MCP Con Amsterdam recap, OpenAI MCP Events, WebMCP and MCP news
From the Creator's Desk
AGNTCon + MCPCon Europe 2026 took place at RAI Amsterdam on September 17 and 18. The Agentic AI Foundation (AAIF) and the Linux Foundation organized it: more than 2,000 attendees, 1,000 companies and 100 speakers. The main topics were connectivity, state, identity, governance and context. The full report is below. This is the short version.
MCP Con in brief
- The AAIF has more than 270 members, six hosted projects and seven working groups. The groups are open to anyone.
- David Soria Parra (co-creator of MCP): connectivity is the most important part of agentic systems. Next on the roadmap: MCP Tasks, skills over MCP, and identity.
- Sam Morrow (GitHub): the context cost comes from the harness, not from the protocol. His harness runs an 86-tool server with almost no startup context.
- Sheng Liang (Obot AI): one MCP gateway is not sufficient. Organizations need an AI control plane.
- Amine Raji (Molntek): a year of MCP attacks at the session, network and approval layers, and the fixes in the July specification.
Stateless MCP
The 2026-07-28 specification removed sessions and the initialize handshake. Each request carries its own protocol version, capabilities and authorization, so any server replica behind a load balancer can process it. State moves into explicit handles, for example a basket_id that the client sends with the next call. More than half of the MCP tool calls at Hugging Face already use the new protocol. Upgrade your SDKs: all of them had major version changes.
WebMCP
With WebMCP, a web page gives tools to an agent in the browser. The W3C Web Machine Learning Community Group published a new draft on October 2. Chrome and Edge have origin trials. The W3C has a draft charter for an Agentic Web Working Group, and the plan is to move WebMCP there. WebKit opposes it. Mozilla is neutral. In Amsterdam, Dominic Farolino (Google Chrome) and Frédéric Barthelet (Alpic) presented MCP, WebMCP and CLIs as three transports to the same tools.
OpenAI: MCP Events in ChatGPT
Since DevDay on September 29, ChatGPT can subscribe to events from your MCP server: new messages, content updates, status changes. The user selects what to monitor and what ChatGPT does when an event arrives. Your server lists its events in server/discover, ChatGPT subscribes with a callback URL and a signing secret, and your server sends matching events as webhooks. Requirements: protocol version 2026-07-28, persistent subscription storage and outbound HTTPS. ChatGPT does not support polling or streaming from the draft specification. OpenAI MCP Events guide

MCP news
- SDK security fixes. Between September 28 and October 5, the TypeScript and Python SDKs fixed OAuth credential redirection, header leaks on cross-origin redirects and missing token audience checks. Upgrade to TypeScript 2.3.x (or 1.32.x) and Python 2.3.0, then set
expectedResource(TypeScript) orvalidate_token_resource(Python). The Python advisory: "Upgrading alone changes nothing." TypeScript · Python - Claude directory. Since September 25, developers on a paid plan can submit remote MCP connectors and plugin bundles for review. Claude blog
- MCP Server Cards. SEP-2127 is final. It defines how a client discovers a remote server before it connects. SEP-2127
- MCPA certification. The Linux Foundation started the MCPA certification for MCP skills. The Gates Foundation joined the AAIF as its first philanthropic member. Announcement
- MCP as ransomware command-and-control. CloudSEK found a ransomware affiliate that registered a reverse shell as an MCP tool. CloudSEK report
MCP Con Amsterdam: the talks
Recordings: day 1 · day 2 · schedule and slides
Opening keynote: Mazin Gilbert, "Building the Internet of Agents in the Open"

Mazin Gilbert is the Executive Director of the AAIF. His keynote put the agentic stack in five layers: hardware, infrastructure, models, the agentic platform and applications. The AAIF works on the agentic platform layer: protocols, harnesses, reliability, identity and authorization. His three reasons for open standards: systemic risk, interoperability and trust.
Numbers: more than 270 members and about one new member each day, six hosted projects (A2A joined in August, Agent Router in September), seven working groups, and 81% of survey respondents with agents in production. The working groups are member-led and open to anyone. Meetings, mailing lists and repositories are public.
David Soria Parra: "MCP and the Era of Connectivity"

