Skip to content

Go SDK - Tier 1 Assessment #3220

Description

@guglielmo-san

MCP SDK Tier Audit: modelcontextprotocol/go-sdk

Date: 2026-08-10
Branch: main (commit e9a85e2)
Version: v1.7.0 · pkg.go.dev/github.com/modelcontextprotocol/go-sdk@v1.7.0
Requested tier: Tier 1
Tool: @modelcontextprotocol/conformance tier-check 0.2.0-alpha.11
Previous assessment: #2279 (Tier 1, v1.4.0, 2026-02-27)

Tier Assessment: Tier 1

All Tier 1 requirements are met. Conformance is 100% across every tier-scored server and client scenario in both frozen requirement revisions (2025-11-25 at the stateful wire, 2026-07-28 at the stateless wire), all repository-health and governance requirements clear the Tier 1 bar.

Requirements Summary

# Requirement Tier 1 Standard Tier 2 Standard Current Value T1? T2? Gap
1a Server Conformance 100% pass rate >= 80% pass rate 100% (67/67 scored) PASS PASS None
1b Client Conformance 100% pass rate >= 80% pass rate 100% (50/50 scored) PASS PASS None
2 Issue Triage >= 90% within 2 biz days >= 80% within 1 month 93.3% (42/45) PASS PASS None
2b Labels 12 required labels 12 required labels 9/12 present + org-wide native issue types PASS* PASS* See note ①
3 Critical Bug Resolution All P0s within 7 days All P0s within 2 weeks 0 open (1 closed within 7d) PASS PASS None
4 Stable Release Required + clear versioning At least one stable release v1.7.0 PASS PASS None
4b Spec Tracking Timeline agreed per release Within 6 months 13-day gap PASS PASS None
5 Documentation Comprehensive w/ examples Basic docs for core features 48/48 implemented features PASS PASS None
6 Dependency Policy Published update policy Published update policy Found + CONTRIBUTING.md § "Adding and updating dependencies" PASS PASS None
7 Roadmap Published roadmap Plan toward Tier 1 Found PASS PASS None
8 Versioning Policy Documented breaking change policy N/A Go modules SemVer + README § "Version Compatibility" PASS N/A Missing policy doc

① Labels — Labels check failed for "bug", "enhancement" and "question", because we use GitHub issue types (each mirrors precedent set in #2279).

Tier Determination

  • Tier 1: PASS — 10/10 requirements met (three items footnoted, all matching Go SDK — Tier 1 Assessment #2279 precedent)
  • Tier 2: PASS — 9/9 requirements met
  • Final Tier: 1

Server Conformance Details

Pass rate: 100% (67/67). Tested against the frozen requirement sets for 2025-11-25 (stateful wire, -stateless=false) and 2026-07-28 (stateless wire, default). The two invocations come from the go-sdk entry in src/sdk-runner/known-sdks.ts, so tier-check --sdk-path spawns the correct server per revision automatically.

Scenario Status Checks Spec Versions
caching PASS 8/8 2026-07-28
completion-complete PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
dns-rebinding-protection PASS 2/2 2025-11-25, 2026-07-28
elicitation-sep1034-defaults PASS 6/6 2025-11-25
elicitation-sep1330-enums PASS 6/6 2025-11-25
input-required-result-basic-elicitation PASS 3/3 2026-07-28
input-required-result-basic-list-roots PASS 3/3 2026-07-28
input-required-result-basic-sampling PASS 3/3 2026-07-28
input-required-result-capability-check PASS 2/2 2026-07-28
input-required-result-ignore-extra-params PASS 2/2 2026-07-28
input-required-result-missing-input-response PASS 2/2 2026-07-28
input-required-result-multi-round PASS 4/4 2026-07-28
input-required-result-multiple-input-requests PASS 3/3 2026-07-28
input-required-result-non-tool-request PASS 3/3 2026-07-28
input-required-result-request-state PASS 3/3 2026-07-28
input-required-result-result-type PASS 2/2 2026-07-28
input-required-result-tampered-state PASS 2/2 2026-07-28
input-required-result-unsupported-methods PASS 2/2 2026-07-28
input-required-result-validate-input PASS 3/3 2026-07-28
logging-set-level PASS 2/2 2025-06-18, 2025-11-25
ping PASS 2/2 2025-06-18, 2025-11-25
prompts-get-embedded-resource PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
prompts-get-simple PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
prompts-get-with-args PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
prompts-get-with-image PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
prompts-list PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
resources-list PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
resources-read-binary PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
resources-read-text PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
resources-subscribe PASS 2/2 2025-06-18, 2025-11-25
resources-templates-read PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
resources-unsubscribe PASS 2/2 2025-06-18, 2025-11-25
sep-2164-resource-not-found PASS 4/4 2026-07-28
server-initialize PASS 3/3 2025-06-18, 2025-11-25
server-sse-multiple-streams PASS 2/2 2025-11-25, 2026-07-28
server-stateless PASS 30/30 2026-07-28
tools-call-audio PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
tools-call-elicitation PASS 2/2 2025-06-18, 2025-11-25
tools-call-embedded-resource PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
tools-call-error PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
tools-call-image PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
tools-call-mixed-content PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
tools-call-sampling PASS 2/2 2025-06-18, 2025-11-25
tools-call-simple-text PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
tools-call-with-logging PASS 2/2 2025-06-18, 2025-11-25
tools-call-with-progress PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28
tools-list PASS 3/3 2025-06-18, 2025-11-25, 2026-07-28

