From cf6d4b962d846ff4dd84f78a6f07bb2472b4e7ca Mon Sep 17 00:00:00 2001 From: cliffhall Date: Wed, 16 Sep 2026 18:16:10 -0400 Subject: [PATCH 01/17] docs: re-align the H2 2026 roadmap with the published MCP roadmap (#2400) The first draft was built from the 2026-03-05 roadmap because the current one was unreadable at the time. Rewrite Track A against the five priority areas of the 2026-08-22 roadmap, move efforts it no longer lists (Server Cards, Interceptors, grouping, streamed results, file pickers, gateways) to watch-only, record what has shipped since the first draft, and add an Official extensions section with per-client support and an extension-watch process for keeping up as extensions are approved. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 773 ++++++++++++++++-------------- 1 file changed, 402 insertions(+), 371 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 64da1509ce..e7b2803840 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -6,7 +6,7 @@ **Horizon:** 2026-08-11 → 2027-02-11 (~26 weekly milestones, `v2.2.0` → ~`v2.27.0`) **Owner:** [Inspector V2 WG](https://modelcontextprotocol.io/community/working-groups/inspector-v2) -**Status:** Draft for WG review +**Status:** Draft for WG review — **revised 2026-09-16** against the published MCP roadmap of 2026-08-22 (#2400) --- @@ -15,36 +15,33 @@ - [1. Why this document exists](#1-why-this-document-exists) - [2. The two tracks](#2-the-two-tracks) - [3. Track A — following the spec](#3-track-a--following-the-spec) - - [3.1 Transport evolution and scalability](#31-transport-evolution-and-scalability) - - [3.2 Server Cards](#32-server-cards) - - [3.3 Agent communication and Tasks](#33-agent-communication-and-tasks) - - [3.4 Enterprise readiness](#34-enterprise-readiness) - - [3.5 Triggers and events](#35-triggers-and-events) - - [3.6 Result type improvements](#36-result-type-improvements) - - [3.7 Interceptors](#37-interceptors) - - [3.8 File uploads](#38-file-uploads) - - [3.9 Skills over MCP](#39-skills-over-mcp) - - [3.10 Primitive grouping and tool annotations](#310-primitive-grouping-and-tool-annotations) - - [3.11 Conformance and validation](#311-conformance-and-validation) -- [4. Track B — experience work we choose](#4-track-b--experience-work-we-choose) - - [4.1 The zoomable timeline (headline)](#41-the-zoomable-timeline-headline) - - [4.2 Session record, replay, and share](#42-session-record-replay-and-share) - - [4.3 Diff and compare](#43-diff-and-compare) - - [4.4 Command palette and global search](#44-command-palette-and-global-search) - - [4.5 Saved calls and collections](#45-saved-calls-and-collections) - - [4.6 Assertions and CI flows](#46-assertions-and-ci-flows) - - [4.7 The argument editor workstream](#47-the-argument-editor-workstream) - - [4.8 Connection Doctor](#48-connection-doctor) - - [4.9 Server management and portability](#49-server-management-and-portability) - - [4.10 Workspace and layout](#410-workspace-and-layout) - - [4.11 Performance at scale](#411-performance-at-scale) - - [4.12 Accessibility and keyboard-first operation](#412-accessibility-and-keyboard-first-operation) - - [4.13 Onboarding](#413-onboarding) - - [4.14 Plugin architecture](#414-plugin-architecture) -- [5. Sequencing](#5-sequencing) -- [6. What we are deliberately not doing](#6-what-we-are-deliberately-not-doing) -- [7. Open questions](#7-open-questions) -- [8. Sources](#8-sources) + - [3.1 Agentic messaging primitives](#31-agentic-messaging-primitives) + - [3.2 HTTP-native transport unification and hardening](#32-http-native-transport-unification-and-hardening) + - [3.3 Agent identity and enterprise-ready security](#33-agent-identity-and-enterprise-ready-security) + - [3.4 Improved primitives](#34-improved-primitives) + - [3.5 Improved SDK developer experience](#35-improved-sdk-developer-experience) + - [3.6 Conformance and validation](#36-conformance-and-validation) + - [3.7 Off the published roadmap — watch only](#37-off-the-published-roadmap--watch-only) +- [4. Official extensions](#4-official-extensions) +- [5. Track B — experience work we choose](#5-track-b--experience-work-we-choose) + - [5.1 The zoomable timeline (headline)](#51-the-zoomable-timeline-headline) + - [5.2 Session record, replay, and share](#52-session-record-replay-and-share) + - [5.3 Diff and compare](#53-diff-and-compare) + - [5.4 Command palette and global search](#54-command-palette-and-global-search) + - [5.5 Saved calls and collections](#55-saved-calls-and-collections) + - [5.6 Assertions and CI flows](#56-assertions-and-ci-flows) + - [5.7 Observability export](#57-observability-export) + - [5.8 Connection Doctor](#58-connection-doctor) + - [5.9 Server management and portability](#59-server-management-and-portability) + - [5.10 Large servers: grouping and performance](#510-large-servers-grouping-and-performance) + - [5.11 Workspace and layout](#511-workspace-and-layout) + - [5.12 Accessibility and keyboard-first operation](#512-accessibility-and-keyboard-first-operation) + - [5.13 Onboarding](#513-onboarding) + - [5.14 Plugin architecture](#514-plugin-architecture) +- [6. Sequencing](#6-sequencing) +- [7. What we are deliberately not doing](#7-what-we-are-deliberately-not-doing) +- [8. Open questions](#8-open-questions) +- [9. Sources](#9-sources) --- @@ -63,24 +60,47 @@ This document splits the next six months into those two kinds of work, so that n starves the other. The explicit intent is a **roughly even split of capacity** — spec-following work is non-negotiable but bounded, and the remaining capacity is ours to direct. -> **Sourcing note.** The MCP roadmap circulated as a Google Doc ("MCP Roadmap Process and -> Timeline") requires authentication and could not be read directly. This plan is built from -> the **published** roadmap at `modelcontextprotocol.io/development/roadmap` (last updated -> 2026-03-05) plus the current WG and IG charters, which together cover the same themes at -> more implementation-relevant detail. If the private doc contains timelines or themes absent -> from the public page, §3 should be revised against it before the plan is adopted. +> **Sourcing note.** The first draft (#1980) was written when the MCP roadmap could not be read +> directly, and was built from the 2026-03-05 public page plus WG charters. This revision (#2400) +> re-aligns §3 with the **published** roadmap at +> [`modelcontextprotocol.io/development/roadmap`](https://modelcontextprotocol.io/development/roadmap), +> last updated **2026-08-22**, which organizes the next spec cycle into five priority areas — +> §3.1 to §3.5 follow them one to one. The roadmap itself states it "reflects current thinking +> rather than firm commitments" and carries **no per-item dates**, only a "six to twelve months" +> window, so the phase placements in §6 remain our estimate. It also adds §4, a standing +> section for **official extensions**, which the roadmap does not list and which we must track +> separately. + +### Already shipped since the first draft + +Worth recording, because much of the first draft's "build now" list is done and should not +be re-planned: + +| Item | Issue(s) | +| ----------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Last-Event-ID` resumption | [#920](https://github.com/modelcontextprotocol/inspector/issues/920) | +| `server.json` support | [#922](https://github.com/modelcontextprotocol/inspector/issues/922) | +| Discover checkmarks for task extensions | [#1887](https://github.com/modelcontextprotocol/inspector/issues/1887) | +| Strict JSON Schema validation | [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015) | +| The argument editor workstream (all six issues) | [#1853](https://github.com/modelcontextprotocol/inspector/issues/1853), [#1856](https://github.com/modelcontextprotocol/inspector/issues/1856), [#1885](https://github.com/modelcontextprotocol/inspector/issues/1885), [#1928](https://github.com/modelcontextprotocol/inspector/issues/1928), [#1919](https://github.com/modelcontextprotocol/inspector/issues/1919), [#1910](https://github.com/modelcontextprotocol/inspector/issues/1910) | +| Connection fixes (version-negotiation DX, `https://localhost`, dev containers, ghost entry) | [#962](https://github.com/modelcontextprotocol/inspector/issues/962), [#1936](https://github.com/modelcontextprotocol/inspector/issues/1936), [#1951](https://github.com/modelcontextprotocol/inspector/issues/1951), [#1914](https://github.com/modelcontextprotocol/inspector/issues/1914) | +| Server config: paste-JSON, custom headers, auth URL overrides, file-backed secrets | [#904](https://github.com/modelcontextprotocol/inspector/issues/904), [#1915](https://github.com/modelcontextprotocol/inspector/issues/1915), [#1906](https://github.com/modelcontextprotocol/inspector/issues/1906), [#1950](https://github.com/modelcontextprotocol/inspector/issues/1950) | +| Enterprise-Managed Authorization; IdP OIDC option | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509), [#1937](https://github.com/modelcontextprotocol/inspector/issues/1937) | +| Skills over MCP (SEP-2640) across web, CLI and TUI | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248) | + +Closed as **not planned**, so not carried forward: custom transports ([#1741](https://github.com/modelcontextprotocol/inspector/issues/1741)), the configurable-proxy base ([#1684](https://github.com/modelcontextprotocol/inspector/issues/1684)), the readiness summary ([#1916](https://github.com/modelcontextprotocol/inspector/issues/1916)), full panel collapse ([#928](https://github.com/modelcontextprotocol/inspector/issues/928)), `*.localhost` domains ([#1944](https://github.com/modelcontextprotocol/inspector/issues/1944)), and the trusted-local-host OAuth HTTP exception ([#1911](https://github.com/modelcontextprotocol/inspector/issues/1911)). --- ## 2. The two tracks -| | **Track A — Spec-following** | **Track B — Experience** | -| --------------------------- | ----------------------------------------------------- | ------------------------------------------- | -| **Driver** | MCP roadmap, WG deliverables, SEP acceptance | Our own judgment about the tool | -| **Trigger to start** | A SEP reaches Draft with a Tier-1 SDK reference impl | Whenever we have capacity | -| **Risk** | Slips when upstream slips; we cannot control the date | We control the date entirely | -| **Failure mode if starved** | Inspector stops being the reference test client | Inspector stays a protocol dump, not a tool | -| **Target capacity** | ~50% | ~50% | +| | **Track A — Spec-following** | **Track B — Experience** | +| --------------------------- | -------------------------------------------------------------------- | ------------------------------------------- | +| **Driver** | MCP roadmap, WG deliverables, SEP acceptance, approved extensions | Our own judgment about the tool | +| **Trigger to start** | A SEP reaches Draft with a Tier-1 SDK reference impl, or is Final | Whenever we have capacity | +| **Risk** | Slips when upstream slips; we cannot control the date | We control the date entirely | +| **Failure mode if starved** | Inspector stops being the reference test client | Inspector stays a protocol dump, not a tool | +| **Target capacity** | ~50% | ~50% | The two tracks are not independent. Several Track B items — the timeline, session record/replay, diff — are **force multipliers for Track A**: each new protocol feature @@ -90,227 +110,243 @@ general surfaces early so the spec work that lands later is cheap to display.