ScreenshotNeo

BlogAI agents

Are MCP Servers Dead? The Current State of MCP

MCP is active, but compatibility and deployment changed. Learn what the 2026-07-28 release means for servers, clients, state, and security.

By the ScreenshotNeo team1 October 20264 min read

Are MCP Servers Dead? The Current State of MCP

No. MCP servers are not dead. Maintainers released the 2026-07-28 specification and a roadmap on 2026-08-22. The practical question is whether a particular server is maintained, compatible with your client, secure, and useful.

Why MCP is still active

The dated releases are direct evidence of protocol work. Maintainers report nearly half a billion monthly downloads across Tier 1 SDKs; TypeScript and Python SDKs each exceed one billion total downloads. Anthropic reports more than 400 million monthly SDK downloads. These are publisher-reported downloads, not counts of active servers, unique developers, production deployments, or successful calls.

Anthropic donated MCP to the Agentic AI Foundation under the Linux Foundation. Claude rollout of the 2026-07-28 release is underway, but support varies by product and version. Verify the client and server versions you deploy.

What changed in the 2026-07-28 release

Stateless core

The protocol core moved toward request/response statelessness. Remote servers can scale horizontally as ordinary HTTP workloads without protocol-level sessions. If an application needs continuity, mint an opaque server handle and pass it as a normal tool argument. Store it in a shared database or cache, scope it to the principal, and give it an expiry.

A stateless core lets HTTP infrastructure distribute requests while application state lives behind an explicit handle.
A stateless core lets HTTP infrastructure distribute requests while application state lives behind an explicit handle.

Other changes

  • Multi Round-Trip Requests support interactions requiring several turns.
  • Header-based routing fits normal HTTP infrastructure.
  • List results can be cached when freshness and authorization allow.
  • Authorization hardening is included, but it does not secure an incorrectly configured deployment.
  • An extensions framework moves evolving capabilities out of the smallest core.
  • Tier 1 SDKs were updated.

The changelog moved Tasks into an official extension and deprecates includeContext values thisServer and allServers. Do not assume automatic compatibility with older clients or servers.

How MCP messages work

MCP uses JSON-RPC 2.0. A request includes a method, id, and parameters; the response repeats the id.

{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/list",
  "params": {}
}

For remote deployments, use TLS, authentication, rate limits, request IDs, and normal HTTP observability.

Compatibility checklist

Area Check
Revision Do both sides support 2026-07-28 or a compatible revision?
Extensions Is the feature core or an extension enabled by both sides?
State Can calls be independent, or do you need scoped, expiring handles?
Authorization Are credentials least-privilege, rotated, and validated?
Operations Can you measure latency, errors, and upstream failures without secrets?

Deployment patterns

  1. Terminate TLS and authenticate at the edge.
  2. Route requests to any healthy instance.
  3. Keep durable workflow state outside the process and pass an opaque handle.
  4. Use idempotency keys and bounded retries.
  5. Expire handles, tasks, and credentials explicitly.

Smoke-test a remote server

cURL

curl -sS https://mcp.example.com/mcp \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  --data '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'

Python

import requests
payload = {"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}
r = requests.post("https://mcp.example.com/mcp", json=payload, headers={"Authorization":"Bearer YOUR_TOKEN"}, timeout=30)
r.raise_for_status()
print(r.json())

Node.js

const payload = { jsonrpc: '2.0', id: 1, method: 'tools/list', params: {} };
const res = await fetch('https://mcp.example.com/mcp', { method: 'POST', headers: { 'content-type': 'application/json', authorization: 'Bearer YOUR_TOKEN' }, body: JSON.stringify(payload) });
if (!res.ok) throw new Error(String(res.status));
console.log(await res.json());

Performance, reliability, and cost

  • Multiple round trips add latency; keep schemas focused.
  • Stateless instances scale, but databases and upstream APIs can bottleneck.
  • Use request IDs, idempotency, backoff, cancellation, and expiry.
  • Cache only when freshness and tenant authorization permit.
  • Budget model tokens, compute, transfer, upstream calls, and logging. SDK downloads are not a usage forecast.

Troubleshooting

Symptom Cause and fix
Method not found Revision or extension mismatch. Inspect capabilities and use a compatible SDK.
Invalid params Schema mismatch. Fetch the current tool schema and validate JSON.
401/403 Expired or wrongly scoped credentials. Refresh and verify proxy headers.
Only one instance works In-memory state. Move it to shared storage and pass an explicit handle.
Duplicate side effect Retry after an ambiguous timeout. Add idempotency.
Stale tools list Cache too long. Honor cache directives and invalidate after changes.
Timeout Use the supported async or task extension, polling, or a webhook.
ScreenshotNeo connects an agent request to a cleaned screenshot or PDF.
ScreenshotNeo connects an agent request to a cleaned screenshot or PDF.

ScreenshotNeo as an MCP example

ScreenshotNeo is a website screenshot API and MCP server with take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients. See the docs.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key":"YOUR_API_KEY","url":"https://stripe.com"}, timeout=90)
open("shot.webp","wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch('https://api.screenshotneo.com/v1/shot?' + q);

It supports full-page and element capture, device presets, retina scale, dark mode, PDFs, HTML/CSS, custom scripts, clicks, waits, blocking, headers, cookies, user agents, Authorization, timezone, geolocation, transparency, resizing, caching, signed links, async webhooks, bulk capture, usage, and OpenAPI. Consent banners, newsletter popups, and chat widgets are removed before capture. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed; responses include X-Page-Verdict and X-Billed.

FAQ

Does stateless mean no application state?

No. Keep state in your application and pass a scoped, expiring handle.

Do downloads prove production adoption?

No. They measure publisher-reported SDK downloads.

Will every client support the new release?

No. Check exact client and server versions and extensions.

Or skip the browser setup

ScreenshotNeo removes cookie banners, popups, and chat widgets before the shot. Bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents capture screenshots and PDFs; 1,000 screenshots a month are free with no card and paid plans start at $5 for 3,000.

Create a free ScreenshotNeo account.