You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
All Tier 1 requirements are met. Conformance is 100% across every tier-scored server and client scenario in both frozen requirement revisions (2025-11-25 at the stateful wire, 2026-07-28 at the stateless wire), all repository-health and governance requirements clear the Tier 1 bar.
Pass rate: 100% (67/67). Tested against the frozen requirement sets for 2025-11-25 (stateful wire, -stateless=false) and 2026-07-28 (stateless wire, default). The two invocations come from the go-sdk entry in src/sdk-runner/known-sdks.ts, so tier-check --sdk-path spawns the correct server per revision automatically.
Scenario
Status
Checks
Spec Versions
caching
PASS
8/8
2026-07-28
completion-complete
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
dns-rebinding-protection
PASS
2/2
2025-11-25, 2026-07-28
elicitation-sep1034-defaults
PASS
6/6
2025-11-25
elicitation-sep1330-enums
PASS
6/6
2025-11-25
input-required-result-basic-elicitation
PASS
3/3
2026-07-28
input-required-result-basic-list-roots
PASS
3/3
2026-07-28
input-required-result-basic-sampling
PASS
3/3
2026-07-28
input-required-result-capability-check
PASS
2/2
2026-07-28
input-required-result-ignore-extra-params
PASS
2/2
2026-07-28
input-required-result-missing-input-response
PASS
2/2
2026-07-28
input-required-result-multi-round
PASS
4/4
2026-07-28
input-required-result-multiple-input-requests
PASS
3/3
2026-07-28
input-required-result-non-tool-request
PASS
3/3
2026-07-28
input-required-result-request-state
PASS
3/3
2026-07-28
input-required-result-result-type
PASS
2/2
2026-07-28
input-required-result-tampered-state
PASS
2/2
2026-07-28
input-required-result-unsupported-methods
PASS
2/2
2026-07-28
input-required-result-validate-input
PASS
3/3
2026-07-28
logging-set-level
PASS
2/2
2025-06-18, 2025-11-25
ping
PASS
2/2
2025-06-18, 2025-11-25
prompts-get-embedded-resource
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
prompts-get-simple
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
prompts-get-with-args
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
prompts-get-with-image
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
prompts-list
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
resources-list
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
resources-read-binary
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
resources-read-text
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
resources-subscribe
PASS
2/2
2025-06-18, 2025-11-25
resources-templates-read
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
resources-unsubscribe
PASS
2/2
2025-06-18, 2025-11-25
sep-2164-resource-not-found
PASS
4/4
2026-07-28
server-initialize
PASS
3/3
2025-06-18, 2025-11-25
server-sse-multiple-streams
PASS
2/2
2025-11-25, 2026-07-28
server-stateless
PASS
30/30
2026-07-28
tools-call-audio
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
tools-call-elicitation
PASS
2/2
2025-06-18, 2025-11-25
tools-call-embedded-resource
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
tools-call-error
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
tools-call-image
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
tools-call-mixed-content
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
tools-call-sampling
PASS
2/2
2025-06-18, 2025-11-25
tools-call-simple-text
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
tools-call-with-logging
PASS
2/2
2025-06-18, 2025-11-25
tools-call-with-progress
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
tools-list
PASS
3/3
2025-06-18, 2025-11-25, 2026-07-28
Client Conformance Details
Full-suite pass rate (tier-scored): 100% (50/50).
Suite breakdown: Core: 11/11 (100%), Auth: 39/39 (100%).
Tier scoring covers the frozen requirement sets for 2025-11-25 and 2026-07-28. Extension scenarios and scenarios added after a revision shipped are informational and not counted toward tier advancement, per the conformance testing rules.
Conformance Matrix
2025-11-25
2026-07-28
All*
T2
T1
Server
30/30
37/37
67/67 (100%)
PASS
PASS
Client: Core
4/4
7/7
11/11 (100%)
—
—
Client: Auth
14/14
25/25
39/39 (100%)
—
—
Client Total
50/50 (100%)
PASS
PASS
* Pairs of (scenario, revision); a scenario belonging to both revisions is run once per revision on that revision's wire.
Baseline (conformance/baseline.yml): 7 client-side auth scenarios are documented as expected failures — auth/client-credentials-basic, auth/client-credentials-jwt, auth/enterprise-managed-authorization, auth/dpop, auth/dpop-nonce, auth/wif-jwt-bearer. All fall in the extension category and are not scored for tier. No unexpected failures.
