MCP’s Biggest Update Made AI Agents Scale. It Also Turned a Prompt Into a Password. The Model Context Protocol's July 28, 2026 update made MCP fully stateless, replacing the initialize handshake and Mcp-Session-Id header with a portable session credential called a handle that lives in the model's context window, creating a new attack path security researchers call handle hijacking. The spec's own security guidance states servers MUST NOT treat possession of a state handle as authentication, yet a planted instruction in a Jira ticket, scraped page, or tool response can make an agent replay a validly signed handle belonging to another user, such as Sarah's report, and the server will accept the call because the signature is valid. The release, the largest in MCP's history, also tightened authentication toward OAuth with an Enterprise Managed Authorization extension built with Okta and added a formal deprecation policy giving enterprises roughly a year to migrate; Anthropic donated MCP to the Agentic AI Foundation, co-founded with OpenAI and Block, which launched December 9, 2025 and grew past 170 member organizations in four months. People love posting a photo of their boarding pass before a trip. But that barcode is not decoration. Anyone who scans it can pull up the booking, and sometimes change or cancel it. The airline’s system sees a valid code and does what it asks. It never checks who is holding the phone. On July 28, 2026, the Model Context Protocol MCP started working a lot like that boarding pass. It was a smart change. It lets agent tools scale like ordinary web services. But it also created a new kind of pass, called a handle. And that pass now lives in the most public place in any agent system: the model’s own conversation. This article explains what changed, how a single planted sentence can turn into a stolen credential, and the four simple checks that close the gap. MCP is the connecting layer that lets AI agents call tools, read files, and hit APIs on a user’s behalf. If an agent books a meeting, updates a Jira ticket, or queries a database, there is a good chance MCP sits in the middle. Anthropic donated MCP to the Agentic AI Foundation AAIF when the Linux Foundation-hosted body launched on December 9, 2025. Anthropic, OpenAI, and Block co-founded it, with platinum members including AWS, Bloomberg, Cloudflare, Google, and Microsoft. The foundation grew past 170 member organizations in its first four months. So when MCP changes, a large part of the agent ecosystem changes with it. The July 28 release was the biggest update in MCP’s history. It did three things at once. 1. MCP went fully stateless. The old initialize handshake and the Mcp-Session-Id header are gone. Each request now stands on its own, so MCP servers can run behind a normal cloud load balancer. 2. Authentication got stricter. The spec aligns more closely with OAuth and adds an Enterprise Managed Authorization extension, built with Okta, so corporate identity providers can gate MCP access directly. 3. A formal deprecation policy arrived. Enterprises now get a guaranteed window, roughly a year, to migrate before old features are removed. None of this was cosmetic. It is the kind of change that lets MCP grow the way ordinary web infrastructure does. But going stateless raised one hard question: if the server no longer remembers the session, who does? MCP’s answer is a portable handle . Think of it as a session credential packed into a short string, something like h 9f2c41ab. The server gives it to the agent, and the agent passes it back on later calls. Here is the problem. That handle sits in the model’s context window. To the model, it is text like any other text. And anything that can put text in front of the model can also read that handle or reuse it. A natural fix is to sign the handle, the way a JWT is signed. Signing is useful. It stops an attacker from forging a fake handle. But it does nothing to stop someone from reusing a real one. The signature answers “is this handle authentic?” It never answers “is the right caller presenting it?” The spec itself is clear on this point. Its security guidance says servers MUST NOT treat possession of a state handle as authentication. In boarding-pass terms: a valid barcode is not proof that it is your flight. Walk through it step by step: 1. An agent working for Sarah gets a real, correctly signed handle for her report. 2. Later, the agent reads a Jira ticket, a scraped web page, or a tool response. Hidden inside is an instruction. 3. The instruction tells the model to call a tool using Sarah’s handle. 