AgentCore Gateway adopts major MCP 2026-07-28 spec revision

The MCP 2026-07-28 specification is described by AWS as the protocol's largest revision since launch. The headline changes: MCP becomes stateless, gains a governed extensions system, and adds hardened authorization — all aimed at making agent-to-tool connections more secure and scalable for enterprise deployment. Amazon Bedrock AgentCore Gateway can move to the new version with a single UpdateGateway call, minimizing migration friction for existing customers.
The practical payoff AWS showcased is configuration-over-code business intelligence: AgentCore delivers cross-system insights through pre-built MCP connectors, fine-grained access control and persistent memory, letting factory managers and analysts query fragmented legacy data in natural language without custom integration work. AgentCore orchestrates agent execution in isolated microVMs, enforces access policies, and caches results to reduce latency. AWS also detailed Private Key JWT authentication in AgentCore Identity, covering KMS signing keys, credential providers and CloudTrail auditing.
The security emphasis is notable given the week's autonomous-agent breach: hardened authorization and microVM isolation are precisely the systems-level controls the community demanded after the Hugging Face incident. Positioning AgentCore as the secure, governed backbone for enterprise agents is a direct response to 'sandboxes don't suffice' skepticism.
Competitively, MCP has become the de facto interoperability layer — Google's Gemini API now supports remote MCP, and Anthropic originated the protocol — so AWS shipping day-one support for the new spec keeps Bedrock aligned with the broader ecosystem. What to watch is adoption: a stateless, extension-governed MCP only matters if tool vendors and agent frameworks actually migrate, and large spec revisions historically fragment ecosystems before they consolidate.