# MCP-RES v0.2 research ledger

Observation date: **2026-08-27**. This ledger is additive; the historical [v0.1 research record](../v0.1.0/RESEARCH.md) is not rewritten. Commit references were resolved from the official repositories on the observation date. “Normative” below describes the upstream source, not MCP-RES status.

## Primary-source decisions

| Source                                                                                                                                                                                                    | Immutable reference                                                                                                            | Upstream status                                                     | Normative / proposed                | MCP-RES implication                                                                                                       | Decision                                                          |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------- |
| [MCP 2026-07-28](https://github.com/modelcontextprotocol/modelcontextprotocol/tree/5f5440bb26a62e2cf3440b92da5a667efa03b267/docs/specification/2026-07-28)                                                | tag target `5f5440bb26a62e2cf3440b92da5a667efa03b267`                                                                          | released                                                            | normative                           | Protocol identity must distinguish this revision from 2025-11-25.                                                         | adopt identity; observe behavior in PR 3                          |
| [MCP current draft](https://github.com/modelcontextprotocol/modelcontextprotocol/tree/d8fdc88fb970313247d8a180ac1ec3f6a10a8885/docs/specification/draft)                                                  | `d8fdc88fb970313247d8a180ac1ec3f6a10a8885`                                                                                     | development head                                                    | proposed                            | Draft behavior cannot silently enter normative profiles.                                                                  | observe / defer                                                   |
| [MCP changelog](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/d8fdc88fb970313247d8a180ac1ec3f6a10a8885/docs/specification/draft/changelog.mdx)                                        | same commit                                                                                                                    | accumulating draft                                                  | proposed                            | No released post-2026-07-28 revision exists at observation time.                                                          | observe                                                           |
| [MCP roadmap](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/d8fdc88fb970313247d8a180ac1ec3f6a10a8885/docs/development/roadmap.mdx)                                                    | same commit; page updated `2026-08-22`                                                                                         | non-binding roadmap                                                 | proposed                            | Agentic messaging, HTTP-native transport/caching, identity, result shape, and SDK work remain moving dependencies.        | defer normative claims                                            |
| [Official conformance main](https://github.com/modelcontextprotocol/conformance/tree/74edef34d674f563537be8c6587cebaa58e830ca)                                                                            | `74edef34d674f563537be8c6587cebaa58e830ca`                                                                                     | `0.2.0-alpha.11` development                                        | implementation, not specification   | Attach exact suite/ref, requirement set, roles, command, results, and expected failures.                                  | adapt in PR 3                                                     |
| [Official conformance v0.1.16](https://github.com/modelcontextprotocol/conformance/tree/21a9a2febd7100d7c17ac1021ee7f2ed9f66a1e0)                                                                         | tag target `21a9a2febd7100d7c17ac1021ee7f2ed9f66a1e0`                                                                          | latest stable tag observed                                          | implementation                      | Stable and main/alpha results must not be conflated.                                                                      | observe                                                           |
| [2025-11-25 requirements](https://github.com/modelcontextprotocol/conformance/blob/74edef34d674f563537be8c6587cebaa58e830ca/requirements/2025-11-25.yaml)                                                 | Git blob `cc29607b78868a33563900f3fafd24af6c301a7a`                                                                            | maintained requirement set                                          | derived from normative spec         | Coverage is revision-specific.                                                                                            | adapt in PR 3                                                     |
| [2026-07-28 requirements](https://github.com/modelcontextprotocol/conformance/blob/74edef34d674f563537be8c6587cebaa58e830ca/requirements/2026-07-28.yaml)                                                 | Git blob `b0c4f8560429e8f4b6c89833cc0b35405bc004ff`                                                                            | maintained requirement set                                          | derived from normative spec         | A result must name this exact requirement set.                                                                            | adapt in PR 3                                                     |
| [TypeScript SDK v2](https://github.com/modelcontextprotocol/typescript-sdk/tree/cc4b41617ce3601b1290d67216ea0b194a3cd9ac)                                                                                 | stable package tag target `cc4b41617ce3601b1290d67216ea0b194a3cd9ac`; observed main `7b781ed4e25355a25d15974f3c76de81299694ed` | v2.0.0 stable                                                       | implementation                      | Use as one field subject; extensions are not core-tier coverage.                                                          | observe / test in PR 3                                            |
| [Python SDK v2](https://github.com/modelcontextprotocol/python-sdk/tree/0921d94a74db900dccd2d534842aa7b6160542d2)                                                                                         | v2.1.1 tag target `0921d94a74db900dccd2d534842aa7b6160542d2`; observed main `6705402e246dc4eb1fcdf4d9902b78d3c9c36e1b`         | v2.1.1 stable                                                       | implementation                      | Tasks, DPoP, and workload identity are recorded by its roadmap as not implemented.                                        | observe / test, never infer                                       |
| [MCP Inspector 2.4.0](https://github.com/modelcontextprotocol/inspector/tree/edf54f5dec5f1fcd6772074f11238d087dd7a1e2)                                                                                    | tag target `edf54f5dec5f1fcd6772074f11238d087dd7a1e2`                                                                          | released `2026-08-26`                                               | diagnostic implementation           | Inspector evidence is diagnostic, not official conformance.                                                               | observe                                                           |
| [Tasks extension](https://github.com/modelcontextprotocol/ext-tasks/tree/0d0a6bd4c258b35caa3c810a1dd506cf105b1501/specification/2026-07-28)                                                               | main `0d0a6bd4c258b35caa3c810a1dd506cf105b1501`                                                                                | 2026-07-28 stable extension plus separate draft                     | normative extension when negotiated | Tasks are outside core; profile exact extension ID/revision.                                                              | adapt provisionally in PR 3                                       |
| [MCP Apps](https://github.com/modelcontextprotocol/ext-apps/tree/92f46a574568a3ddac7600343b7d3c4c4ed7b588)                                                                                                | v1.7.5 tag target `92f46a574568a3ddac7600343b7d3c4c4ed7b588`                                                                   | released SDK; stable `2026-01-26` specification and draft coexist   | extension                           | Do not treat app bridge/UI behavior as core MCP behavior.                                                                 | profile boundary in PR 3                                          |
| [Authorization extensions](https://github.com/modelcontextprotocol/ext-auth/tree/fb374c7db2b34f18ca9183882e0beecdf661892b)                                                                                | `fb374c7db2b34f18ca9183882e0beecdf661892b`                                                                                     | enterprise-managed auth stable; client credentials draft            | mixed                               | Each extension needs its own status and negotiation evidence.                                                             | defer/profile in PR 4                                             |