** ### How the Inspector's role is changing -Worth stating plainly, because it shapes the priorities below. The roadmap's Validation -section names **conformance test suites**, **SDK tiers**, and **reference implementations** as -standing investments, and SEP-2484 now requires conformance tests for final SEPs. The -Inspector is the most visible MCP client in the ecosystem and is already the thing people -reach for when a server misbehaves. +Worth stating plainly, because it shapes the priorities below. The roadmap's SDK area makes +the **conformance test suite** the source of truth that SDKs and quickstarts are validated +against, and SEP-2484 (Final) requires conformance tests for Standards Track SEPs to reach +Final. The Inspector is the most visible MCP client in the ecosystem and is already the thing +people reach for when a server misbehaves. That points at an expanded role: not just _"show me the traffic"_ but _"tell me whether this -server is correct."_ Several items below (Server Card diffing, the conformance runner, -assertions, the readiness summary) are steps toward that, and they should be evaluated as a +server is correct."_ Several items below (the conformance runner, assertions, cache-hint +validation, the capability diff) are steps toward that, and they should be evaluated as a group rather than individually. --- ## 3. Track A — following the spec -Each subsection states the upstream theme, our read on what it means for the Inspector, and a -concrete feature list. **Confidence** flags how much of the list we can commit to now: +§3.1–§3.5 mirror the five priority areas of the published roadmap, in its order. Each states +the upstream area, our read on what it means for the Inspector, and a concrete feature list. +**Confidence** flags how much of the list we can commit to now: -- 🟢 **Build now** — the shape is known; blocked only on our own capacity. +- 🟢 **Build now** — the shape is known (the SEP is Final, or the work is ours alone); blocked only on our own capacity. - 🟡 **Design now, build on signal** — enough detail to design against; wait for a Draft SEP or a Tier-1 SDK impl before building. - 🔴 **Watch** — too early to predict a UI; keep a tracking issue and a WG liaison. -### 3.1 Transport evolution and scalability - -**Upstream:** Transports WG. Next-generation Streamable HTTP that runs statelessly across -multiple instances and behaves correctly behind load balancers and proxies; a session model -covering creation, resumption, and migration; conformance guidance for SDK authors. The -roadmap is explicit that **no additional official transports** ship this cycle. - -**Read:** This is the theme most likely to produce breaking wire changes, and the one where -the Inspector is most useful — session resumption and proxy behavior are exactly the failures -nobody can reproduce by reading code. Our era model (`legacy` / `modern` / `auto`) already -gives us the negotiation seam to add a third era behind. - -| Feature | Confidence | Notes | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Session lifecycle lane** — session id, creation, resumption, migration, and expiry as first-class events, not log lines | 🟢 | Renders into the timeline (§4.1). Buildable against today's session model; extends to the new one. | -| **`Last-Event-ID` resumption support and display** | 🟢 | Existing gap — [#920](https://github.com/modelcontextprotocol/inspector/issues/920). Do it now; it is table stakes for the new session work. | -| **Proxy / intermediary harness** — route through a configurable proxy, then deliberately misbehave: rewrite headers, drop the GET stream, close mid-response | 🟡 | Builds on [#1684](https://github.com/modelcontextprotocol/inspector/issues/1684). Needs a `misbehaving-proxy` preset in `test-servers/`. | -| **Stateless-mode verification** — issue the same request across N synthetic instances and diff the responses | 🟡 | Directly tests the property the WG is specifying. Pairs with §4.3. | -| **Third protocol era behind the existing negotiation seam** | 🟡 | Cost is low _if_ we keep era-conditional exposure rather than replacing the legacy path. | -| **Custom transport support** | 🟢 | [#1741](https://github.com/modelcontextprotocol/inspector/issues/1741). The roadmap pushes experimentation to custom transports, so the Inspector should be able to load one. | - -### 3.2 Server Cards - -**Upstream:** Server Card WG, [SEP-2127](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2127) (Draft). A standard `.well-known` document exposing structured server metadata so browsers, crawlers, and registries can discover capabilities **without connecting**. Deliberately kept close to a subset of `server.json`. - -**Read:** This is the single highest-leverage Track A item for us, because it creates a new -Inspector capability rather than a new panel: **inspect before connect**. It also creates an -obvious correctness question that only a tool like ours can answer. - -| Feature | Confidence | Notes | -| ----------------------------------------------------------------------------------------------------------- | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Card preview** — paste a URL, fetch the card, render the capability surface, one-click add to catalog | 🟡 | The pre-connection entry point. Wait for the format to settle. | -| **Card-vs-reality diff** — compare the advertised card against what `initialize` + `*/list` actually return | 🟡 | _The_ Inspector-shaped feature here. Nobody else in the ecosystem is positioned to check this. Shares machinery with [#1034](https://github.com/modelcontextprotocol/inspector/issues/1034) and §4.3. | -| **`mcp-inspector --card-lint `** — validate a card, non-zero exit on drift | 🟡 | CI-usable; a natural companion to the conformance runner (§3.11). | -| **`server.json` support** | 🟢 | [#922](https://github.com/modelcontextprotocol/inspector/issues/922). Prerequisite — the card is a subset, so this lands first regardless. | - -### 3.3 Agent communication and Tasks - -**Upstream:** Agents WG. Tasks (`io.modelcontextprotocol/tasks`, SEP-2663) is being -**stabilized and promoted from an extension into core**. Named open gaps: **retry semantics** -(what happens on transient failure, who decides to retry) and **expiry policies** (result -retention, how clients learn a result expired). An Agents Extension is under evaluation. - -**Read:** We already drive the modern Tasks extension ourselves over a raw-wire channel, -because SDK v2 era-gates `tasks/*` out. Promotion to core will move that back under the SDK — -plan for the migration, but **keep the era-conditional exposure**; the legacy `capabilities.tasks` -path must keep working. - -| Feature | Confidence | Notes | -| -------------------------------------------------------------------------------------------------------------------- | ---------- | ------------------------------------------------------------------------------------------- | -| **Retry visualization** — attempts, backoff, who initiated each retry | 🟡 | Design against the WG's gap list now. | -| **Expiry / TTL surfacing** — retention countdown on a completed task, distinct rendering for an expired-result error | 🟡 | Cheap once the semantics land; easy to get wrong if we guess early. | -| **Tasks as timeline spans** — a long-running task is a span, not a row | 🟢 | Falls out of §4.1 for free. The strongest argument for building the timeline first. | -| **Extension → core migration** | 🟡 | Retire the raw-wire channel when the SDK covers it; keep both paths during overlap. | -| **`Mcp-Name` header on Tasks over Streamable HTTP** | 🟢 | [#1917](https://github.com/modelcontextprotocol/inspector/issues/1917) — open bug, fix now. | -| **Discover checkmarks for task extensions** | 🟢 | [#1887](https://github.com/modelcontextprotocol/inspector/issues/1887). | - -### 3.4 Enterprise readiness - -**Upstream:** An Enterprise WG is expected to form. Four named areas: **audit trails and -observability**, **enterprise-managed auth** (Cross-App Access / ID-JAG), **gateway and proxy -patterns**, and **configuration portability**. Most output is expected as extensions rather -than core spec changes. Related: the Enterprise-Managed Authorization IG, and sponsored work -on [SEP-1932 (DPoP)](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/1932) and [SEP-1933 (Workload Identity Federation)](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/1933). - -**Read:** "Audit trails and observability, in a form enterprises can feed into their existing -pipelines" is a description of something the Inspector nearly already has. We hold the entire -session; we simply cannot **export** it in any pipeline-shaped format. That gap is cheap to -close and disproportionately valuable. - -| Feature | Confidence | Notes | -| ------------------------------------------------------------------------------------------------------ | ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **OTLP export** — emit the session as OpenTelemetry spans; show trace/span ids inline; "copy as trace" | 🟢 | SEP-414 already puts trace context in `_meta`. Buildable today, no upstream dependency. | -| **Structured audit transcript** — the full session as a stable, documented JSON artifact | 🟢 | Shares its format with §4.2 record/replay. Build once, use for both. | -| **Machine-readable readiness summary** | 🟢 | [#1916](https://github.com/modelcontextprotocol/inspector/issues/1916). | -| **ID-JAG / Cross-App Access test flow** | 🟡 | The EMA IG exists specifically because this only works when IdP + client + AS interoperate. A test client is exactly what they lack. Related: [#1937](https://github.com/modelcontextprotocol/inspector/issues/1937), [#571](https://github.com/modelcontextprotocol/inspector/issues/571). | -| **DPoP and Workload Identity Federation** | 🔴 | Both sponsored but pre-acceptance. Watch; do not build. | -| **Gateway mode** — declare an intermediary, then show what we sent vs. what the gateway forwarded | 🟡 | Depends on the Gateways IG settling propagation semantics. | -| **Configuration portability** | 🟢 | [#1912](https://github.com/modelcontextprotocol/inspector/issues/1912), [#904](https://github.com/modelcontextprotocol/inspector/issues/904), plus `server.json` (§3.2). | - -### 3.5 Triggers and events - -**Upstream:** Triggers and Events WG. A standardized server→client callback mechanism -(webhooks or similar), with subscription lifecycle and **ordering guarantees that hold across -all transports**. Status: "SEP: Events in MCP v1 RFC" — **Ideating**. - -**Read:** ⚠️ **This is the largest architectural change on the horizon for us, and the one we -are least prepared for.