Client Conformance Details

Full-suite pass rate (tier-scored): 100% (50/50).

Suite breakdown: Core: 11/11 (100%), Auth: 39/39 (100%).
Tier scoring covers the frozen requirement sets for 2025-11-25 and 2026-07-28. Extension scenarios and scenarios added after a revision shipped are informational and not counted toward tier advancement, per the conformance testing rules.

Conformance Matrix

2025-11-25 2026-07-28 All* T2 T1
Server 30/30 37/37 67/67 (100%) PASS PASS
Client: Core 4/4 7/7 11/11 (100%)
Client: Auth 14/14 25/25 39/39 (100%)
Client Total 50/50 (100%) PASS PASS

* Pairs of (scenario, revision); a scenario belonging to both revisions is run once per revision on that revision's wire.

Baseline (conformance/baseline.yml): 7 client-side auth scenarios are documented as expected failures — auth/client-credentials-basic, auth/client-credentials-jwt, auth/enterprise-managed-authorization, auth/dpop, auth/dpop-nonce, auth/wif-jwt-bearer. All fall in the extension category and are not scored for tier. No unexpected failures.

Informational (not scored for tier):

pending added-after-release extension
Server 5 pass 1 pass 10 fail
Client 2 fail 12 fail

The 10 failing server extensions and all 12 failing client extensions belong to the Tasks family (SEP-2322 request state, MRTR composition, dispatch/envelope, lifecycle, capability negotiation) and the SEP-1932/SEP-1933/SEP-1934 client-side auth extensions (auth/dpop, auth/dpop-nonce, auth/wif-jwt-bearer, auth/enterprise-managed-authorization, auth/client-credentials-basic, auth/client-credentials-jwt) — all off-timeline extensions that the SDK does not yet implement. The 2 failing client added-after-release items are two revisions of json-schema-2020-12-preservation, added to the suite after both 2025-11-25 and 2026-07-28 shipped. None of these affect tier classification.

Core Scenarios (scored)

Scenario Status Checks Spec Versions
elicitation-sep1034-client-defaults PASS 5/5 2025-11-25
http-custom-headers PASS 18/18 2026-07-28
http-invalid-tool-headers PASS 11/11 2026-07-28
http-standard-headers PASS 9/9 2026-07-28
initialize PASS 1/1 2025-06-18, 2025-11-25
json-schema-ref-no-deref PASS 1/1 2026-07-28
request-metadata PASS 6/6 2026-07-28
sep-2322-client-request-state PASS 5/5 2026-07-28
sse-retry PASS 3/3 2025-11-25
tools_call PASS 2/2 2025-06-18, 2025-11-25, 2026-07-28

Auth Scenarios (scored)

