* feat(mcp): speak spec revision 2026-07-28 (stateless core)
Adopt the 2026-07-28 MCP spec revision on the connector endpoint while
keeping every handshake-era client (2025-06-18 and earlier) byte-identical:
- Accept per-request _meta protocol negotiation
(io.modelcontextprotocol/protocolVersion); unsupported versions return
UnsupportedProtocolVersionError (-32022) with the supported list.
- Implement server/discover (spec MUST): supported revisions, capabilities
including the extensions field, identity, instructions, freshness hints.
- Decorate results for stateless clients: required resultType, serverInfo
in _meta, and CacheableResult ttlMs/cacheScope on tools/list,
prompts/list, resources/list, resources/read.
- Validate the standard Mcp-Method/Mcp-Name request headers when present
(HeaderMismatchError -32020); absence stays accepted.
- Declare the ratified MCP Apps extension (io.modelcontextprotocol/ui) in
capabilities; the widgets already use the ratified mime type and
_meta.ui.resourceUri shape, so no widget changes are needed.
- OAuth: include the RFC 9207 iss parameter on every authorization
response (success and error) and advertise
authorization_response_iss_parameter_supported in RFC 8414 metadata.
Resource-not-found already used -32602 and tools/list ordering was already
deterministic; both are covered by the new test file.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(mcp): Mcp-Name covers params.uri, base64 sentinel, version-header consistency
Review follow-ups against the transport spec text: Mcp-Name mirrors
params.name OR params.uri (resources/read), values arrive base64-wrapped
in the =?base64?...?= sentinel and must be decoded before comparison, and
an MCP-Protocol-Version header that disagrees with the _meta protocol
version is a HeaderMismatch. Absence of any header stays accepted since
this server supports handshake-era clients (spec-sanctioned leniency).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>