Connectivity is the most important part of agentic systems. Coding agents went to production first, because compilers and tests keep models on track. Knowledge agents are next, and they need connections to documents, databases and scientific sources.
Scale: more than one billion MCP tool calls in Claude, and more than 500 million downloads of the tier-one SDKs. Roadmap: MCP Tasks for agentic messaging, skills over MCP, and authorization and identity. His request to builders: make clients that support elicitation, tasks and MCP Apps. MCP roadmap
Stateless MCP: the protocol moves closer to HTTP
!The MCP maintainer meetup in Amsterdam. Source: David Soria Parra (@dsp) on X, September 21._
Kurtis Van Gent (Google) and Shaun Smith (Hugging Face) lead the Transports Working Group. David Soria Parra described the stateless core of the 2026-07-28 specification as HTTP with some additions. The changes:
- No handshake and no session ID. Each request has its own protocol version, capabilities and authorization (SEP-2575). Any server replica behind a load balancer can process it. "Each request carries the protocol context needed to understand it."
- Explicit state handles. The server keeps no session. It returns a handle, for example
basket_id, and the client sends that handle with the next call (SEP-2567). - Multi-round-trip requests. A tool can ask the user for input, and the connection does not stay open.
- Proposals for the next version. Routing headers such as
MCP-MethodandMCP-Name(SEP-2243), tool lists that clients cache with ETags, and HTTP framing over stdio. The schedule is not final.
Production data from Shaun Smith's day-two keynote: more than half of the tool calls at Hugging Face use the new protocol, Anthropic's Claude products have almost completed the migration, and OpenAI has started. His recommendations: upgrade your SDKs, set list caching to on, and use an optimistic design: make the call, then handle the error. Security caution from Amine Raji: "An authorization-bearing handle is a credential in a chat log." Transports Working Group
Three doors to one tool: MCP vs WebMCP vs CLI
Frédéric Barthelet (CTO and co-founder, Alpic) and Dominic Farolino (Google Chrome, WebMCP specification editor) compared the three surfaces by "agent experience" (AX). MCP has the only standardized authorization path: OAuth 2.1 and cross-app access. CLIs are good at composition, and MCP gets composition back through code mode. WebMCP is still experimental. The three are not competitors. They are three transports to the same tools. Alpic's open-source Skybridge framework for ChatGPT and Claude apps now supports the 2026-07-28 specification. WebMCP draft specification
Sam Morrow (GitHub): "MCP Doesn't Have a Context Problem"

Sam Morrow leads the GitHub MCP server. He opened with the critics: the GitHub MCP server uses 23k tokens (Peter Steinberger), Sentry about 14,000 (David Cramer). His answer: the cost comes from harnesses that load all tools at the start, not from the protocol. His harness, mcpi, runs an 86-tool server with almost no startup context. Tools are discovered progressively, skills load tools, and code mode does the composition. Two rules from his slides: "All tool calls go through one chokepoint" (32 of the 86 tools are approval-gated) and "Skills can load tools." mcpi on GitHub
Sheng Liang (Obot AI): why organizations need an AI control plane
Sheng Liang is the co-founder and CEO of Obot AI. One gateway cannot control agents such as Claude Code, which run on laptops with human-level privileges. Most organizations use a "bag of tricks": curate, monitor, isolate. His solution is one control plane with four parts: an MCP gateway, an LLM gateway, a sandbox and a desktop plugin. Obot is open source (MIT) with a free self-hosted tier. The Obot team also gave a workshop on the governance of agent actions. Obot recap
The security track
Amine Raji (Molntek) showed a year of real MCP attacks at three trust points. Session: a Grafana MCP server accepted caller-made session IDs, which enabled server-side request forgery (CVE-2026-19516, fixed in 1.1.0). Network: GitLab MCP servers with wildcard CORS and 0.0.0.0 binds, callable from any web page. Approval: in four coding clients, code ran before the trust dialog appeared. The July specification fixed real problems, but cacheable discovery and state handles add new attack surfaces, and no working group owns publisher identity. His three rules: verify the publisher before the content, authenticate inbound requests separately from downstream requests, and snapshot tool definitions and block on drift. Attack labs
At enterprise scale, defense in depth is the only architecture that holds. No single control catches everything. You need policies, runtime threat detection, and fine-grained access controls applied at every layer of the agentic stack, paired with full-session observability and behavioral baselines so you can find signals in the noise.
— Jake Moghtader, Runlayer, "Securing the Agentic Universe, One Layer at a Time"