Scenario Status Checks Spec Versions Notes
auth/authorization-server-migration PASS 27/27 2026-07-28
auth/basic-cimd PASS 13/13 2025-11-25, 2026-07-28
auth/iss-normalized PASS 15/15 2026-07-28
auth/iss-not-advertised PASS 14/14 2026-07-28
auth/iss-supported PASS 14/14 2026-07-28
auth/iss-supported-missing PASS 15/15 2026-07-28
auth/iss-unexpected PASS 15/15 2026-07-28
auth/iss-wrong-issuer PASS 15/15 2026-07-28
auth/metadata-default PASS 13/13 2025-11-25, 2026-07-28
auth/metadata-issuer-mismatch PASS 5/5 2026-07-28
auth/metadata-var1 PASS 13/13 2025-11-25, 2026-07-28
auth/metadata-var2 PASS 13/13 2025-11-25, 2026-07-28
auth/metadata-var3 PASS 13/13 2025-11-25, 2026-07-28
auth/offline-access-not-supported PASS 14/14 2026-07-28
auth/offline-access-scope PASS 11/11 2026-07-28
auth/pre-registration PASS 13/13 2025-11-25, 2026-07-28
auth/resource-mismatch PASS 5/5 2026-07-28
auth/scope-from-scopes-supported PASS 14/14 2025-11-25, 2026-07-28
auth/scope-from-www-authenticate PASS 14/14 2025-11-25, 2026-07-28
auth/scope-omitted-when-undefined PASS 14/14 2025-11-25, 2026-07-28
auth/scope-retry-limit PASS 15/15 2025-11-25, 2026-07-28
auth/scope-step-up PASS 25/25 2025-11-25, 2026-07-28
auth/token-endpoint-auth-basic PASS 18/18 2025-06-18, 2025-11-25, 2026-07-28
auth/token-endpoint-auth-none PASS 18/18 2025-06-18, 2025-11-25, 2026-07-28
auth/token-endpoint-auth-post PASS 18/18 2025-06-18, 2025-11-25, 2026-07-28
Informational scenarios (extension / added-after-release / pending — not scored)

Server, passing (6): server-sse-polling (pending), server-session-lifecycle (added-after-release), json-schema-2020-12 (pending, both revisions), http-header-validation (pending), http-custom-header-server-validation (pending).

Server, failing (10, informational only): the Tasks family under revision 2026-07-28tasks-wire-fields, tasks-status-notifications, tasks-required-task-error, tasks-request-state-removal, tasks-request-headers, tasks-mrtr-input, tasks-mrtr-composition, tasks-lifecycle, tasks-dispatch-and-envelope, tasks-capability-negotiation. All are extension scenarios for an experimental protocol area the SDK does not yet implement.

Client, failing (14, informational only): json-schema-2020-12-preservation (added-after-release, both revisions); auth/wif-jwt-bearer, auth/enterprise-managed-authorization, auth/dpop-nonce, auth/dpop, auth/client-credentials-jwt, auth/client-credentials-basic (extension, each present under both revisions). The seven auth items are baselined in conformance/baseline.yml and correspond to SEPs (SEP-1932 DPoP, SEP-1933 WIF JWT-Bearer, SEP-1934 Enterprise Managed Auth) that are on the roadmap but not yet implemented.


Issue Triage Details

Analysis period: last 45 open issues.
Labels: needs confirmation, needs repro, ready for work, good first issue, help wanted, P0, P1, P2, P3 — plus org-wide native Issue Types (Task, Bug, Enhancement, Question) used for Type categorization. See Note ① for the tool-detection caveat.

Metric Value T1 Req T2 Req Verdict
Compliance rate 93.3% >= 90% >= 80% PASS
Exceeding SLA 2
Open P0s 0 0 0 PASS

P0 resolution: 1 P0 closed within 7 days; 0 currently open.

Spec tracking: latest spec release 2026-07-28; latest SDK release 2026-07-28 (13-day gap).

Stable release: v1.7.0 — semantic version 1.7.0 (>= 1.0.0), not a pre-release. Go module SemVer is enforced by the toolchain; spec-compatibility guarantees are documented in README § "Version Compatibility".


Documentation Coverage

Documentation locations: root README.md (getting-started + spec-version compatibility matrix), docs/README.md, docs/quick_start.md, docs/protocol.md, docs/server.md, docs/client.md, docs/troubleshooting.md, docs/mcpgodebug.md, docs/rough_edges.md; examples/ with 20+ programs under server/, client/, auth/, http/; and Go Example* functions in mcp/*_example_test.go rendered on pkg.go.dev. Source-of-truth for generated docs is in internal/docs/*.src.md (regenerated via go generate ./internal/docs per AGENTS.md).