** Every Inspector surface today assumes we are the party that -_initiated_ the connection. A webhook mechanism makes us a **server** — we must host a -publicly reachable callback endpoint, which for a tool that usually runs on `localhost` is a -real problem (tunnels, port forwarding, or a relay). - -We should start the design conversation **now**, well ahead of the SEP, and bring it to the -WG as implementation feedback. The ordering-guarantee requirement in particular is -untestable without a client that records arrival order — which is us. - -| Feature | Confidence | Notes | -| ----------------------------------------------------------------------------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------ | -| **Callback receiver** — backend-hosted endpoint, its URL registered as the trigger target | 🔴 | Needs design now, build later. Security review mandatory: an inbound public endpoint on a process that spawns subprocesses is a serious surface. | -| **Local reachability story** — tunnel integration or documented guidance | 🔴 | Likely the hardest UX problem of the whole six months. | -| **Delivery log with ordering and duplicate assertions** | 🔴 | The conformance value: did events arrive in the promised order? were any redelivered? | - -### 3.6 Result type improvements - -**Upstream:** "On the Horizon." **Streamed results** (incremental output for generated text, -audio, video frames) and **reference-based results** (client decides when to pull a large -payload into context). Explicitly cross-cutting — streaming touches transport, references -touch the schema. - -**Read:** Streaming changes how every result panel renders: today we display a _result_, and -we would need to display a _stream that becomes a result_. Worth a rendering abstraction -before the SEP, not after. - -| Feature | Confidence | Notes | -| ------------------------------------------------------------------------------------------------------- | ---------- | ----------------------------------------------------------------------------------- | -| **Incremental result rendering** — progressive display, with time-to-first-chunk and inter-chunk timing | 🔴 | The timing view is Inspector-shaped; the timeline is the natural home. | -| **Reference-result handling** — show a handle plus an explicit "pull payload", with size accounting | 🔴 | Also a good default for large payloads _today_, independent of the SEP (see §4.11). | - -### 3.7 Interceptors - -**Upstream:** Interceptors WG, [SEP-1763](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2076) (Draft). Interceptors as a new primitive with two types — **validators** (pass/fail) and **mutators** (transform payloads) — across in-process, sidecar, and remote deployment models, with priority-based chain ordering and audit-mode semantics. A **CLI client for interceptor invocation and testing** is a listed WG deliverable (Ideating, unowned). - -**Read:** Two things stand out. First, "CLI client for interceptor invocation and testing" is -**an unclaimed deliverable that describes our CLI**. Worth raising with the WG — Ola co-leads -both groups, so the liaison already exists. Second, an interceptor chain is a -_before → after payload transformation_, which is a diff, which we should already be able to -render (§4.3). - -| Feature | Confidence | Notes | -| ---------------------------------------------------------------------------------------------------------- | ---------- | ---------------------------------------------------------------------------------------------------------------------- | -| **Interceptor test bench** — register a chain, show before/after diff per hop, visualize priority ordering | 🟡 | The clearest "Inspector as the reference tool" opportunity of the six months. | -| **Audit-mode rendering** — what _would_ have been blocked or mutated | 🟡 | Follows the SEP's audit semantics. | -| **CLI interceptor invocation** | 🟡 | **Action: raise with the Interceptors WG.** If we take it, it needs its own milestone allocation. | -| **Our plugin architecture as an interceptor host** | 🟡 | [#1025](https://github.com/modelcontextprotocol/inspector/issues/1025). Prevents us building two extension mechanisms. | - -### 3.8 File uploads - -**Upstream:** File Uploads WG, [SEP-2356](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2356) (Draft, TS SDK reference impl targeted End May). Declarative `FileInputDescriptor` on tool input schemas and elicitation schemas, so hosts render native file pickers. Success criteria explicitly include **"at least one production host rendering a native file picker from the descriptor."** - -**Read:** The most tractable Track A item on the list — narrow, well-specified, with a TS SDK -reference implementation coming, and we are a credible candidate for that "production host." -It touches three surfaces: `SchemaForm` (Tools), elicitation forms, and MCP Apps. - -| Feature | Confidence | Notes | -| ------------------------------------------------------------------------------------ | ---------- | ------------------------------------------------ | -| **File picker in `SchemaForm`** when a descriptor is present, with data-URI encoding | 🟡 | Wait for the TS SDK types, then build. Low risk. | -| **Same in elicitation forms** | 🟡 | Shared component. | -| **Size guardrails and host-side validation** | 🟡 | The SEP references OWASP ASVS V5. | - -### 3.9 Skills over MCP - -**Upstream:** Skills Over MCP WG, [SEP-2640](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2640) (In Review, Extensions Track). Resources-based; a reference implementation is also In Review. - -**Read:** Because it is Resources-based, the incremental cost is low — a Skills view over the -existing resource machinery rather than a new subsystem. - -| Feature | Confidence | Notes | -| -------------------------------------------------------- | ---------- | -------------------------------------------------------------------- | -| **Skills view** — list, preview content, show activation | 🟡 | Gate on the negotiated extension, the way the Tasks tab gates today. | - -### 3.10 Primitive grouping and tool annotations - -**Upstream:** Two IGs. **Primitive Grouping** explores organizing Tools/Resources/Prompts -beyond flat lists — deliberately not picking one canonical pattern early. **Tool Annotations** -is consolidating six independent annotation SEPs and considering runtime annotations and tool -_response_ annotations. - -**Read:** Grouping is the rare case where the spec-following work and the UX work are the same -work. Flat lists are already our weakest surface on large servers — [#1957](https://github.com/modelcontextprotocol/inspector/issues/1957) (duplicate tool names) was a symptom. **Build the grouped sidebar as a UX -improvement now**, and adopt whatever grouping the IG lands as a data source later. - -| Feature | Confidence | Notes | -| ------------------------------------------------------------------ | ---------- | --------------------------------------------------------------------------------------------------------------------- | -| **Grouped / tree sidebars with group-aware search** | 🟢 | Build now on client-side heuristics (name prefixes, annotations). Ship value immediately; swap the data source later. | -| **Richer annotation rendering** | 🟢 | Extends the existing `AnnotationBadge`. | -| **Annotation-driven confirmation** before a `destructiveHint` call | 🟢 | Small, obviously correct, no upstream dependency. | -| **Runtime / response annotations** | 🔴 | Watch. | - -### 3.11 Conformance and validation - -**Upstream:** Standing investment — conformance test suites, SDK tiers ([SEP-1730](https://github.com/modelcontextprotocol/modelcontextprotocol/issues/1730)), reference implementations. [SEP-2484](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2484) now **requires conformance tests for final SEPs**, and the EMA IG is explicitly contributing scenarios to the `modelcontextprotocol/conformance` repository. +### 3.1 Agentic messaging primitives + +**Upstream:** Triggers & Events, Agents, and Transports WGs. Messaging beyond +request/response: work that runs for minutes, servers that push, results that stream, and +steering work mid-flight. This period: **server-initiated events** ("channels and +subscriptions for push delivery, including webhooks") and a **composition review** so Tasks, +triggers, `subscriptions/listen` and progress notifications share "a lifecycle, a cancellation +model, [and] an error surface". **Beyond this period:** Tasks (SEP-2663) toward eventual +inclusion in core. + +**Read:** Two changes from the first draft. First, **Tasks moving into core is no longer a +this-period item**, so the raw-wire Tasks channel stays for the whole horizon and its +retirement drops out of the plan. Second, the composition review names the exact thing a +timeline can show better than any list: three kinds of "not done yet" work side by side. That +argues for **one lane for in-flight work** rather than a tasks lane and a subscriptions lane. + +The webhook half remains the largest architectural change on the horizon for us. Every +Inspector surface assumes we initiated the connection; a webhook makes us a **server** that +must be publicly reachable, which a tool usually run on `localhost` is not. Start the design +conversation now and bring it to the WG as implementation feedback. + +| Feature | Confidence | Notes | +| ----------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | +| **In-flight work lane** — tasks, open `subscriptions/listen` streams and progress-reporting requests as spans on one timeline lane (§5.1) | 🟢 | All three already exist in the 2026-07-28 spec. Makes composition gaps (mismatched cancellation, divergent errors) visible, which the WG can use. | +| **Cancellation and error comparison** — show how each in-flight kind ended (completed, cancelled, errored, server-closed) with the same vocabulary | 🟢 | A small, direct contribution to the composition review. | +| **Callback receiver** — backend-hosted endpoint registered as a push target | 🔴 | Design now, build when the SEP lands. Security review mandatory: an inbound public endpoint on a process that spawns subprocesses. | +| **Local reachability story** — tunnel integration or documented guidance | 🔴 | Likely the hardest UX problem of the six months. | +| **Delivery log with ordering and duplicate assertions** | 🔴 | The conformance value: did events arrive in order? were any redelivered? | +| **`Mcp-Name` header on Tasks over Streamable HTTP** | 