Informational (not scored for tier):
pending
added-after-release
extension
Server
5 pass
1 pass
10 fail
Client
—
2 fail
12 fail
The 10 failing server extensions and all 12 failing client extensions belong to the Tasks family (SEP-2322 request state, MRTR composition, dispatch/envelope, lifecycle, capability negotiation) and the SEP-1932/SEP-1933/SEP-1934 client-side auth extensions (auth/dpop, auth/dpop-nonce, auth/wif-jwt-bearer, auth/enterprise-managed-authorization, auth/client-credentials-basic, auth/client-credentials-jwt) — all off-timeline extensions that the SDK does not yet implement. The 2 failing client added-after-release items are two revisions of json-schema-2020-12-preservation, added to the suite after both 2025-11-25 and 2026-07-28 shipped. None of these affect tier classification.
Core Scenarios (scored)
Scenario
Status
Checks
Spec Versions
elicitation-sep1034-client-defaults
PASS
5/5
2025-11-25
http-custom-headers
PASS
18/18
2026-07-28
http-invalid-tool-headers
PASS
11/11
2026-07-28
http-standard-headers
PASS
9/9
2026-07-28
initialize
PASS
1/1
2025-06-18, 2025-11-25
json-schema-ref-no-deref
PASS
1/1
2026-07-28
request-metadata
PASS
6/6
2026-07-28
sep-2322-client-request-state
PASS
5/5
2026-07-28
sse-retry
PASS
3/3
2025-11-25
tools_call
PASS
2/2
2025-06-18, 2025-11-25, 2026-07-28
Auth Scenarios (scored)
Scenario
Status
Checks
Spec Versions
Notes
auth/authorization-server-migration
PASS
27/27
2026-07-28
auth/basic-cimd
PASS
13/13
2025-11-25, 2026-07-28
auth/iss-normalized
PASS
15/15
2026-07-28
auth/iss-not-advertised
PASS
14/14
2026-07-28
auth/iss-supported
PASS
14/14
2026-07-28
auth/iss-supported-missing
PASS
15/15
2026-07-28
auth/iss-unexpected
PASS
15/15
2026-07-28
auth/iss-wrong-issuer
PASS
15/15
2026-07-28
auth/metadata-default
PASS
13/13
2025-11-25, 2026-07-28
auth/metadata-issuer-mismatch
PASS
5/5
2026-07-28
auth/metadata-var1
PASS
13/13
2025-11-25, 2026-07-28
auth/metadata-var2
PASS
13/13
2025-11-25, 2026-07-28
auth/metadata-var3
PASS
13/13
2025-11-25, 2026-07-28
auth/offline-access-not-supported
PASS
14/14
2026-07-28
auth/offline-access-scope
PASS
11/11
2026-07-28
auth/pre-registration
PASS
13/13
2025-11-25, 2026-07-28
auth/resource-mismatch
PASS
5/5
2026-07-28
auth/scope-from-scopes-supported
PASS
14/14
2025-11-25, 2026-07-28
auth/scope-from-www-authenticate
PASS
14/14
2025-11-25, 2026-07-28
auth/scope-omitted-when-undefined
PASS
14/14
2025-11-25, 2026-07-28
auth/scope-retry-limit
PASS
15/15
2025-11-25, 2026-07-28
auth/scope-step-up
PASS
25/25
2025-11-25, 2026-07-28
auth/token-endpoint-auth-basic
PASS
18/18
2025-06-18, 2025-11-25, 2026-07-28
auth/token-endpoint-auth-none
PASS
18/18
2025-06-18, 2025-11-25, 2026-07-28
auth/token-endpoint-auth-post
PASS
18/18
2025-06-18, 2025-11-25, 2026-07-28
Informational scenarios (extension / added-after-release / pending — not scored)
Server, failing (10, informational only): the Tasks family under revision 2026-07-28 — tasks-wire-fields, tasks-status-notifications, tasks-required-task-error, tasks-request-state-removal, tasks-request-headers, tasks-mrtr-input, tasks-mrtr-composition, tasks-lifecycle, tasks-dispatch-and-envelope, tasks-capability-negotiation. All are extension scenarios for an experimental protocol area the SDK does not yet implement.
Client, failing (14, informational only):json-schema-2020-12-preservation (added-after-release, both revisions); auth/wif-jwt-bearer, auth/enterprise-managed-authorization, auth/dpop-nonce, auth/dpop, auth/client-credentials-jwt, auth/client-credentials-basic (extension, each present under both revisions). The seven auth items are baselined in conformance/baseline.yml and correspond to SEPs (SEP-1932 DPoP, SEP-1933 WIF JWT-Bearer, SEP-1934 Enterprise Managed Auth) that are on the roadmap but not yet implemented.
Issue Triage Details
Analysis period: last 45 open issues.
Labels: needs confirmation, needs repro, ready for work, good first issue, help wanted, P0, P1, P2, P3 — plus org-wide native Issue Types (Task, Bug, Enhancement, Question) used for Type categorization. See Note ① for the tool-detection caveat.
Metric
Value
T1 Req
T2 Req
Verdict
Compliance rate
93.3%
>= 90%
>= 80%
PASS
Exceeding SLA
2
—
—
—
Open P0s
0
0
0
PASS
P0 resolution: 1 P0 closed within 7 days; 0 currently open.
Stable release: v1.7.0 — semantic version 1.7.0 (>= 1.0.0), not a pre-release. Go module SemVer is enforced by the toolchain; spec-compatibility guarantees are documented in README § "Version Compatibility".
Summary: 48/48 non-experimental features documented with examples (100%); core features 36/36 (100%).
Experimental features (informational only)
Feature
Documented?
Where
Examples
Verdict
Tasks - get
No
Not implemented
No
INFO
Tasks - result
No
Not implemented
No
INFO
Tasks - cancel
No
Not implemented
No
INFO
Tasks - list
No
Not implemented
No
INFO
Tasks - status notifications
No
Not implemented
No
INFO
Tasks (SEP-2322 and related extensions) are on the roadmap but not yet implemented in the SDK. The corresponding conformance scenarios are extension and are not scored for tier.
Substantive — proposal-required for new modules, free upgrades for existing modules, govulncheck after any change
Verdict: PASS — a substantive written policy (CONTRIBUTING.md) and a working Dependabot configuration are present and consistent. Matches #2279 treatment.
MCP SDK Tier Audit: modelcontextprotocol/go-sdk
Date: 2026-08-10
Branch:
main(commite9a85e2)Version: v1.7.0 · pkg.go.dev/github.com/modelcontextprotocol/go-sdk@v1.7.0
Requested tier: Tier 1
Tool:
@modelcontextprotocol/conformancetier-check0.2.0-alpha.11Previous assessment: #2279 (Tier 1, v1.4.0, 2026-02-27)
Tier Assessment: Tier 1
All Tier 1 requirements are met. Conformance is 100% across every tier-scored server and client scenario in both frozen requirement revisions (
2025-11-25at the stateful wire,2026-07-28at the stateless wire), all repository-health and governance requirements clear the Tier 1 bar.Requirements Summary
① Labels — Labels check failed for "bug", "enhancement" and "question", because we use GitHub issue types (each mirrors precedent set in #2279).
Tier Determination
Server Conformance Details
Pass rate: 100% (67/67). Tested against the frozen requirement sets for
2025-11-25(stateful wire,-stateless=false) and2026-07-28(stateless wire, default). The two invocations come from the go-sdk entry insrc/sdk-runner/known-sdks.ts, sotier-check --sdk-pathspawns the correct server per revision automatically.Client Conformance Details
Full-suite pass rate (tier-scored): 100% (50/50).
Conformance Matrix
* Pairs of
(scenario, revision); a scenario belonging to both revisions is run once per revision on that revision's wire.Baseline (
conformance/baseline.yml): 7 client-side auth scenarios are documented as expected failures —auth/client-credentials-basic,auth/client-credentials-jwt,auth/enterprise-managed-authorization,auth/dpop,auth/dpop-nonce,auth/wif-jwt-bearer. All fall in theextensioncategory and are not scored for tier. No unexpected failures.Informational (not scored for tier):
The 10 failing server extensions and all 12 failing client extensions belong to the Tasks family (SEP-2322 request state, MRTR composition, dispatch/envelope, lifecycle, capability negotiation) and the SEP-1932/SEP-1933/SEP-1934 client-side auth extensions (
auth/dpop,auth/dpop-nonce,auth/wif-jwt-bearer,auth/enterprise-managed-authorization,auth/client-credentials-basic,auth/client-credentials-jwt) — all off-timeline extensions that the SDK does not yet implement. The 2 failing clientadded-after-releaseitems are two revisions ofjson-schema-2020-12-preservation, added to the suite after both2025-11-25and2026-07-28shipped. None of these affect tier classification.Core Scenarios (scored)
Auth Scenarios (scored)
Informational scenarios (extension / added-after-release / pending — not scored)
Server, passing (6):
server-sse-polling(pending),server-session-lifecycle(added-after-release),json-schema-2020-12(pending, both revisions),http-header-validation(pending),http-custom-header-server-validation(pending).Server, failing (10, informational only): the Tasks family under revision
2026-07-28—tasks-wire-fields,tasks-status-notifications,tasks-required-task-error,tasks-request-state-removal,tasks-request-headers,tasks-mrtr-input,tasks-mrtr-composition,tasks-lifecycle,tasks-dispatch-and-envelope,tasks-capability-negotiation. All areextensionscenarios for an experimental protocol area the SDK does not yet implement.Client, failing (14, informational only):
json-schema-2020-12-preservation(added-after-release, both revisions);auth/wif-jwt-bearer,auth/enterprise-managed-authorization,auth/dpop-nonce,auth/dpop,auth/client-credentials-jwt,auth/client-credentials-basic(extension, each present under both revisions). The seven auth items are baselined inconformance/baseline.ymland correspond to SEPs (SEP-1932 DPoP, SEP-1933 WIF JWT-Bearer, SEP-1934 Enterprise Managed Auth) that are on the roadmap but not yet implemented.Issue Triage Details
Analysis period: last 45 open issues.
Labels:
needs confirmation,needs repro,ready for work,good first issue,help wanted,P0,P1,P2,P3— plus org-wide native Issue Types (Task,Bug,Enhancement,Question) used for Type categorization. See Note ① for the tool-detection caveat.P0 resolution: 1 P0 closed within 7 days; 0 currently open.
Spec tracking: latest spec release
2026-07-28; latest SDK release2026-07-28(13-day gap).Stable release: v1.7.0 — semantic version
1.7.0(>= 1.0.0), not a pre-release. Go module SemVer is enforced by the toolchain; spec-compatibility guarantees are documented in README § "Version Compatibility".Documentation Coverage
Documentation locations: root
README.md(getting-started + spec-version compatibility matrix),docs/README.md,docs/quick_start.md,docs/protocol.md,docs/server.md,docs/client.md,docs/troubleshooting.md,docs/mcpgodebug.md,docs/rough_edges.md;examples/with 20+ programs underserver/,client/,auth/,http/; and GoExample*functions inmcp/*_example_test.gorendered on pkg.go.dev. Source-of-truth for generated docs is ininternal/docs/*.src.md(regenerated viago generate ./internal/docsperAGENTS.md).Example_resourcesExample_resourcesExample_resourcesExample_resourcesExample_promptsExample_promptsExample_promptsExample_sampling; examples/server/everything/main.goExample_elicitation; examples/server/elicitationExample_elicitationElicitationCompleteHandler)Example_roots; examples/server/everything/main.goExample_logging; examples/server/everything/main.goExample_loggingExampleStreamableHTTPHandler; examples/httpExampleStreamableHTTPHandler_middlewareExampleSSEHandler; examples/server/sse/main.goExampleSSEHandler; examples/server/sse/main.goExample_progressExample_cancellationExample_prompts;Example_resourcesExampleAddTool_*; examples/server/toolschemasSummary: 48/48 non-experimental features documented with examples (100%); core features 36/36 (100%).
Experimental features (informational only)
Tasks (SEP-2322 and related extensions) are on the roadmap but not yet implemented in the SDK. The corresponding conformance scenarios are
extensionand are not scored for tier.Policy Evaluation
1. Dependency Update Policy — PASS
github/codeql-action/*Verdict: PASS — a substantive written policy (CONTRIBUTING.md) and a working Dependabot configuration are present and consistent. Matches #2279 treatment.
2. Roadmap — PASS
Verdict (Tier 1): PASS —
ROADMAP.mdlists concrete work items tracking MCP spec components: SEP-1730 Tier 1 support (#675), SEP-1577 (Sampling with Tools completing 2025-11-25), client-side OAuth SEPs, ext-auth extensions, and Tasks (experimental).3. Versioning Policy — PASS (see Note ③)
Verdict (Tier 1): PASS — matches #2279 treatment ("Go uses semantic versioning by default. No additional policies are needed.").
Reproduce This Assessment