4. The server checks the signature. It is valid. The call goes through. No server was hacked. No token vault was breached. The attacker only needed one line of text in the right place. That is why security researchers now describe this pattern as handle hijacking: prompt injection is the technique, and a stolen handle is the prize. The handle risk lands on top of a protocol that already has a record of exploited flaws, not just reported ones. The exposure numbers make it an enterprise story, not just a developer-tools story. In one internet scan, Knostic found 1,862 MCP servers exposed with no authentication at all. Government security guidance from the NSA’s AI Security Center has also warned that MCP adoption has moved faster than its security model. Now add handles. Every one of those weak servers is a place where a stolen handle could simply be replayed. The good news is that the fix is not exotic. You do not need a blockchain or a new consensus system. A distributed ledger helps strangers agree on shared history. Broadcasting a bearer credential to more nodes would only widen the exposure. What you need is simpler. Every MCP server should ask four questions on every single request. Here is what that looks like in a few lines of Python: Check 2 is audience binding. A handle issued for server A is useless at server B. Check 3 is a short lifetime, so a leaked handle is only good for a narrow window. OAuth 2.1 already pushes in both directions. Check 4 is the one most teams skip. It ties the handle to the identity it was issued to, so a copied string is worthless in someone else’s hands. There is a real shift hiding here. Before, session enforcement lived deep in the transport layer, invisible to most developers. Now it has to be rebuilt on purpose, at every endpoint. The protocol will not do it for you. The 12-month clock to move to the new spec started the same month researchers found this new hole. That is not a reason to stay on the old spec, which has its own well-documented problems. It is a reason to treat the migration as a security project, not a routine upgrade. Three steps follow directly from how the attack works. 1. Check at the request level. Do not trust anything cached in session state. Every call gets verified on its own. 2. Treat every handle as untrusted input. Handle it the way you would handle any string that came from a tool response or a document the agent read. Check audience, expiry, and caller, not just the signature. 3. Put an identity-aware gate in front of every MCP server. A call without a valid, audience-bound token should be rejected before it ever reaches a tool. Where you can, also strip or flag instruction-like text in tool outputs, since that is where planted handles arrive. • Stateless Is Still the Right Call: Dropping server-side sessions lets MCP scale like normal web infrastructure. The problem is not the design, it is where the credential now lives. • A Signature Is Not an Identity: Signing stops fake handles but not stolen ones. A real handle planted through a poisoned Jira ticket still passes a signature check. • Four Checks Close the Gap: Verify the signature, the audience, the expiry, and the caller on every request. A handle replayed to another server, or by another caller, then fails on its own. A boarding pass photo feels harmless because the barcode looks like decoration. A handle in an agent’s context window looks harmless for the same reason. But anything that can read the conversation can use it. Your agent’s context window is the Instagram post. So check more than the barcode. Check who is holding it. 1. Dashrath, S. “MCP Goes Stateless. MCP Didn’t Become REST. It Just Learned REST’s Lessons.” CodeToDeploy, Medium, Aug 22, 2026. 2. Dashrath, S. “MCP’s Skeleton-Key Exploit.” Towards AWS, Medium, Sept 2026. https://medium.com/towards-aws/mcps-skeleton-key-exploit-ea7c92743745 https://medium.com/towards-aws/mcps-skeleton-key-exploit-ea7c92743745 3. Model Context Protocol. “Security Best Practices” 2026–07–28 specification . https://modelcontextprotocol.io/specification/draft/basic/security best practices https://modelcontextprotocol.io/specification/draft/basic/security best practices 4. Agentic AI Foundation. “What’s Changing in MCP: The 2026–07–28 Release Candidate.” blog.modelcontextprotocol.io 5. VentureBeat. “MCP’s new spec turns a planted prompt into a stolen credential.” Sept 2026. https://venturebeat.com/security/mcps-new-spec-turns-a-planted-prompt-into-a-stolen-credential https://venturebeat.com/security/mcps-new-spec-turns-a-planted-prompt-into-a-stolen-credential 6. VentureBeat. “MCP shipped without authentication. Clawdbot shows why that’s a problem.” Jan 27, 2026. 7. Backslash Security. “New MCP Spec Opens Three New Attack Surfaces.” 2026. 8. NSA AI Security Center. MCP security guidance PDF . media.defense.gov Swapnali Dashrath is a Senior AI Solution Architect with 20+ years of enterprise AI/ML experience, designing agentic AI and multi-agent systems for Fortune 10 and Fortune 100 clients in financial services, automotive, and supply chain. MCP’s Biggest Update Made AI Agents Scale. It Also Turned a Prompt Into a Password. https://pub.towardsai.net/mcps-biggest-update-made-ai-agents-scale-it-also-turned-a-prompt-into-a-password-43b3ff534a89 was originally published in Towards AI https://pub.towardsai.net on Medium, where people are continuing the conversation by highlighting and responding to this story.