# Feature Documented? Where Has Examples? Verdict
1 Tools - listing Yes docs/server.md § Tools; examples/client/listfeatures/main.go Yes PASS
2 Tools - calling Yes README.md § Quick start; docs/server.md § Tools; docs/quick_start.md Yes PASS
3 Tools - text results Yes README.md § Quick start; docs/server.md § Tools Yes PASS
4 Tools - image results Yes docs/server.md § Tools (content types) Yes PASS
5 Tools - audio results Yes docs/server.md § Tools (content types); docs/rough_edges.md Yes PASS
6 Tools - embedded resources Yes docs/server.md § Tools (content types); examples/server/everything/main.go Yes PASS
7 Tools - error handling Yes docs/server.md § Tools (IsError semantics) Yes PASS
8 Tools - change notifications Yes docs/server.md § Tools (ToolListChangedHandler) Yes PASS
9 Resources - listing Yes docs/server.md § Resources; Example_resources Yes PASS
10 Resources - reading text Yes docs/server.md § Resources; Example_resources Yes PASS
11 Resources - reading binary Yes docs/server.md § Resources (binary/text) Yes PASS
12 Resources - templates Yes docs/server.md § Resources; Example_resources Yes PASS
13 Resources - template reading Yes docs/server.md § Resources (URI templates); Example_resources Yes PASS
14 Resources - subscribing Yes docs/server.md § Resources (Subscribe/Unsubscribe) Yes PASS
15 Resources - unsubscribing Yes docs/server.md § Resources (Subscribe/Unsubscribe) Yes PASS
16 Resources - change notifications Yes docs/server.md § Resources (ResourceListChangedHandler) Yes PASS
17 Prompts - listing Yes docs/server.md § Prompts; Example_prompts Yes PASS
18 Prompts - getting simple Yes docs/server.md § Prompts; Example_prompts Yes PASS
19 Prompts - getting with arguments Yes docs/server.md § Prompts; Example_prompts Yes PASS
20 Prompts - embedded resources Yes docs/server.md § Prompts (embedded resources) Yes PASS
21 Prompts - image content Yes docs/server.md § Prompts (image content) Yes PASS
22 Prompts - change notifications Yes docs/server.md § Prompts (PromptListChangedHandler) Yes PASS
23 Sampling - creating messages Yes docs/client.md § Sampling; Example_sampling; examples/server/everything/main.go Yes PASS
24 Elicitation - form mode Yes docs/client.md § Elicitation; Example_elicitation; examples/server/elicitation Yes PASS
25 Elicitation - URL mode Yes docs/client.md § Elicitation (URL mode); examples/server/everything/main.go Yes PASS
26 Elicitation - schema validation Yes docs/client.md § Elicitation; Example_elicitation Yes PASS
27 Elicitation - default values Yes docs/client.md § Elicitation (SEP-1034 defaults) Yes PASS
28 Elicitation - enum values Yes docs/client.md § Elicitation (SEP-1330 enums) Yes PASS
29 Elicitation - complete notification Yes mcp/elicitation_test.go (ElicitationCompleteHandler) Yes PASS
30 Roots - listing Yes docs/client.md § Roots; Example_roots; examples/server/everything/main.go Yes PASS
31 Roots - change notifications Yes docs/client.md § Roots (RootsListChangedHandler) Yes PASS
32 Logging - sending log messages Yes docs/server.md § Logging; Example_logging; examples/server/everything/main.go Yes PASS
33 Logging - setting level Yes docs/server.md § Logging; Example_logging Yes PASS
34 Completions - resource argument Yes docs/server.md § Completion; examples/server/completion/main.go Yes PASS
35 Completions - prompt argument Yes docs/server.md § Completion; examples/server/completion/main.go Yes PASS
36 Ping Yes docs/protocol.md § Ping; examples/server/everything/main.go Yes PASS
37 Streamable HTTP transport (client) Yes docs/protocol.md § Streamable Transport; ExampleStreamableHTTPHandler; examples/http Yes PASS
38 Streamable HTTP transport (server) Yes docs/protocol.md § Streamable Transport; ExampleStreamableHTTPHandler_middleware Yes PASS
39 SSE transport - legacy (client) Yes docs/protocol.md § SSE; ExampleSSEHandler; examples/server/sse/main.go Yes PASS
40 SSE transport - legacy (server) Yes docs/protocol.md § SSE; ExampleSSEHandler; examples/server/sse/main.go Yes PASS
41 stdio transport (client) Yes docs/protocol.md § Stdio Transport; README quick-start; examples/client/* Yes PASS
42 stdio transport (server) Yes docs/protocol.md § Stdio Transport; README quick-start; examples/server/hello Yes PASS
43 Progress notifications Yes docs/protocol.md § Progress; Example_progress Yes PASS
44 Cancellation Yes docs/protocol.md § Cancellation; Example_cancellation Yes PASS
45 Pagination Yes docs/server.md § Pagination; Example_prompts; Example_resources Yes PASS
46 Capability negotiation Yes docs/server.md § Capabilities; docs/client.md § Capabilities Yes PASS
47 Protocol version negotiation Yes docs/protocol.md § Lifecycle + Discovery; README § Version Compatibility Yes PASS
48 JSON Schema 2020-12 support Yes docs/server.md § Tools (jsonschema-go); ExampleAddTool_*; examples/server/toolschemas Yes PASS