🟡 | [#1917](https://github.com/modelcontextprotocol/inspector/issues/1917) — blocked upstream. | +| **Tasks extension → core migration** | 🔴 | Moved to "Beyond" upstream. Keep the era-conditional exposure; the legacy `capabilities.tasks` path must keep working. | + +### 3.2 HTTP-native transport unification and hardening + +**Upstream:** Transports WG. "The 2026-07-28 release made a remote MCP server a normal HTTP +workload." The goal is **one transport model**: **HTTP over stdio** (Streamable HTTP as the +single binding, possibly HTTP/2 over stdin/stdout for multiplexing) and **caching** — SEP-2549 +(Final) added `ttlMs` and `cacheScope` to list results and resource reads, with **ETags** next, +including for tool-call results. **Beyond:** standardized error handling across all surfaces, +capability scoping for tool lists after SEP-2575, and a secure way to hand servers +configuration. + +**Read:** The first draft's §3.1 (stateless Streamable HTTP, session creation / resumption / +migration) is **largely obsolete**: SEP-2575 (stateless) and SEP-2567 (sessionless, explicit +state handles) are Final and already shipped. A "session lifecycle lane" describes a model the +spec has left behind; what remains to show is **state handles**. Caching, on the other hand, is +Final and we already parse the fields — we just do not render them, and a client that shows +cache hints is exactly how a server author finds out theirs are wrong. + +HTTP over stdio would change how every stdio server connects, and our transport layer is +where the Inspector is thinnest over the SDK. Watch closely. + +| Feature | Confidence | Notes | +| --------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | ----------------------------------------------------------------------------------------------------------------------- | +| **Cache hint display** — `ttlMs` / `cacheScope` on every list and resource read, with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. Today the fields appear only in our tests. | +| **Cache behavior checks** — flag a re-fetch the hints said was unnecessary, and a list that changed inside its declared TTL | 🟢 | Inspector-shaped: nobody else observes both the hint and the reality. | +| **State handle view** — surface SEP-2567 state handles as first-class values, not opaque fields | 🟢 | Replaces the first draft's "session lifecycle lane". | +| **ETag support** — send `If-None-Match`, show 304s and version changes | 🟡 | Build when the SEP reaches Draft with an SDK impl. | +| **HTTP over stdio** | 🔴 | Watch. If it lands, the Network screen becomes meaningful for stdio servers too — a large win. | +| **Standardized error rendering** | 🔴 | "Beyond". Our Protocol-vs-Network error split (#1628) is the seam to adopt it into. | + +### 3.3 Agent identity and enterprise-ready security + +**Upstream:** Agent Identity WG (forming this period), coordinated with the IETF OAuth and +WIMSE WGs. MCP authorization assumes a person at a browser; increasingly the caller is an +agent. This period: **finalize DPoP** and drive adoption; an opinionated **agent identity and +delegation** model built on **Workload Identity Federation** (SEP-1933), **ID-JAG** as used by +Enterprise-Managed Authorization, and **RFC 8693 token exchange**. **Beyond:** +human-presence attestation. + +**Read:** DPoP was 🔴 in the first draft and is now a named deliverable, so it moves up. Our +EMA work (#1509) already gives us the ID-JAG leg, which makes the Inspector a credible test +client for the whole identity chain. The first draft's audit trails, gateway mode and +configuration portability are **no longer on the MCP roadmap**; OTLP export and the audit +transcript are still worth building, but as our own Track B work (§5.7), not as spec-following. + +| Feature | Confidence | Notes | +| --------------------------------------------------------------------------------------------------------- | ---------- | ----------------------------------------------------------------------------------------------- | +| **OAuth Client Credentials extension** — client-secret and JWT-bearer assertion flows | 🟢 | An **approved** official extension (§4) we do not support. No upstream dependency. | +| **Token exchange (RFC 8693) test flow** | 🟡 | Named in the roadmap; the RFC is stable, the MCP profile of it is not. | +| **DPoP** — generate a proof key, send `DPoP` proofs, show proof/nonce exchange in the Network view | 🟡 | Design against SEP-1932; build when it is Final or has a Tier-1 SDK impl. | +| **Workload Identity Federation** | 🟡 | SEP-1933. Needs a way to present a workload credential from a developer machine — design first. | +| **Human-presence attestation** | 🔴 | "Beyond". | + +### 3.4 Improved primitives + +**Upstream:** Core Primitives WG (forming this period); File Uploads WG. This period: a +**`tools/call` result-shape redesign** to resolve the `content` vs `structuredContent` +confusion; **progressive discovery**, where clients learn tools and resources as needed +instead of ingesting the whole catalog, interacting with the caching work; and a review of +**primitive annotations** (audience and priority), which "most implementers haven't adopted" +and which may be deprecated. The File Uploads WG continues on **scoped file operations and +filesystem-like resource semantics** (range reads, hierarchical listing). + +**Read:** Every item here touches a panel we own. The result-shape redesign rewrites the tool +result view; progressive discovery breaks the assumption behind every list we render (that +`*/list` returns everything); and a possible annotation deprecation means we should not invest +in richer annotation rendering now. The first draft's §3.6 (streamed and reference results) +and §3.8 (the SEP-2356 file picker) are **not on the published roadmap** and move to watch. + +What we _can_ do now is show the problem the redesign is solving: a server returning +`content` and `structuredContent` that disagree is a real bug today. + +| Feature | Confidence | Notes | +| ------------------------------------------------------------------------------------------------------------------------ | ---------- | ------------------------------------------------------------------------------------------------------------------------ | +| **`content` / `structuredContent` consistency check** — flag results where the two disagree or one is missing | 🟢 | Useful today, and implementation evidence for the Core Primitives WG. | +| **New tool result shape** | 🔴 | WG still forming. Keep both renderings behind the era seam when it lands. | +| **Progressive discovery** | 🔴 | Design the lists (§5.10) so "not loaded yet" is a state, not an empty list. | +| **Annotation-driven confirmation** before a `destructiveHint` call | 🟢 | Tool annotations are not the audience/priority content annotations under review. Small and obviously correct. | +| **Richer audience / priority annotation rendering** | 🔴 | Paused: may be deprecated. | +| **Range reads and hierarchical resource listing** | 🟡 | We already render `resources/directory/read` for Skills (#2248); generalize it when the File Uploads WG publishes a SEP. | + +### 3.5 Improved SDK developer experience + +**Upstream:** SDK WG with the Core Maintainers. This period: **the extension contract** — +which role an extension binds (host, client, server, agent), what each does when the +capability is declared, what SDKs must support natively, packaging, and capability additions +as versioned changes; and **the generated-artifacts experiment** — generate a Tier-1 SDK and its +quickstarts from the spec, validated against the conformance suite. + +**Read:** The extension contract decides how we present extensions: today our capability view +lists advertised extension ids, and a contract that names roles and versions gives us +something to validate declarations against. The generated-artifacts experiment makes the +conformance suite central, which strengthens §3.6. + +| Feature | Confidence | Notes | +| ------------------------------------------------------------------------------------------------------------------------------- | ---------- | ---------------------------------------------------------------------------------------- | +| **Extension declaration view** — for each advertised extension: identifier, settings object, whether the Inspector supports it | 🟢 | Buildable on today's negotiation (#1738); extend with role and version once the contract lands. | +| **Extension contract validation** | 🟡 | Validate a server's declaration against the contract once published. | +| **Run generated quickstart servers as fixtures** | 🔴 | If the experiment publishes them, they are free test servers. | + +### 3.6 Conformance and validation + +**Upstream:** Standing investment rather than a priority area — the conformance suite, SDK +tiers ([SEP-1730](https://modelcontextprotocol.io/seps/1730-sdks-tiering-system)), and +[SEP-2484](https://modelcontextprotocol.io/seps/2484-conformance-tests-required-for-final-seps) +(Final), which requires conformance tests for Standards Track SEPs to reach Final. §3.5 makes +the suite the validation target for generated SDKs. **Read:** A conformance suite needs a driver and a report. We are the natural driver, and we -already have a CLI that exits non-zero. This is the clearest path to the expanded role -described in §2 — and unlike most of Track A, **it is not gated on any SEP**. +already have a CLI that exits non-zero. The runner itself needs agreement with the suite's +maintainers on a programmatic interface; the **assertion engine** it would share with §5.6 +does not. + +| Feature | Confidence | Notes | +| ------------------------------------------------------------------------------------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------------------------- | +| **Conformance runner** — run the suite against a connected server, render pass/fail per assertion | 🟡 | **Action: open a conversation with the conformance maintainers.