MCP went stateless: Is your AWS MCP server deployment well-architected?¶
Summary¶
On 2026-07-28, the Model Context Protocol
shipped its largest revision since launch, making the protocol core
stateless. The initialize handshake and the
Mcp-Session-Id header are gone; every request now self-describes (protocol
version, client context) and any server instance can answer it. The AWS
Architecture Blog reads the MCP 2026-07-28 spec against the AWS
Well-Architected Agentic AI Lens, pillar by pillar, and argues that the new
protocol natively achieves what the old session-based protocol could only
reach through compensating AWS infrastructure — sticky routing on Application
Load Balancers, session stores in DynamoDB/ElastiCache, and body-parsing
gateways. The recommendation: migrate, delete the session infrastructure that
existed only to preserve protocol sessions, and (only after old-client traffic
reaches zero) retire the backward-compatible legacy lane. The post targets teams
managing the full deployment stack themselves; teams behind Amazon Bedrock
AgentCore Gateway get protocol management and backward compatibility handled
for them.
Key takeaways¶
-
Stateless describes the protocol, not your application. Stateful use cases still work: when a server needs continuity, a tool returns an identifier for stored state, the model carries that key on later calls, and the state lives in your datastore. The analogy is a coat check — the old protocol was a valet who remembered your face (forcing you back to the same valet); now you hold a numbered ticket any attendant can honor. Advantage: the identifier sits in the model's context (reasoned about, threaded across tools) rather than hidden in a header (Source: this article).
-
The before/after deployment table is the actionable core. Each row is a piece of AWS infrastructure the old protocol required that the stateless core makes unnecessary:
- ALB stickiness → plain round-robin (delete the stickiness config).
- Session state in DynamoDB / ElastiCache → no session store; server-minted identifiers passed as tool arguments.
- Gateway parses request bodies to route by method → route/throttle on the
Mcp-MethodandMcp-Nameheaders. - AWS Lambda workarounds for the stateful handshake → Lambda is a natural fit (request in, response out).
- Refetch tool lists per session → cache with
ttlMsandcacheScope. - Bolt-on tracing / proprietary protocol logging → W3C Trace Context in
_meta;stderror OpenTelemetry for logging (protocol logging deprecated). -
Stream resumption (
Last-Event-ID) → make tools idempotent; clients re-issue broken calls. -
server/discoverreplaces the handshake for capability negotiation. A client that wants to know what a server supports before calling it gets supported protocol versions, capabilities, and identity in a single response. Servers must implement it; calling it is optional for the client. -
Multi Round-Trip Requests (MRTR) replace server-initiated push. Servers can no longer push a request to a client mid-call (how confirmations, sampling, and root queries used to work over a held-open stream). Instead a server returns an
input_requiredresult carrying aninputRequestsmap and an opaquerequestStatetoken; the client fulfills the requests and re-sends the original call withinputResponsesand the echoedrequestState. Any instance can resume becauserequestStatecarries all needed context — no shared session store, no held-open connection. This is what makes rich interaction work on AWS Lambda (multi-round-trip-request). -
Well-Architected, pillar by pillar (the spec converges on the Lens):
- Operational excellence — W3C Trace Context in
_meta(traceparent/tracestate/baggage) traces end-to-end through any OpenTelemetry backend incl. CloudWatch;Mcp-Method/Mcp-Nameheaders and a requiredresultTypefield (complete/input_required) give gateways per-operation signals without body parsing; protocol logging deprecated in favor ofstderr/OTel. - Security — clients must validate the
issparam (RFC 9207) and declareapplication_typeat registration (Dynamic Client Registration itself is now deprecated in favor of Client ID Metadata Documents); MRTR bounds when a server can prompt a human; because state identifiers are model-visible, servers must enforce ownership on every call and treatrequestStateas untrusted input, protecting integrity with HMAC or AEAD; tool I/O schemas validated against JSON Schema 2020-12. - Reliability — stateless transport makes instance loss a non-event;
requestStatecontinuation tokens resume interrupted multi-step interactions; stream resumability was removed so tools must be idempotent on client re-issue; standardized error-code ranges (-32000..-32019 implementation-defined, -32020..-32099 reserved) give canonical retry/backoff/circuit-break signals. - Performance efficiency — protocol-declared caching (
ttlMs+cacheScope, now required on list/resource-read results); deterministic tool-list ordering enables LLM prompt-cache hits; header-based routing avoids body parsing. - Cost optimization — delete session infrastructure that exists only to
preserve sessions. A two-node ElastiCache
cache.t4g.microsession store is ~$23/month (AWS Pricing Calculator, July 2026); the larger saving is eliminating an entire class of infra + its operational burden, and sticky routing's uneven load distribution. Serverless (Lambda) moves from workaround to first-class pattern. -
Sustainability — no pinned-session capacity means no instance must stay warm to hold a session; right-size against real traffic, not theoretical peak.
