← Files MCP BoundaryARCHIVED FILE
skills/mcp-boundary/references/profiles/mcp-2025-11-25.md
5.37 KB · Oct 5, 2026 · 18:34 UTC
--- profile_id: mcp-2025-11-25 profile_version: 1 assessed_at: 2026-08-15 status: historical-supported language: en language_peer: mcp-2025-11-25.zh-CN.md --- # MCP profile: 2025-11-25 This profile describes implementations that intentionally speak MCP revision `2025-11-25`. It preserves the stateful lifecycle era while incorporating the November 2025 feature and security changes. ## Normative sources - [Specification index](https://modelcontextprotocol.io/specification/2025-11-25) - [Key changes from 2025-06-18](https://modelcontextprotocol.io/specification/2025-11-25/changelog) - [Lifecycle](https://modelcontextprotocol.io/specification/2025-11-25/basic/lifecycle) - [Transports](https://modelcontextprotocol.io/specification/2025-11-25/basic/transports) - [Authorization](https://modelcontextprotocol.io/specification/2025-11-25/basic/authorization) Normative requirements remain in the linked specification. ## Protocol shape - The `initialize` / `notifications/initialized` lifecycle and negotiated protocol version remain authoritative. - Streamable HTTP still permits optional protocol sessions through `MCP-Session-Id`, request-scoped SSE responses, a GET SSE channel, and resumability with `Last-Event-ID`. - A present invalid `Origin` has an explicit transport outcome: HTTP `403 Forbidden`. - Polling SSE is supported: a server may close a connection without terminating its logical stream, while event IDs and retry behavior carry the resumption contract. - URL-mode elicitation, tool use during sampling, OAuth Client ID Metadata Documents, incremental scope consent, icons, and experimental tasks enter the feature surface. - JSON Schema 2020-12 is the default dialect for MCP schema definitions. - Input validation failures during a tool call are tool execution errors so a model can correct arguments; they are not automatically protocol errors. ## Streamable HTTP obligations - Use one MCP endpoint for POST and GET. - Validate `Origin`; if it is present and invalid, return HTTP 403. A missing `Origin` is not identical to an invalid present value—define policy separately. - Require `Accept` negotiation and a single JSON-RPC message per POST. - Return HTTP 202 without a body for an accepted notification or response. - Return JSON or a request-scoped SSE stream for a request. - If implementing polling or resumability, make event IDs identify the originating stream and resume through GET with `Last-Event-ID`. - If issuing `MCP-Session-Id`, own its generation, secure handling, lookup, expiry, termination, and 404 semantics. - Send `MCP-Protocol-Version` on subsequent requests; reject unsupported versions. ## Implementation consequences 1. Keep transport session state distinct from application operation state. A session ID is not a substitute for an idempotency key or authorization subject. 2. Model polling SSE as a stateful feature. Closing the TCP connection must not silently discard the logical stream if resumability is claimed. 3. Preserve `stderr` as the logging channel for stdio; `stdout` contains only valid MCP messages. 4. Validate schemas under JSON Schema 2020-12 assumptions and bound recursive/composed schema work. 5. Keep URL elicitation and experimental tasks behind explicit capability declarations and host-compatibility evidence. 6. Treat tool annotations, icons, descriptions, and validation-error classification as behavior visible to both host and model. ## Revision-bound test obligations - Stateful lifecycle ordering and re-initialization tests. - Explicit HTTP 403 for a present disallowed `Origin`; exact allowlist echo for permitted cross-origin use. - No JSON-RPC batch acceptance. - Notification/response POSTs yield HTTP 202 with no body. - Session issuance is either absent or backed by secure uniqueness, request validation, expiry, termination, and 404 behavior. - Polling SSE reconnection preserves stream identity and honors retry timing without replaying another stream's messages. - Tool input validation failures use the tool-result error channel expected by this revision. - Experimental task, URL elicitation, and sampling-tool capabilities are absent unless fully implemented and tested with the intended host. ## Migration boundary from 2025-06-18 Do not infer support from a shared lifecycle shape. The explicit invalid-Origin 403 behavior, polling SSE rules, JSON Schema dialect, URL elicitation, sampling tools, registration guidance, and tasks require individual implementation and tests. ## Migration boundary to 2026-07-28 The next revision removes the lifecycle and session architecture this profile depends on. It also removes GET-based general server streams and SSE resumability, replaces server-initiated requests with Multi Round-Trip Requests, requires request metadata in `_meta`, adds `server/discover` and HTTP routing headers, and moves tasks into an extension. See the [2026-07-28 profile](mcp-2026-07-28.md). Compatibility should be an explicit adapter or negotiated mode. Do not leave old session checks partially active after selecting the stateless revision. ## Known unknowns - Host support for polling SSE, URL elicitation, experimental tasks, and Client ID Metadata Documents varies. - A framework may generate or consume session and version headers before application dispatch; inspect the real hook order. - Authorization topology cannot be proven from application code alone. - Current ecosystem recommendations may have moved since this profile's assessment date.
SHA-256: ec024345678601db437ea981a32713623a41f53f505fcd0fd7292c4849068b45