** Build the shared assertion engine (§5.6) first. | +| **`mcp-inspector --conformance` for CI** | 🟡 | Same engine, CLI report, exit code. | +| **Strict schema validation with actionable errors** | ✅ | Shipped — [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015). | + +### 3.7 Off the published roadmap — watch only + +The first draft planned build work for several WG efforts that the 2026-08-22 roadmap does not +list. They are not cancelled upstream — WGs keep working outside the priority areas — but the +roadmap says SEPs outside those areas "expect a longer queue", so **we do not schedule build +work for them this horizon**. Each keeps a tracking issue and a liaison. + +| Effort | First-draft plan | Now | +| ---------------------------------------------------------------------------------------- | ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| **Server Cards** (SEP-2127) | Card preview, card-vs-reality diff, `--card-lint` in Phase 3 | 🔴 Watch. [#1857](https://github.com/modelcontextprotocol/inspector/issues/1857)'s **registry** half does not depend on it (§5.9). | +| **Interceptors** (SEP-1763) | Test bench, audit mode, CLI invocation in Phase 4 | 🔴 Watch. The WG's unowned "CLI client for interceptor invocation" is still worth raising (§8). | +| **Primitive grouping** (IG) | Grouped sidebars | The **UX** half proceeds as Track B (§5.10) on client-side heuristics; no spec data source is expected this horizon. | +| **Streamed and reference results** | Incremental rendering, reference handles | 🔴 Watch. Payload truncation in §5.10 covers the large-result case today. | +| **File picker from `FileInputDescriptor`** (SEP-2356) | `SchemaForm` + elicitation picker | 🔴 Watch. The File Uploads WG's published direction is now filesystem-like resources (§3.4). | +| **Gateways, audit trails, configuration portability** | Gateway mode; OTLP as spec work | Gateway mode dropped. OTLP and the audit transcript continue as Track B (§5.7). | + +--- -| Feature | Confidence | Notes | -| ------------------------------------------------------------------------------------------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Conformance runner** — run the suite against a connected server, render pass/fail per assertion | 🟡 | Needs coordination on the suite's programmatic interface. **Action: open a conversation with the conformance maintainers.** | -| **`mcp-inspector --conformance` for CI** | 🟡 | Same engine, CLI report, exit code. | -| **Strict schema validation with actionable errors** | 🟢 | [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015). No dependency; start here. | +## 4. Official extensions + +The MCP roadmap does not list extensions, but **approved extensions are spec-following work** — +a client that ignores them stops being a reference client. The list lives at +[`/extensions/overview`](https://modelcontextprotocol.io/extensions/overview), implementations +are recorded in the community-maintained +[client matrix](https://modelcontextprotocol.io/extensions/client-matrix), and extensions reach +official status through the Extensions Track of +[SEP-2133](https://modelcontextprotocol.io/seps/2133-extensions), usually after incubating in an +`experimental-ext-*` repository. + +### Current support (as of 2026-09-16) + +| Extension | Identifier | Web | CLI | TUI | Upstream matrix | Notes | +| -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ------------------------ | ------------------------------------------------------------------------------------------------------- | +| MCP Apps | `io.modelcontextprotocol/ui` | ✅ | — | — | ❌ not listed | Apps tab. Rendering an app needs a browser, so CLI/TUI absence is by design. | +| Tasks | `io.modelcontextprotocol/tasks` | ✅ | ✅ | ❌ | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). No TUI Tasks pane yet. | +| Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | +| Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | ✅ | ✅ | ❌ not listed | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). | +| OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | ❌ | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | + +**Actions:** implement OAuth Client Credentials; and, with maintainer sign-off, open a PR on +`modelcontextprotocol/modelcontextprotocol` to correct the Inspector's row in the client matrix. + +### Keeping up as extensions are approved + +We picked up Skills because someone noticed, not because anything told us. Make it a +mechanism, the way SDK releases already are: + +- **An extension-watch sweep**, modelled on `scripts/sdk-watch.mjs`: on a schedule, list the + org's `ext-*` and `experimental-ext-*` repositories and the extension identifiers on + `/extensions/overview`, compare with a committed list of the ones we have assessed, and file + one issue per new entry. It **files issues, never PRs**, and trusts only markers the + automation wrote, exactly as the SDK watch does. +- **Official extension** → a `v2` + `enhancement` issue to implement it, milestoned at triage. +- **Experimental extension** → a `v2` + `question` tracking issue, so we can design against it + before its SEP (the 🟡 rule) without committing build capacity. +- **This table is the record.** An extension is added here when its issue is filed, and its + cells move as support lands. --- -## 4. Track B — experience work we choose +## 5. Track B — experience work we choose -Nothing in this section waits on a SEP. Ordered by leverage, not by effort. +Nothing in this section waits on a SEP or another project. Ordered by leverage, not by effort. -### 4.1 The zoomable timeline (headline) +### 5.1 The zoomable timeline (headline) **Committed.** The single feature that most changes what the Inspector _is_. @@ -327,7 +363,7 @@ at a glance. Timeline become three renderings of one session. This keeps the coverage gate and the existing `protocolUtils` derivations intact. - **Lanes**, each independently collapsible: - `client → server` · `server → client` · notifications · tasks · subscription streams · OAuth/auth · errors + `client → server` · `server → client` · notifications · **in-flight work** (tasks, subscriptions, progress — §3.1) · OAuth/auth · errors - **Spans, not points.** A request occupies from send to response; a task occupies its whole lifetime; a stream is a bar with events on it. Duration becomes visible, which is most of the value. @@ -342,20 +378,20 @@ at a glance. - **Latency distribution** as a secondary view — per method, so a slow tool is obvious. - **Virtualized**, keyboard-navigable, and rendered from the same store the other views use. -**Deliberately out of scope for v1 of this feature:** cross-server correlation (needs §4.10), -and OTLP-shaped nesting (needs §3.4). +**Deliberately out of scope for v1 of this feature:** cross-server correlation (needs §5.11), +and OTLP-shaped nesting (needs §5.7). -### 4.2 Session record, replay, and share +### 5.2 Session record, replay, and share Save a complete session — protocol log, network log, server config, negotiated capabilities — to a single file. Reopen it later, on another machine, with no server running. Attach it to a bug report. This changes issue triage from "works on my machine" into an artifact, and it is the same -serialization format as the enterprise audit transcript (§3.4) — **build the format once**. -Replay also gives us fixtures: a recorded session is a regression test. +serialization format as the audit transcript (§5.7) — **build the format once**. Replay also +gives us fixtures: a recorded session is a regression test. -### 4.3 Diff and compare +### 5.3 Diff and compare Two sessions, or two servers, side by side. Concretely: @@ -364,166 +400,154 @@ Two sessions, or two servers, side by side. Concretely: - **Session diff** — same calls, two servers, what differed. - **Payload diff** — before/after for any pair of JSON documents. -The payload differ is a **shared primitive**: interceptor before/after (§3.7), Server -Card-vs-reality (§3.2), and stateless-instance comparison (§3.1) are all the same widget with -different inputs. Build it as a component first, then wire the three consumers. +The payload differ is a **shared primitive**: capability diff, session diff, the cache checks +(§3.2) and any later card-vs-reality or interceptor view are the same widget with different +inputs. Build it as a component first, then wire the consumers. -### 4.4 Command palette and global search +### 5.4 Command palette and global search `⌘K` to jump to any server, tool, resource, or prompt; re-run the last call; switch tabs. Plus full-text search across the protocol log with a real filter syntax (`method:tools/call status:error duration:>500ms`). The Inspector is currently a mouse-driven app; for a developer tool that is a daily tax. -### 4.5 Saved calls and collections +### 5.5 Saved calls and collections Name a tool call with its arguments, save it, re-run it, parameterize it, share it. A Postman-collection model for MCP. The single most requested shape of workflow improvement for -any protocol client, and it composes directly with §4.6. +any protocol client, and it composes directly with §5.6. -### 4.6 Assertions and CI flows +### 5.6 Assertions and CI flows Attach expectations to a saved call — result matches schema, field equals value, latency under a bound — and run the collection from the CLI with a non-zero exit on failure. This turns the Inspector from an interactive tool into part of a server author's test suite, and it shares an -engine with the conformance runner (§3.11). -Related: [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1886](https://github.com/modelcontextprotocol/inspector/issues/1886), [#1916](https://github.com/modelcontextprotocol/inspector/issues/1916). +engine with the conformance runner (§3.6). -### 4.7 The argument editor workstream +### 5.7 Observability export -Six open issues are all the same defect class — the argument editor is not schema-aware: +Moved here from the first draft's enterprise section: the roadmap no longer lists audit trails, +but we hold the entire session and cannot export it in any pipeline-shaped form. -| Issue | Symptom | -| ---------------------------------------------------------------------- | ------------------------------------------------------------------- | -| [#1853](https://github.com/modelcontextprotocol/inspector/issues/1853) | JSON parameter editor escaping while typing | -| [#1856](https://github.com/modelcontextprotocol/inspector/issues/1856) | Backspace recursively escapes JSON tool inputs | -| [#1885](https://github.com/modelcontextprotocol/inspector/issues/1885) | Null values corrupted with cascading escapes | -| [#1928](https://github.com/modelcontextprotocol/inspector/issues/1928) | Nullable enums fall back to a broken raw Textarea (v1.x regression) | -| [#1919](https://github.com/modelcontextprotocol/inspector/issues/1919) | Resource templates lack RFC 6570 expansion | -| [#1910](https://github.com/modelcontextprotocol/inspector/issues/1910) | Complex `_meta` not expressible | +- **OTLP export** — emit the session as OpenTelemetry spans; show trace/span ids from `_meta` + (SEP-414) inline; "copy as trace". +- **Structured audit transcript** — the §5.2 session file, documented as a stable format. -**Fix them as one workstream, not six bugs.