-
Backward-compat lane has a clock. The 2026-07-28 spec keeps a backward-compatible lane for pre-2026-07-28 (2025-11-25) clients. Keep ALB stickiness and the DynamoDB/ElastiCache session store until old-client traffic reaches zero. Instrument the gateway to log protocol version per request, set a sunset date, communicate it to client teams, and only then decommission — the dual-route drain-then-remove shape.
-
Deprecations have a 12-month floor. Roots, Sampling, Logging, and the HTTP+SSE transport are deprecated with a twelve-month minimum before removal (earliest July 2027).
ping,logging/setLevel, andnotifications/roots/list_changedwere removed outright; log level moved into per-request_meta. Migration paths: directories via tool params/resource URIs (not Roots), direct LLM-provider APIs (not Sampling),stderr/OTel (not Logging), Streamable HTTP (not HTTP+SSE). This is the feature-lifecycle policy in action. -
New operational surfaces to watch.
subscriptions/listenconsolidates change notifications into a single opt-in POST-response stream (check idle timeouts across LB/proxy/compute). MCP Apps puts server-supplied HTML inside the host (iframesandboxing + auditable JSON-RPC + pre-declared UI templates — treat template review as mandatory, decide which servers may ship UI).cacheScope: "public"is a multi-tenant disclosure risk — default to"private", widen only for responses identical across callers. -
Guardrails against future breaks. Three mechanisms shipped with the stateless core: the feature-lifecycle policy (Active/Deprecated/Removed, ≥12mo floor), an extensions framework (opt-in capabilities prove themselves outside the core — where Tasks landed after redesign), and a conformance suite every Standards-Track proposal must satisfy before reaching Final (the same suite the official SDKs validate against).
Operational numbers¶
- MCP stateless revision published 2026-07-28; blog post 2026-09-01.
- Deprecated features: ≥12-month floor before removal; earliest removal July 2027; DCR removal targeted after summer 2027.
- Standardized error codes: -32000..-32019 implementation-defined; -32020..-32099 reserved for MCP.
- Example session-store cost: two-node ElastiCache
cache.t4g.micro≈ $23/month (AWS Pricing Calculator, July 2026) — cited as the small part of the saving. - Resource-not-found error code migration:
-32002→-32602.
Systems / concepts / patterns extracted¶
- Systems: MCP (2026-07-28 stateless revision), AWS Lambda (now first-class MCP host), ElastiCache + DynamoDB (session stores now deletable), ALB (stickiness now removable), CloudWatch + OpenTelemetry (tracing/logging backends), Amazon Bedrock AgentCore / AgentCore Gateway (managed path that handles protocol + back-compat).
- Concepts: concepts/stateless-compute, multi-round-trip-request, feature-lifecycle-deprecation-policy, concepts/idempotent-operations, well-architected-framework (new), protocol-declared-caching (new).
- Patterns: protocol-metadata-in-http-headers, patterns/shadow-migration, delete-session-infrastructure (new), idempotent-retry-on-broken-stream (new), server-minted-continuation-token (new).
Caveats¶
- This is an architecture/guidance post, not a production retrospective: the only hard number is an illustrative ElastiCache price; no throughput, latency, or fleet-size figures from a real migration.
- Guidance applies to session infrastructure built to compensate for the old protocol. Managed hosts that offer session features by design for specific use cases are explicitly out of scope.
- The core claims (statelessness, MRTR, deprecation windows, headers, caching
fields) mirror Cloudflare's 2026-08-06 write-up of the same spec revision — see
sources/2026-08-06-cloudflare-the-next-generation-of-mcp. The AWS post adds
the Well-Architected framing, the AWS-service deployment table, cost/sustain
ability angles, and
server/discover,resultType, and standardized error-code detail.
Source¶
- Original: https://aws.amazon.com/blogs/architecture/mcp-went-stateless-is-your-aws-mcp-server-deployment-well-architected/
- Raw markdown:
raw/aws/2026-09-01-mcp-went-stateless-is-your-aws-mcp-server-deployment-well-ar-7d5b6832.md
Related¶
- systems/model-context-protocol — the protocol; 2026-07-28 stateless revision
- concepts/stateless-compute — the core design shift
- multi-round-trip-request — replaces server-initiated push
- protocol-metadata-in-http-headers —
Mcp-Method/Mcp-Namerouting - patterns/shadow-migration — the backward-compat lane
- sources/2026-08-06-cloudflare-the-next-generation-of-mcp — Cloudflare's take on the same spec