MCP Apps: two users, one app
Florian Bauer (OpenAI) on MCP Apps that a person and an agent change at the same time. Three patterns: send both through the same state functions, run a revision check before each write, and keep the agent's proposals in a separate draft until the user accepts them. Apps SDK examples
Apify and AgentCat were startup sponsors of the event. Apify makes mcpc, a universal CLI client for MCP. AgentCat makes analytics and observability for MCP servers.
Highlights of the week
MCPs
- Enrich Layer: An MCP server that gives agents professional profile, company and job data. The database has more than one billion records, with real-time job listings.
- Kleo: An MCP server that makes a narrated film from a Claude or ChatGPT chat. Realistic or animation, 15 seconds to 5 minutes, 4K at 60 fps. Connector:
https://mcp.kleooai.com/mcp
Open source on GitHub
- Ponytail (MIT): A skill for AI coding agents with one rule: do not make the code more complex than necessary. Install it as a plugin in Claude Code or Codex, or as an
AGENTS.mdfile for other agents. More than 150,000 stars. - mcpc (Apache-2.0): Apify's universal MCP CLI client. It maps each MCP operation to a shell command, so an agent can use any MCP server through one Bash call. Supports OAuth 2.1, Tasks, Skills and JSON output for code mode.
- auth.md (MIT): WorkOS's open protocol for agents that register for a service for a user. The service publishes an
AUTH.mdfile at its domain. Identity comes from an ID-JAG assertion or an RFC 8628-style claim procedure.
Podcast
The Context, featuring MintMCP: The Context is the podcast of the Agentic AI Foundation. This episode, published on October 6, features MintMCP, an MCP gateway that gives each agent its models, tools and context through one role-governed gateway. 39 minutes.
Meme

Sponsor Spotlight
Valency
Valency Bond connects Claude, ChatGPT, Codex and other agents to scientific literature over MCP. It has 44.5 million papers from seven sources, for example PubMed, arXiv and bioRxiv, more than 500 million citation references, and 38 tools. Bond became generally available on October 1. It is free for individuals. valency.io/bond
Hot from r/MCPservers
Obot: complete AI governance, open source. Obot is an open-source (MIT) AI governance platform with a governed MCP gateway, registries for MCP servers and skills, sandboxed MCP workloads and audit logs. The post has a Docker quickstart and the GitHub repository. r/MCPservers has more than 27,000 members: join the discussion.
Upcoming hackathons
- init() by WorkOS: a conference for builders. San Francisco (SFJAZZ Center), October 7.
- MCP Bootcamp: online, October 31 to November 1.
More events are on MCPHackathon.com. If you organize an MCP event, add it there.
Sponsor MCPnewsletter
Reach developers who build with MCP servers, SDKs, registries, authorization and agent tools. Send sponsorship requests to [contact@mcpnewsletter.com](mailto:contact@mcpnewsletter.com).
About MCPnewsletter
MCPnewsletter is a weekly newsletter about Model Context Protocol (MCP) tools, servers, apps, SDKs, registries and implementation patterns. Subscribe at mcpnewsletter.com.
Get the next edition in your inbox
MCP servers, SDKs, registries, auth patterns, security tools, and launches worth knowing. Free.