Summary: 48/48 non-experimental features documented with examples (100%); core features 36/36 (100%).

Experimental features (informational only)
Feature Documented? Where Examples Verdict
Tasks - get No Not implemented No INFO
Tasks - result No Not implemented No INFO
Tasks - cancel No Not implemented No INFO
Tasks - list No Not implemented No INFO
Tasks - status notifications No Not implemented No INFO

Tasks (SEP-2322 and related extensions) are on the roadmap but not yet implemented in the SDK. The corresponding conformance scenarios are extension and are not scored for tier.


Policy Evaluation

1. Dependency Update Policy — PASS

File Exists Content Verdict
.github/dependabot.yml Yes Configured — monthly GitHub Actions updates with grouped github/codeql-action/*
CONTRIBUTING.md § "Adding and updating dependencies" Yes Substantive — proposal-required for new modules, free upgrades for existing modules, govulncheck after any change

Verdict: PASS — a substantive written policy (CONTRIBUTING.md) and a working Dependabot configuration are present and consistent. Matches #2279 treatment.

2. Roadmap — PASS

File Exists Content Verdict
ROADMAP.md Yes Substantive — published roadmap with spec-tied work items

Verdict (Tier 1): PASS — ROADMAP.md lists concrete work items tracking MCP spec components: SEP-1730 Tier 1 support (#675), SEP-1577 (Sampling with Tools completing 2025-11-25), client-side OAuth SEPs, ext-auth extensions, and Tasks (experimental).

3. Versioning Policy — PASS (see Note ③)

File Exists Content Verdict
Go module system (go.dev/ref/mod#versions) Yes SemVer 2.0.0 enforced by the toolchain — module paths encode major version; breaking changes require a major-version bump
README.md § "Version Compatibility" Yes Substantive — spec-version compatibility matrix, Go-version support policy, roots/sampling/logging deprecation notice per SEP-2577

Verdict (Tier 1): PASS — matches #2279 treatment ("Go uses semantic versioning by default. No additional policies are needed.").

Policy Area Tier 1 Tier 2
Dependency Update Policy PASS PASS
Roadmap PASS PASS
Versioning Policy PASS N/A

Reproduce This Assessment

# From the conformance repo at the alpha.11 revision
git clone https://github.com/modelcontextprotocol/conformance.git
cd conformance
git checkout c321dd3  # @modelcontextprotocol/conformance 0.2.0-alpha.11
npm install

# GitHub API access for repo-health checks
gh auth login
export GITHUB_TOKEN=$(gh auth token)

# tier-check spawns the correct server invocation per revision, per
# the go-sdk entry in src/sdk-runner/known-sdks.ts (stateful for
# 2025-11-25, stateless for 2026-07-28). No separate server terminal needed.
node dist/index.js tier-check \
  --sdk-path /path/to/go-sdk \
  --requirements 2025-11-25,2026-07-28 \
  --output markdown

# Verify the stable release metadata directly
gh release view v1.7.0 --repo modelcontextprotocol/go-sdk

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions