP Protocol News - August 28, 2026
Week of: August 28, 2026
Overview
This week's MCP ecosystem activity centered on SDK releases and spec governance. The MCP Python SDK shipped a feature release (v2.1.0) plus patches across both the 2.x and 1.x lines, GitHub MCP Server 1.11.0 introduced per-call OAuth scopes, and the specification repo formalized a transports working group while updating its roadmap.
Stories
1. GitHub MCP Server 1.11.0 Adds Per-Call OAuth Scopes and Atomic Sub-Issue Creation
Source: GitHub MCP Server Link: https://github.com/github/github-mcp-server/releases/tag/v1.11.0
GitHub's MCP server release 1.11.0 introduces smarter OAuth challenges with per-call scope checks, so each tool invocation requests only the permissions it needs. It also improves browser OAuth support — CORS now works across OAuth discovery routes with configurable authorization-server URLs — and creates parent and sub-issues atomically. REST responses gained ETag conditional request support for better HTTP caching on STDIO, and the release upgrades to Go 1.27 with routine security updates.
For MCP builders, per-call scope checks address the common problem of MCP servers requesting broad permissions up front, a frequent blocker in production deployments. Atomic sub-issue creation is a concrete capability for agentic GitHub workflows that depend on multi-step issue operations.
Impact Analysis: Granular OAuth scoping sets a bar for secure-by-design MCP server behavior.
2. MCP Python SDK v2.1.0 Streamlines Client Wiring and Adds Multimodal Prompts
Source: MCP Python SDK Link: https://github.com/modelcontextprotocol/python-sdk/releases/tag/v2.1.0
The Python SDK v2.1.0 lets Client accept StdioServerParameters directly, e.g. Client(StdioServerParameters(command="uv", args=["run", "server.py"])), eliminating a layer of boilerplate when spawning stdio servers. Prompt messages now accept Image and Audio content, prompt functions may return bare content blocks, and Message/UserMessage/AssistantMessage are exported from mcp.server.mcpserver. The 4 MiB request body limit now also covers the SSE transport and OAuth endpoints, and the SSE message endpoint answers 405 to non-POST requests.
The direct StdioServerParameters client simplifies programmatic server startup, especially for servers run via uv or similar runtimes. Image/Audio prompt support extends the SDK to multimodal MCP use cases, while the expanded body limits harden the SSE and OAuth paths.
Impact Analysis: Less boilerplate and multimodal support lower the barrier to Python-based MCP integrations.
3. MCP Specification Formalizes Transports Working Group Charter
Source: MCP Specification Link: https://github.com/modelcontextprotocol/modelcontextprotocol/commit/d8fdc88fb970313247d8a180ac1ec3f6a10a8885
The MCP specification repository merged a charter for a new transports working group, with follow-up documentation updates in the community working-groups docs. The charter adds formal structure for how transport-related changes and discussions are governed.
A dedicated working group signals that transport standardization — streamable HTTP, SSE, and future transports — is a priority area for the MCP governance process. For builders tracking where transport-level features are headed, this provides a venue to watch for proposals and decisions.
Impact Analysis: Formal transport governance suggests continued evolution of MCP's wire-level protocols.
4. MCP Python SDK Patches FastMCP Import Warning in v2.0.1 and v2.1.1
Source: MCP Python SDK Link: https://github.com/modelcontextprotocol/python-sdk/releases/tag/v2.0.1
Patch releases v2.0.1 and v2.1.1 backport a fix that points imports of mcp.server.fastmcp at the migration guide. The maintainers noted that many users were hitting the error and filing issues on other repos, so the warning was backported to the 2.0.x line as a one-off; they recommend either pinning mcp<2 or upgrading to 2.
The FastMCP import path has been a source of confusion for teams navigating between SDK major versions. These patches make the deprecation path clearer for anyone still importing from the old location.
Impact Analysis: Cleaner migration messaging reduces cross-repo issue noise for SDK maintainers and users alike.
5. MCP Python SDK v1.29.1 Backports Transport Limits and Recursive Schema Fixes
Source: MCP Python SDK Link: https://github.com/modelcontextprotocol/python-sdk/releases/tag/v1.29.1
The v1.x line received a maintenance release completing the FastMCP Settings model at import time, applying the request body limit to SSE and OAuth endpoints, and giving recursive tool return types an object-rooted output schema.
These backports bring the 1.x line closer to 2.x behavior on transport hardening and schema generation for recursive types. Teams still on 1.x get the compatibility fixes without a major upgrade.
Impact Analysis: Converging 1.x and 2.x behavior reduces the urgency and risk of migrating between major versions.
6. MCP Spec Repo Moves Node Floor to 24 and Patches High-Severity Dev Advisories
Source: MCP Specification Link: https://github.com/modelcontextprotocol/modelcontextprotocol/commit/320aeda390a8f138ad7246c016197ca876f7ecf4
The specification repository raised its Node.js engine floor from end-of-life 20 to 24 and separately patched two high-severity advisories in dev dependencies, including one tied to fast-uri (CVE-2026-18446). These changes update the toolchain for contributors working on spec docs and site infrastructure.
While not user-facing, the move off an EOL Node runtime and the dependency security patches keep the spec repo's contribution pipeline healthy. It signals that spec-side development infrastructure is being maintained alongside the protocol itself.
Impact Analysis: Security and toolchain hygiene in the spec repo keeps the documentation supply chain clean for contributors.
Source Links
More from News