Sources for every figure, date, name and quotation the finished picture puts on screen.
The roadmap page is dated 2026-08-22 and states five priority areas, in this order:
The roadmap ranks nothing and gives no relative weighting, which is why the picture draws the five as equal columns rather than as a bar chart.
The deliverables named on screen for each area are the ones the page lists for this roadmap period:
ttlMs and cacheScope (SEP-2549) toward ETags.tools/call interface);
progressive discovery; primitive annotations.Source: https://modelcontextprotocol.io/development/roadmap
The roadmap page states the problem it is solving in agent identity as: “MCP authorization assumes a person with a browser at consent time. Increasingly the caller is an agent: a cloud workload with its own identity, acting for a user who isn’t present, or spawning sub-agents that should get narrower authority than their parent.”
Source: https://modelcontextprotocol.io/development/roadmap
Both are quoted verbatim from the roadmap announcement of 22 August 2026.
Source: https://blog.modelcontextprotocol.io/posts/mcp-roadmap/
The changelog entries the picture renders are quoted from the specification’s own list of major and minor changes:
Mcp-Session-Id header were removed from the Streamable
HTTP transport; list endpoints no longer vary per connection (SEP-2567).initialize / notifications/initialized handshake was
removed, and every request now carries its protocol version and client capabilities in
_meta (SEP-2575).server/discover was added, which servers must implement to advertise supported protocol
versions, capabilities and identity (SEP-2575).Last-Event-ID header, were
removed (SEP-2575).io.modelcontextprotocol/tasks. The redesigned extension replaces the blocking
tasks/result method with polling via tasks/get, adds tasks/update for
client-to-server input, removes tasks/list, and allows servers to return task handles
unsolicited (SEP-2663).InputRequiredResult
(resultType: "input_required") whose inputRequests field carries what it needs; the
client responds with inputResponses on a retry of the original request (SEP-2322).Mcp-Method and Mcp-Name are required on Streamable
HTTP POST requests (SEP-2243). This is what the picture shows a gateway reading.ttlMs and cacheScope are required on results returned by tools/list,
prompts/list, resources/list, resources/read and resources/templates/list, via a
new CacheableResult interface. cacheScope is "public" or "private" and controls
whether shared intermediaries may cache the response (SEP-2549).Source: https://modelcontextprotocol.io/specification/2026-07-28/changelog
Every number the picture renders is computed from the thing it is drawn beside rather than typed next to it, so the figure and the drawing cannot disagree:
The three sizes used to make the catalog argument (ten, fifty, two hundred) are the script’s own wording and are illustrative rather than measured; they are drawn as the exact counts the narration says.
repo.search, ci.logs, incidents.timeline and the rest) are invented for
the illustration. No real organisation’s MCP server is depicted.