# A tool request now carries its own routing record

[Journal](/journal/)

August 14, 2026 · [evidence](/journal/#evidence)



The 2026-07-28 MCP standard puts routing fields and client context on each request. Gateways can record the route without decoding the body.

![A request record enters a gateway instrument, which marks one route across three possible paths.](/_astro/a-tool-request-now-carries-its-own-routing-record.By0P7mdg_1BlCC9.avif)

A tool request should arrive with enough context for a gateway to record its route. The 2026-07-28 Model Context Protocol standard makes that practical.

Model Context Protocol, or MCP, is [a standard that connects models to tools and data](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md). Its maintainers [published the 2026-07-28 version with a stateless protocol core](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md). Stateless means the server [keeps no protocol session shared across requests](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md).

## Routing moves into headers

Streamable HTTP requests [must include `Mcp-Method` and `Mcp-Name`](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md). Those headers [expose the method and tool name to a gateway](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md). It can [route, authorize, and meter a request without parsing its JSON body](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md).

The request also [states its version through `MCP-Protocol-Version`](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md). Its schema [requires the matching `io.modelcontextprotocol/protocolVersion` value in `_meta`](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/schema/2026-07-28/schema.ts).

That makes the routing decision easier to record. A gateway can retain the protocol version, method, tool name, decision, and result as one request record.

## Client context travels with the request

The schema [requires `io.modelcontextprotocol/clientCapabilities` on each request](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/schema/2026-07-28/schema.ts). An empty object [says that the client supports no optional capabilities](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/schema/2026-07-28/schema.ts). A server [must not infer capabilities from an earlier request](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/schema/2026-07-28/schema.ts).

Client software [can also send `io.modelcontextprotocol/clientInfo`](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/schema/2026-07-28/schema.ts). That field [holds the client name and version](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/schema/2026-07-28/schema.ts). The schema [defines this identity as self-reported and unsuitable for security decisions](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/schema/2026-07-28/schema.ts).

This limit matters. A request can state useful context without proving the client’s authority. The record should keep the claimed identity separate from verified authorization facts.

## Session state no longer fills the gaps

The release [removes the `initialize` handshake and the `Mcp-Session-Id` header](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md). Any request [can reach any server instance without shared protocol storage](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md).

Application state can still exist. The maintainers [say a tool can issue an explicit handle for a later request](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md). That handle becomes visible request data instead of hidden transport state.

Authorization changes follow the same boundary. The release [requires RFC 9207 issuer validation before a client redeems a code](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md). It also [binds client credentials to their issuing authorization server](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md).

Dynamic Client Registration [remains for compatibility](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md). This standard [deprecates it in favor of Client ID Metadata Documents](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md). The release also [formalizes an extension framework](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md).

Muniment’s position is that routing and authorization facts belong on the request record. Our connections bind by name to approved MCP registry or local-stdio allowlist entries.

This standard defines fields and behavior. It does not measure production outcomes. The MCP maintainers are neither Muniment customers nor endorsers.

## Sources

1.  [The 2026-07-28 Specification](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/blog/content/posts/2026-07-28-spec-ga/index.md) github.com
2.  [modelcontextprotocol/schema/2026-07-28/schema.ts at main · modelcontextprotocol/modelcontextprotocol · GitHub](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/schema/2026-07-28/schema.ts) github.com