| [MCP authorization](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/5f5440bb26a62e2cf3440b92da5a667efa03b267/docs/specification/2026-07-28/basic/authorization.mdx)                     | released tag target above                                                                                                      | released                                                            | normative                           | OAuth boundary reliability must bind resource, audience, discovery, and redirects.                                        | adapt in PR 4                                                     |
| [MCP security best practices](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/5f5440bb26a62e2cf3440b92da5a667efa03b267/docs/specification/2026-07-28/basic/security_best_practices.mdx) | released tag target above                                                                                                      | released                                                            | normative guidance                  | Token passthrough, confused deputy, SSRF, session hijacking, and local-server risks require negative evidence.            | adapt in PR 4                                                     |
| [JSON Schema 2020-12](https://json-schema.org/draft/2020-12/json-schema-core.html)                                                                                                                        | dated dialect `2020-12`                                                                                                        | published                                                           | normative specification             | Schemas use the 2020-12 dialect.                                                                                          | adopt                                                             |
| [RFC 2119](https://www.rfc-editor.org/rfc/rfc2119) and [RFC 8174](https://www.rfc-editor.org/rfc/rfc8174)                                                                                                 | RFC 2119 / RFC 8174                                                                                                            | published                                                           | normative                           | Requirement keywords are used only in their special uppercase form.                                                       | adopt                                                             |
| [RFC 8785](https://www.rfc-editor.org/rfc/rfc8785)                                                                                                                                                        | RFC 8785                                                                                                                       | published                                                           | normative                           | Cross-language JSON differences must reject explicitly; replacing the historical algorithm would break digest continuity. | retain explicit v1 algorithm; defer a versioned dual-hash profile |
| [RFC 8707](https://www.rfc-editor.org/rfc/rfc8707)                                                                                                                                                        | RFC 8707                                                                                                                       | published                                                           | normative                           | Authorization-code and token requests need resource binding tests.                                                        | adapt in PR 4                                                     |
| [OAuth 2.1](https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-1/15/)                                                                                                                                   | `draft-ietf-oauth-v2-1-15`, `2026-03-02`                                                                                       | Internet-Draft                                                      | proposed                            | Never label OAuth 2.1 an RFC; pin the draft revision.                                                                     | observe                                                           |
| [OAuth Security BCP](https://www.rfc-editor.org/rfc/rfc9700)                                                                                                                                              | RFC 9700 / BCP 240                                                                                                             | published                                                           | normative best current practice     | PKCE, redirect, state, mix-up, and token handling need negative paths.                                                    | adapt in PR 4                                                     |
| [DPoP](https://www.rfc-editor.org/rfc/rfc9449)                                                                                                                                                            | RFC 9449                                                                                                                       | published                                                           | normative                           | MCP SDK support is incomplete; keep future identity profiles experimental.                                                | defer/profile experimentally                                      |
| [OAuth token exchange](https://www.rfc-editor.org/rfc/rfc8693)                                                                                                                                            | RFC 8693                                                                                                                       | published                                                           | normative                           | Do not imply MCP workload-delegation support without negotiated implementation evidence.                                  | defer                                                             |
| [in-toto Attestation](https://github.com/in-toto/attestation/tree/2dcd055e9f72e746687c306e35f4e59720ff45be)                                                                                               | main `2dcd055e9f72e746687c306e35f4e59720ff45be` (v1.2.0 observed)                                                              | released model                                                      | specification                       | Attestation claims must name predicate and subject digest.                                                                | adapt in PR 2                                                     |
| [DSSE](https://github.com/secure-systems-lab/dsse/tree/1d3370f62565bca041e97c8310b873ac340edc2e)                                                                                                          | `1d3370f62565bca041e97c8310b873ac340edc2e`                                                                                     | published protocol                                                  | specification                       | Optional envelope can bind payload bytes and signer identity.                                                             | adapt in PR 2                                                     |
| [SLSA](https://github.com/slsa-framework/slsa/tree/1686afeba11a456e470235ecf50cfc0d2f9ecbc3)                                                                                                              | `1686afeba11a456e470235ecf50cfc0d2f9ecbc3`                                                                                     | current framework source                                            | framework                           | A GitHub attestation alone does not establish an unmeasured SLSA level.                                                   | observe / reject overclaim                                        |
| [Sigstore Cosign](https://github.com/sigstore/cosign/tree/58aae9e112fa1de80594eed34667e920ac4d4a3b)                                                                                                       | main `58aae9e112fa1de80594eed34667e920ac4d4a3b` (v3.1.3 observed)                                                              | released implementation                                             | implementation                      | Verification procedure must be explicit and offline behavior tested.                                                      | adapt in PR 2                                                     |
| [GitHub build provenance action](https://github.com/actions/attest-build-provenance/tree/4d101475d8b20a2381f78447822ac1eab6504dd8)                                                                        | `4d101475d8b20a2381f78447822ac1eab6504dd8` (v4.2.2)                                                                            | released action                                                     | implementation                      | Release workflow can issue GitHub artifact attestations with least privileges.                                            | adopt in PR 2                                                     |
| [GitHub attest action](https://github.com/actions/attest/tree/508db95dd578ae2727ebd6217d5ba78e4fbda05d)                                                                                                   | `508db95dd578ae2727ebd6217d5ba78e4fbda05d` (v4.2.1)                                                                            | released action; dedicated `attest-sbom` action observed deprecated | implementation                      | SBOM attestation is distinct from build provenance; use the current general attest action.                                | adopt in PR 2                                                     |

