pragma.vision Technology observatory & strategic foresight

Verification register Agentic Commerce & Payments

Readiness verdict

Model Context Protocol (MCP)

A dated reading of what is claimed, reported, and independently verified in the current evidence.

As of
2026-08-20
Revision
1
Method
v1.3.0

Current reading

Readiness band and full integer triple

AI-assisted assembly · derived results

Readiness band

Ready

Primary summary from verified readiness

Confidence
72% · stale
Computed at
2026-08-20T10:52:47.757735+00:00
Claimed
80

Public ambition and stated capability

Reported
73

Observed practitioner reporting

Verified
66

Independently supported evidence

Gap
+14

Claimed leads verified

Evidence strength Strong

Decision

What the current evidence supports

Human editorial judgment · 2026-08-20

Adopt with guardrails

Why
Massive verified adoption (97M+ monthly SDK downloads, 9,652 registry servers) and we already run MCP servers, but the upcoming breaking RC plus authoritative auth/prompt-injection warnings demand guardrails, not a blind upgrade — and only ~41% of surveyed orgs are in any production stage.
Next
Pin to the 2026-11-25 stable spec now, prototype against the 2026-07-28 RC stateless transport in a branch, and enforce OAuth 2.1 + iss validation (RFC 9207) + explicit user-consent gates and least-privilege per-tool tokens on every server per NSA guidance before exposing any PII tool.

Constraints

Blockers

No named blocker is present in the current public projection.

Evidence summary

Derived counts

AI-assisted assembly

Total
14
Tier 1
0
Tier 2
6
Tier 3
8
Supports
6
Contradicts
4
Context
4
Latest observed
2026-05-24

Counts and dates only. Raw signals, private excerpts, trust records, and internal corpus material are not published here.

Publication record

Revisions

Initial public reading

  1. 2026-07-19 Reading moved from ready to ready.

Your opinion

Tell us anything.

What works, what doesn't, what's missing — especially about our watches, lenses, and the register itself. Anonymous is fine; leave an email if you'd like a reply.