## Official conformance gap audit

No upstream comment, issue, or pull request was created. State is as observed on `2026-08-27`.

| Gap                                         | Official record                                                                                                                                           | State                          | Exact implication                                                                                      |
| ------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------ | ------------------------------------------------------------------------------------------------------ |
| Wrong-reason negatives / false greens       | [conformance#467](https://github.com/modelcontextprotocol/conformance/issues/467)                                                                         | **open**, updated `2026-08-25` | Verdict-only expected failures are insufficient; PR 1 adds reason-bound reachability and stop reasons. |
| Raw HTTP and inline mocks bypass validation | [conformance#418](https://github.com/modelcontextprotocol/conformance/issues/418)                                                                         | **open**                       | Coverage must disclose uninstrumented/bypassed traffic.                                                |
| Extension result envelopes                  | [conformance#424](https://github.com/modelcontextprotocol/conformance/issues/424)                                                                         | **open**                       | Core result validation must allow negotiated extension branches without accepting arbitrary envelopes. |
| Streamed `resultType`                       | [conformance#461](https://github.com/modelcontextprotocol/conformance/issues/461)                                                                         | **open**                       | Streamed tool result tests need the released discriminator rule.                                       |
| Safe-integer behavior                       | [conformance#445](https://github.com/modelcontextprotocol/conformance/issues/445)                                                                         | **open**                       | SDK acceptance must not substitute for explicit boundary vectors.                                      |
| OAuth resource parameter                    | [conformance#465](https://github.com/modelcontextprotocol/conformance/issues/465)                                                                         | **open**                       | The authorization-code path needs direct RFC 8707 observation.                                         |
| Bounded raw-session probes                  | [conformance#428](https://github.com/modelcontextprotocol/conformance/issues/428)                                                                         | **open**                       | Raw probes need finite timeout/body consumption/cleanup evidence.                                      |
| Requirement-set coverage                    | [conformance#451](https://github.com/modelcontextprotocol/conformance/issues/451)                                                                         | **open**                       | Results must distinguish required/emitted checks and uncovered requirements.                           |
| Stale expected-failure behavior             | [conformance#426](https://github.com/modelcontextprotocol/conformance/issues/426)                                                                         | **open**                       | A fixed behavior must not remain green merely because an expected-failure entry is stale.              |
| Stateless fixture prerequisite              | [conformance#382](https://github.com/modelcontextprotocol/conformance/issues/382)                                                                         | **closed/completed**           | Preserve prerequisite reachability evidence so equivalent regressions cannot recur invisibly.          |
| Granular expected failures                  | [conformance#404](https://github.com/modelcontextprotocol/conformance/issues/404)                                                                         | **closed/completed**           | Granularity helps but does not replace reason-bound observation.                                       |
| Tasks scenarios                             | [conformance#260](https://github.com/modelcontextprotocol/conformance/issues/260), [#261](https://github.com/modelcontextprotocol/conformance/issues/261) | **closed/completed**           | Attach exact extension/revision and requirement coverage in PR 3.                                      |

## Research limits

Repository heads are observations, not stability promises. MCP-RES adopts released normative behavior only when the owning profile names it. Roadmaps, drafts, open issues, and SDK implementation state are evidence for gap disposition, never substitutes for the released MCP specification.