** A proper schema-aware editor (CodeMirror or -Monaco with JSON Schema integration) resolves the class and unblocks file inputs (§3.8) and -strict validation (§3.11). Treating them individually has already produced one regression from -v1. +### 5.8 Connection Doctor -### 4.8 Connection Doctor +The individual connection bugs have been fixed (§1), but a failure is still reported as a +single error. Run an ordered checklist on failure — DNS · TCP · TLS (including local-cert +cases) · `/.well-known` discovery · protocol version negotiation · auth — and report **which +step failed and what to do about it**. First-connection success is the entire first impression +of the tool. -Connection failures are currently opaque, and five open issues say so -([#962](https://github.com/modelcontextprotocol/inspector/issues/962), [#1936](https://github.com/modelcontextprotocol/inspector/issues/1936), [#1951](https://github.com/modelcontextprotocol/inspector/issues/1951), [#1944](https://github.com/modelcontextprotocol/inspector/issues/1944), [#1914](https://github.com/modelcontextprotocol/inspector/issues/1914)). +### 5.9 Server management and portability -Run an ordered checklist on failure — DNS · TCP · TLS (including local-cert cases) · -`/.well-known` discovery · protocol version negotiation · auth — and report **which step -failed and what to do about it**. First-connection success is the entire first impression of -the tool, and today a `https://localhost` server or a dev container silently fails. +Most of the first draft's list has shipped (§1). What remains is +[#1857](https://github.com/modelcontextprotocol/inspector/issues/1857), rich server configuration, +whose **registry** half — browse an MCP Registry, pick a server, generate its configuration +form from `server.json` — needs nothing but the Registry API and our existing `server.json` +support (#922). Its Server Card half waits on SEP-2127 (§3.7). -Bundle the related fixes: `*.localhost` domains ([#1944](https://github.com/modelcontextprotocol/inspector/issues/1944)), the trusted-local-host OAuth HTTP -exception ([#1911](https://github.com/modelcontextprotocol/inspector/issues/1911)), and the ghost-server entry left by a failed manual connect ([#1914](https://github.com/modelcontextprotocol/inspector/issues/1914)). +### 5.10 Large servers: grouping and performance -### 4.9 Server management and portability +A 1000-tool server or a long-running session should not degrade. -Already well represented on the board; grouping it here so it is scheduled as a theme rather -than piecemeal: rich server configuration ([#1857](https://github.com/modelcontextprotocol/inspector/issues/1857)), custom headers and cookies ([#1915](https://github.com/modelcontextprotocol/inspector/issues/1915)), -auth/token URL overrides ([#1906](https://github.com/modelcontextprotocol/inspector/issues/1906)), file-backed secrets where no OS keychain exists ([#1950](https://github.com/modelcontextprotocol/inspector/issues/1950)), -paste-MCP-JSON ([#904](https://github.com/modelcontextprotocol/inspector/issues/904)), and registry discovery ([#1101](https://github.com/modelcontextprotocol/inspector/issues/1101)). +- **Grouped / tree lists with group-aware search**, built on client-side heuristics (name + prefixes, annotations). No spec data source is expected this horizon (§3.7). +- **Virtualize** the long lists and logs; cap in-memory protocol history; truncate large + payloads by default with explicit expansion. +- Design lists so **"not loaded yet" is a state**, ready for progressive discovery (§3.4). -### 4.10 Workspace and layout +### 5.11 Workspace and layout Multiple servers side by side — the actual shape of debugging a gateway, or comparing a server against a reference implementation. Detachable/resizable panels, remembered layout per -server, density modes, and full-collapse ([#928](https://github.com/modelcontextprotocol/inspector/issues/928)). Prerequisite for cross-server timeline -correlation. +server, and density modes. Prerequisite for cross-server timeline correlation. -### 4.11 Performance at scale - -A 1000-tool server or a long-running session should not degrade. Virtualize the long lists and -logs; cap in-memory protocol history with spill-to-disk; truncate large payloads by default -with explicit expansion (which is also the right default for reference results, §3.6). - -### 4.12 Accessibility and keyboard-first operation +### 5.12 Accessibility and keyboard-first operation Full keyboard operation across every tab, correct roles and labels, high-contrast support, and `prefers-reduced-motion` (which the timeline's animations will make newly relevant). We have a Storybook a11y harness already; the gap is coverage, not tooling. -### 4.13 Onboarding +### 5.13 Onboarding A first run currently presents an empty server list and no path forward. Add a guided first connection, one-click example servers drawn from `test-servers/`, and inline links from each panel to the relevant spec section. -### 4.14 Plugin architecture +### 5.14 Plugin architecture -[#1025](https://github.com/modelcontextprotocol/inspector/issues/1025). The multiplier on everything above — custom panels, custom transports (§3.1), -interceptor hosting (§3.7), and community-contributed views without core changes. Sequenced -late deliberately: designing a plugin API before the timeline, diff, and session format exist -would mean designing it against the wrong surfaces. +[#1025](https://github.com/modelcontextprotocol/inspector/issues/1025) recorded the placeholder +spec. The multiplier on everything above — custom panels and community-contributed views +without core changes. Sequenced late deliberately: designing a plugin API before the timeline, +diff, and session format exist would mean designing it against the wrong surfaces. --- -## 5. Sequencing +## 6. Sequencing Four phases of roughly six weekly milestones each. Track A items appear where their upstream -signal is expected; Track B items are placed to unblock Track A wherever possible. - -### Phase 1 — Foundations (~`v2.2` – `v2.7`, Aug–Sep 2026) +signal is expected; Track B items are placed to unblock Track A wherever possible. Phase 1 is +annotated with what has already shipped. -_Build the general surfaces the rest of the plan renders into, and clear the debt that makes -first impressions bad._ +### Phase 1 — Foundations (~`v2.2` – `v2.9`, Aug–Sep 2026) -- 🅑 **Zoomable timeline v1** — lanes, spans, zoom/pan, click-through -- 🅑 **Argument editor workstream** (§4.7) — closes six issues as one -- 🅑 **Connection Doctor** (§4.8) + the local-host connection fixes -- 🅐 `Last-Event-ID` resumption ([#920](https://github.com/modelcontextprotocol/inspector/issues/920)); `Mcp-Name` on Tasks ([#1917](https://github.com/modelcontextprotocol/inspector/issues/1917)); discover checkmarks ([#1887](https://github.com/modelcontextprotocol/inspector/issues/1887)) -- 🅐 `server.json` support ([#922](https://github.com/modelcontextprotocol/inspector/issues/922)) — prerequisite for Server Cards -- ⚙️ Windows CI/gate fixes already in `v2.2.0` +- ✅ `Last-Event-ID` resumption (#920); discover checkmarks (#1887); `server.json` (#922) +- ✅ Argument editor workstream (six issues); connection fixes (§1) +- ✅ Skills over MCP (#2234, #2248); Enterprise-Managed Authorization (#1509) +- 🅑 **Zoomable timeline v1** — carried into Phase 2 +- 🅑 **Connection Doctor** (§5.8) — carried into Phase 2 -### Phase 2 — Artifacts and comparison (~`v2.8` – `v2.13`, Sep–Nov 2026) +### Phase 2 — Artifacts, comparison, and cheap spec wins (~`v2.10` – `v2.15`, Oct–Nov 2026) -_Make sessions into things you can keep, share, and compare._ +_Make sessions into things you can keep, share, and compare; take the Final-SEP and extension +items that need no upstream work._ -- 🅑 **Session record / replay / share** (§4.2) — format shared with audit transcript -- 🅑 **Diff primitive** (§4.3) — then wire capability diff ([#1034](https://github.com/modelcontextprotocol/inspector/issues/1034)) -- 🅑 **Command palette and global search** (§4.4) -- 🅐 **OTLP export and audit transcript** (§3.4) — no upstream dependency -- 🅐 **Grouped sidebars** (§3.10) on client-side heuristics -- 🅐 Strict schema validation ([#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015)) -- 🅐 Timeline lanes for tasks and sessions (falls out of Phase 1) +- 🅑 **Zoomable timeline v1**, including the **in-flight work lane** (§3.1) +- 🅑 **Session record / replay / share** (§5.2) — format shared with the audit transcript +- 🅑 **Diff primitive** (§5.3) — then capability diff (#1034) +- 🅑 **Command palette and global search** (§5.4); **Connection Doctor** (§5.8) +- 🅐 **Cache hint display and checks** (§3.2) — SEP-2549 is Final +- 🅐 **OAuth Client Credentials extension** (§3.3, §4) +- 🅐 **`content` / `structuredContent` consistency check** and **destructive-call confirmation** (§3.4) +- 🅐 **Extension-watch sweep** (§4) -### Phase 3 — Automation and spec catch-up (~`v2.14` – `v2.20`, Nov 2026 – Jan 2027) +### Phase 3 — Automation (~`v2.16` – `v2.21`, Nov 2026 – Jan 2027) -_Turn the Inspector into something you can run in CI, and absorb the SEPs that have landed._ +_Turn the Inspector into something you can run in CI._ -- 🅑 **Saved calls / collections** (§4.5) → **assertions and CI flows** (§4.6) -- 🅐 **Conformance runner** (§3.11) — shares the assertion engine -- 🅐 **File uploads** (§3.8) — assumes the TS SDK reference impl has shipped -- 🅐 **Server Card preview + card-vs-reality diff** (§3.2) — assumes SEP-2127 has settled -- 🅐 **Skills view** (§3.9) — assumes SEP-2640 accepted -- 🅑 Performance at scale (§4.11); accessibility pass (§4.12) +- 🅑 **Saved calls / collections** (§5.5) → **assertions and CI flows** (§5.6) +- 🅐 **Conformance runner** (§3.6) — shares the assertion engine, if the maintainers agree an interface +- 🅑 **OTLP export** (§5.7); **registry browsing** (§5.9) +- 🅑 **Grouping and performance at scale** (§5.10); accessibility pass (§5.12) +- 🅐 **State handle view** (§3.2); **extension declaration view** (§3.5) -### Phase 4 — Frontier (~`v2.21` – `v2.27`, Jan–Feb 2027) +### Phase 4 — Frontier (~`v2.22` – `v2.27`, Jan–Feb 2027) _The items whose shape we cannot yet commit to, plus the multiplier._ -- 🅐 **Interceptor test bench** (§3.7) — and a decision on owning the WG's CLI deliverable -- 🅐 **Triggers/events receiver** (§3.5) — design throughout, build only if the SEP lands -- 🅐 **Transport/session work** (§3.1) — proxy harness, stateless verification, third era -- 🅐 **ID-JAG / Cross-App Access flow** (§3.4) -- 🅑 **Plugin architecture** (§4.14) — designed against surfaces that now exist -- 🅑 Workspace and layout (§4.10); onboarding (§4.13) +- 🅐 **DPoP**, **token exchange**, **Workload Identity Federation** (§3.3) — as each reaches Final or a Tier-1 SDK impl +- 🅐 **Server-initiated events receiver** (§3.1) — design throughout, build only if the SEP lands +- 🅐 **ETags** (§3.2); **extension contract validation** (§3.5) +- 🅑 **Plugin architecture** (§5.14) — designed against surfaces that now exist +- 🅑 Workspace and layout (§5.11); onboarding (§5.13) ### Standing commitments across all phases -- **Weekly milestone cadence** and the pre-push gate (`npm run local:gate`, renamed off `ci` in #2146) are unchanged. +- **Weekly milestone cadence** and the pre-push gate (`npm run local:gate`) are unchanged. - **Bug and triage capacity is reserved, not scheduled.** The board's Incoming queue keeps flowing regardless of phase. -- **WG liaison**: attend Transports, Agents, Triggers, Interceptors, and Server Card sessions - and feed implementation experience back. Several items above are as much _inputs to_ the - spec as outputs of it. +- **Re-read the MCP roadmap when it changes.** It carries a "Last updated" date; a change there + is the trigger to revisit §3 and §6, the way #2400 revisited this draft. +- **WG liaison**: attend Triggers & Events, Transports, Agents, Agent Identity, Core Primitives, + and SDK sessions and feed implementation experience back. Several items above are as much + _inputs to_ the spec as outputs of it. --- -## 6. What we are deliberately not doing +## 7. What we are deliberately not doing Stating these so they are decisions rather than oversights. @@ -531,40 +555,47 @@ Stating these so they are decisions rather than oversights. the diff, or the session format, it does. A new top-level tab needs justification. - **Not chasing pre-Draft SEPs.** 🔴 items get a tracking issue and a WG liaison, not code. We were burned by this in v1. +- **Not scheduling build work outside the published priority areas** (§3.7). A WG effort that + the roadmap does not list gets a liaison, not milestones. - **Not publishing `core/` as a package this cycle.** [#1636](https://github.com/modelcontextprotocol/inspector/issues/1636) stays deferred; it adds an API compatibility obligation we cannot yet afford. -- **Not adding transports beyond what the spec blesses**, per the roadmap — but §3.1 makes - _custom_ transports loadable so the community can experiment. -- **Not building a second extension mechanism.** If we host interceptors, they run on the - plugin architecture (§4.14). +- **Not adding transports beyond what the spec blesses.** Custom transports were closed as not + planned ([#1741](https://github.com/modelcontextprotocol/inspector/issues/1741)). +- **Not investing in audience/priority annotation rendering** while their deprecation is under + review (§3.4). +- **Not building a second extension mechanism.** Anything pluggable runs on the plugin + architecture (§5.14). --- -## 7. Open questions - -For WG discussion before this plan is adopted. - -1. **Does the private roadmap doc change §3?** This plan is built from the public roadmap; the - private doc may carry timelines or themes it omits. -2. **Do we claim the Interceptors WG's "CLI client for interceptor invocation and testing"?** - It is Ideating and unowned, it describes our CLI, and we have a co-lead in common. If yes, - it needs milestone allocation in Phase 3, not Phase 4. -3. **How far do we take the conformance role?** §3.11 and §4.6 point at "the Inspector tells - you whether your server is correct." That is a real expansion of mission — worth an - explicit yes or no, and possibly a charter amendment. -4. **Who owns the triggers/events reachability problem?** A publicly reachable callback - endpoint on a localhost dev tool is a security question as much as a UX one, and it needs - an owner before Phase 4. +## 8. Open questions + +For WG discussion. + +1. **Do we claim the Interceptors WG's "CLI client for interceptor invocation and testing"?** + It is unowned and describes our CLI, but Interceptors is no longer on the published roadmap + (§3.7). If yes, it needs its own allocation rather than borrowed Phase 4 capacity. +2. **How far do we take the conformance role?** §3.6 and §5.6 point at "the Inspector tells + you whether your server is correct." With conformance now central to the SDK area (§3.5), + that is worth an explicit yes or no, and possibly a charter amendment. +3. **Who owns the server-initiated events reachability problem?** A publicly reachable + callback endpoint on a localhost dev tool is a security question as much as a UX one, and + it needs an owner before Phase 4. +4. **Should the Inspector feed the composition review directly?** The in-flight work lane + (§3.1) produces exactly the evidence the review needs; decide whether we bring it to the + Agents / Triggers & Events WGs as a demo. 5. **Is the ~50/50 capacity split right?** It is an assertion in this draft, not a measurement. -6. **Timeline v1 scope.** The §4.1 sketch is deliberately broad. Which parts are v1 and which - are follow-ups should be settled before Phase 1 starts. +6. **Timeline v1 scope.** The §5.1 sketch is deliberately broad. Which parts are v1 and which + are follow-ups should be settled before it starts. --- -## 8. Sources +## 9. Sources -- [MCP Roadmap](https://modelcontextprotocol.io/development/roadmap) (last updated 2026-03-05) -- WG charters: [Inspector V2](https://modelcontextprotocol.io/community/working-groups/inspector-v2) · [Server Card](https://modelcontextprotocol.io/community/working-groups/server-card) · [Triggers & Events](https://modelcontextprotocol.io/community/working-groups/triggers-events) · [Agents](https://modelcontextprotocol.io/community/working-groups/agents) · [Interceptors](https://modelcontextprotocol.io/community/working-groups/interceptors) · [File Uploads](https://modelcontextprotocol.io/community/working-groups/file-uploads) · [Skills Over MCP](https://modelcontextprotocol.io/community/working-groups/skills-over-mcp) -- IG charters: [Primitive Grouping](https://modelcontextprotocol.io/community/interest-groups/primitive-grouping) · [Tool Annotations](https://modelcontextprotocol.io/community/interest-groups/tool-annotations) · [Enterprise-Managed Authorization](https://modelcontextprotocol.io/community/interest-groups/enterprise-managed-authorization) +- [MCP Roadmap](https://modelcontextprotocol.io/development/roadmap) (last updated 2026-08-22) +- [Extensions overview](https://modelcontextprotocol.io/extensions/overview) · [Extension support matrix](https://modelcontextprotocol.io/extensions/client-matrix) · [SEP-2133: Extensions](https://modelcontextprotocol.io/seps/2133-extensions) +- Final SEPs cited: [SEP-2549 (TTL for list results)](https://modelcontextprotocol.io/seps/2549-TTL-for-list-results) · [SEP-2567 (sessionless)](https://modelcontextprotocol.io/seps/2567-sessionless-mcp) · [SEP-2575 (stateless)](https://modelcontextprotocol.io/seps/2575-stateless-mcp) · [SEP-2663 (Tasks extension)](https://modelcontextprotocol.io/seps/2663-tasks-extension) · [SEP-2640 (Skills extension)](https://modelcontextprotocol.io/seps/2640-skills-extension) · [SEP-2484 (conformance tests)](https://modelcontextprotocol.io/seps/2484-conformance-tests-required-for-final-seps) +- WG charters: [Inspector V2](https://modelcontextprotocol.io/community/working-groups/inspector-v2) · [Triggers & Events](https://modelcontextprotocol.io/community/working-groups/triggers-events) · [Agents](https://modelcontextprotocol.io/community/working-groups/agents) · [File Uploads](https://modelcontextprotocol.io/community/working-groups/file-uploads) · [SDK](https://modelcontextprotocol.io/community/working-groups/sdk) +- [SDK tiers and conformance testing](https://modelcontextprotocol.io/community/sdk-tiers) - Internal: [`specification/v2_new_spec_impact.md`](../specification/v2_new_spec_impact.md) · [`specification/v2_scope.md`](../specification/v2_scope.md) · [`specification/v2_ux_features.md`](../specification/v2_ux_features.md) - [Inspector V2 project board (#28)](https://github.com/orgs/modelcontextprotocol/projects/28) From c0bef16f6db033613a4e8a0ecc34f421b09f6fa9 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Wed, 16 Sep 2026 18:55:55 -0400 Subject: [PATCH 02/17] docs: link the unblocked-work artifact at the top of the roadmap (#2400) Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index e7b2803840..a95370696c 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -8,6 +8,10 @@ **Owner:** [Inspector V2 WG](https://modelcontextprotocol.io/community/working-groups/inspector-v2) **Status:** Draft for WG review — **revised 2026-09-16** against the published MCP roadmap of 2026-08-22 (#2400) +## Work we can start now, no external blockers + +[Inspector Unblocked Work](https://claude.ai/artifact/MTFGsTVbKCqMchA1JYHo83) lists the roadmap items that depend on nothing outside this repo. + --- ## Table of Contents From 298cce3d587818ef520ba7285bc4e0463e60569d Mon Sep 17 00:00:00 2001 From: cliffhall Date: Wed, 16 Sep 2026 19:17:55 -0400 Subject: [PATCH 03/17] docs: address Copilot review on the roadmap realignment (#2401 review) Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 154 +++++++++++++++--------------- 1 file changed, 78 insertions(+), 76 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index a95370696c..96d46552c9 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -80,17 +80,17 @@ work is non-negotiable but bounded, and the remaining capacity is ours to direct Worth recording, because much of the first draft's "build now" list is done and should not be re-planned: -| Item | Issue(s) | -| ----------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `Last-Event-ID` resumption | [#920](https://github.com/modelcontextprotocol/inspector/issues/920) | -| `server.json` support | [#922](https://github.com/modelcontextprotocol/inspector/issues/922) | -| Discover checkmarks for task extensions | [#1887](https://github.com/modelcontextprotocol/inspector/issues/1887) | -| Strict JSON Schema validation | [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015) | -| The argument editor workstream (all six issues) | [#1853](https://github.com/modelcontextprotocol/inspector/issues/1853), [#1856](https://github.com/modelcontextprotocol/inspector/issues/1856), [#1885](https://github.com/modelcontextprotocol/inspector/issues/1885), [#1928](https://github.com/modelcontextprotocol/inspector/issues/1928), [#1919](https://github.com/modelcontextprotocol/inspector/issues/1919), [#1910](https://github.com/modelcontextprotocol/inspector/issues/1910) | -| Connection fixes (version-negotiation DX, `https://localhost`, dev containers, ghost entry) | [#962](https://github.com/modelcontextprotocol/inspector/issues/962), [#1936](https://github.com/modelcontextprotocol/inspector/issues/1936), [#1951](https://github.com/modelcontextprotocol/inspector/issues/1951), [#1914](https://github.com/modelcontextprotocol/inspector/issues/1914) | -| Server config: paste-JSON, custom headers, auth URL overrides, file-backed secrets | [#904](https://github.com/modelcontextprotocol/inspector/issues/904), [#1915](https://github.com/modelcontextprotocol/inspector/issues/1915), [#1906](https://github.com/modelcontextprotocol/inspector/issues/1906), [#1950](https://github.com/modelcontextprotocol/inspector/issues/1950) | -| Enterprise-Managed Authorization; IdP OIDC option | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509), [#1937](https://github.com/modelcontextprotocol/inspector/issues/1937) | -| Skills over MCP (SEP-2640) across web, CLI and TUI | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248) | +| Item | Issue(s) | +| ------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `Last-Event-ID` resumption | [#920](https://github.com/modelcontextprotocol/inspector/issues/920) | +| `server.json` support | [#922](https://github.com/modelcontextprotocol/inspector/issues/922) | +| Discover checkmarks for task extensions | [#1887](https://github.com/modelcontextprotocol/inspector/issues/1887) | +| Strict JSON Schema validation | [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015) | +| The argument editor workstream (all six issues) | [#1853](https://github.com/modelcontextprotocol/inspector/issues/1853), [#1856](https://github.com/modelcontextprotocol/inspector/issues/1856), [#1885](https://github.com/modelcontextprotocol/inspector/issues/1885), [#1928](https://github.com/modelcontextprotocol/inspector/issues/1928), [#1919](https://github.com/modelcontextprotocol/inspector/issues/1919), [#1910](https://github.com/modelcontextprotocol/inspector/issues/1910) | +| Connection fixes (version-negotiation DX, `https://localhost`, dev containers, ghost entry) | [#962](https://github.com/modelcontextprotocol/inspector/issues/962), [#1936](https://github.com/modelcontextprotocol/inspector/issues/1936), [#1951](https://github.com/modelcontextprotocol/inspector/issues/1951), [#1914](https://github.com/modelcontextprotocol/inspector/issues/1914) | +| Server config: paste-JSON, custom headers, auth URL overrides, file-backed secrets | [#904](https://github.com/modelcontextprotocol/inspector/issues/904), [#1915](https://github.com/modelcontextprotocol/inspector/issues/1915), [#1906](https://github.com/modelcontextprotocol/inspector/issues/1906), [#1950](https://github.com/modelcontextprotocol/inspector/issues/1950) | +| Enterprise-Managed Authorization; IdP OIDC option | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509), [#1937](https://github.com/modelcontextprotocol/inspector/issues/1937) | +| Skills over MCP (SEP-2640) across web, CLI and TUI | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248) | Closed as **not planned**, so not carried forward: custom transports ([#1741](https://github.com/modelcontextprotocol/inspector/issues/1741)), the configurable-proxy base ([#1684](https://github.com/modelcontextprotocol/inspector/issues/1684)), the readiness summary ([#1916](https://github.com/modelcontextprotocol/inspector/issues/1916)), full panel collapse ([#928](https://github.com/modelcontextprotocol/inspector/issues/928)), `*.localhost` domains ([#1944](https://github.com/modelcontextprotocol/inspector/issues/1944)), and the trusted-local-host OAuth HTTP exception ([#1911](https://github.com/modelcontextprotocol/inspector/issues/1911)). @@ -98,13 +98,13 @@ Closed as **not planned**, so not carried forward: custom transports ([#1741](ht ## 2. The two tracks -| | **Track A — Spec-following** | **Track B — Experience** | -| --------------------------- | -------------------------------------------------------------------- | ------------------------------------------- | -| **Driver** | MCP roadmap, WG deliverables, SEP acceptance, approved extensions | Our own judgment about the tool | -| **Trigger to start** | A SEP reaches Draft with a Tier-1 SDK reference impl, or is Final | Whenever we have capacity | -| **Risk** | Slips when upstream slips; we cannot control the date | We control the date entirely | -| **Failure mode if starved** | Inspector stops being the reference test client | Inspector stays a protocol dump, not a tool | -| **Target capacity** | ~50% | ~50% | +| | **Track A — Spec-following** | **Track B — Experience** | +| --------------------------- | ----------------------------------------------------------------- | ------------------------------------------- | +| **Driver** | MCP roadmap, WG deliverables, SEP acceptance, approved extensions | Our own judgment about the tool | +| **Trigger to start** | A SEP reaches Draft with a Tier-1 SDK reference impl, or is Final | Whenever we have capacity | +| **Risk** | Slips when upstream slips; we cannot control the date | We control the date entirely | +| **Failure mode if starved** | Inspector stops being the reference test client | Inspector stays a protocol dump, not a tool | +| **Target capacity** | ~50% | ~50% | The two tracks are not independent. Several Track B items — the timeline, session record/replay, diff — are **force multipliers for Track A**: each new protocol feature @@ -136,6 +136,7 @@ the upstream area, our read on what it means for the Inspector, and a concrete f - 🟢 **Build now** — the shape is known (the SEP is Final, or the work is ours alone); blocked only on our own capacity. - 🟡 **Design now, build on signal** — enough detail to design against; wait for a Draft SEP or a Tier-1 SDK impl before building. - 🔴 **Watch** — too early to predict a UI; keep a tracking issue and a WG liaison. +- ✅ **Shipped** — already in the Inspector; listed for completeness, not scheduled. ### 3.1 Agentic messaging primitives @@ -158,15 +159,15 @@ Inspector surface assumes we initiated the connection; a webhook makes us a **se must be publicly reachable, which a tool usually run on `localhost` is not. Start the design conversation now and bring it to the WG as implementation feedback. -| Feature | Confidence | Notes | -| ----------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | -| **In-flight work lane** — tasks, open `subscriptions/listen` streams and progress-reporting requests as spans on one timeline lane (§5.1) | 🟢 | All three already exist in the 2026-07-28 spec. Makes composition gaps (mismatched cancellation, divergent errors) visible, which the WG can use. | -| **Cancellation and error comparison** — show how each in-flight kind ended (completed, cancelled, errored, server-closed) with the same vocabulary | 🟢 | A small, direct contribution to the composition review. | -| **Callback receiver** — backend-hosted endpoint registered as a push target | 🔴 | Design now, build when the SEP lands. Security review mandatory: an inbound public endpoint on a process that spawns subprocesses. | -| **Local reachability story** — tunnel integration or documented guidance | 🔴 | Likely the hardest UX problem of the six months. | -| **Delivery log with ordering and duplicate assertions** | 🔴 | The conformance value: did events arrive in order? were any redelivered? | -| **`Mcp-Name` header on Tasks over Streamable HTTP** | 🟡 | [#1917](https://github.com/modelcontextprotocol/inspector/issues/1917) — blocked upstream. | -| **Tasks extension → core migration** | 🔴 | Moved to "Beyond" upstream. Keep the era-conditional exposure; the legacy `capabilities.tasks` path must keep working. | +| Feature | Confidence | Notes | +| -------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | +| **In-flight work lane** — tasks, open `subscriptions/listen` streams and progress-reporting requests as spans on one timeline lane (§5.1) | 🟢 | All three already exist in the 2026-07-28 spec. Makes composition gaps (mismatched cancellation, divergent errors) visible, which the WG can use. | +| **Cancellation and error comparison** — show how each in-flight kind ended (completed, cancelled, errored, server-closed) with the same vocabulary | 🟢 | A small, direct contribution to the composition review. | +| **Callback receiver** — backend-hosted endpoint registered as a push target | 🔴 | Design now, build when the SEP lands. Security review mandatory: an inbound public endpoint on a process that spawns subprocesses. | +| **Local reachability story** — tunnel integration or documented guidance | 🔴 | Likely the hardest UX problem of the six months. | +| **Delivery log with ordering and duplicate assertions** | 🔴 | The conformance value: did events arrive in order? were any redelivered? | +| **`Mcp-Name` header on Tasks over Streamable HTTP** | 🟡 | [#1917](https://github.com/modelcontextprotocol/inspector/issues/1917) — blocked upstream. | +| **Tasks extension → core migration** | 🔴 | Moved to "Beyond" upstream. Keep the era-conditional exposure; the legacy `capabilities.tasks` path must keep working. | ### 3.2 HTTP-native transport unification and hardening @@ -188,14 +189,14 @@ cache hints is exactly how a server author finds out theirs are wrong. HTTP over stdio would change how every stdio server connects, and our transport layer is where the Inspector is thinnest over the SDK. Watch closely. -| Feature | Confidence | Notes | -| --------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | ----------------------------------------------------------------------------------------------------------------------- | -| **Cache hint display** — `ttlMs` / `cacheScope` on every list and resource read, with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. Today the fields appear only in our tests. | -| **Cache behavior checks** — flag a re-fetch the hints said was unnecessary, and a list that changed inside its declared TTL | 🟢 | Inspector-shaped: nobody else observes both the hint and the reality. | -| **State handle view** — surface SEP-2567 state handles as first-class values, not opaque fields | 🟢 | Replaces the first draft's "session lifecycle lane". | -| **ETag support** — send `If-None-Match`, show 304s and version changes | 🟡 | Build when the SEP reaches Draft with an SDK impl. | -| **HTTP over stdio** | 🔴 | Watch. If it lands, the Network screen becomes meaningful for stdio servers too — a large win. | -| **Standardized error rendering** | 🔴 | "Beyond". Our Protocol-vs-Network error split (#1628) is the seam to adopt it into. | +| Feature | Confidence | Notes | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| **Cache hint display** — `ttlMs` / `cacheScope` on every list and resource read, with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. The runtime already parses the hints and honors them through the SDK list cache; the gap is showing them. | +| **Cache behavior observations** — note a re-fetch of a still-fresh result, and a list that changed inside its declared TTL, as diagnostics rather than errors | 🟢 | Inspector-shaped: nobody else observes both the hint and the reality. `ttlMs` is a freshness hint, so both are compliant. | +| **Stateful-tool workflow investigation** — how to help a user carry an SEP-2567-style handle from one tool result into the next call | 🟡 | Replaces the first draft's "session lifecycle lane". The protocol has no concept of a handle (it is ordinary tool data), so a generic view would be inference; investigate before designing. | +| **ETag support** — send `If-None-Match`, show 304s and version changes | 🟡 | Build when the SEP reaches Draft with an SDK impl. | +| **HTTP over stdio** | 🔴 | Watch. If it lands, the Network screen becomes meaningful for stdio servers too — a large win. | +| **Standardized error rendering** | 🔴 | "Beyond". Our Protocol-vs-Network error split (#1628) is the seam to adopt it into. | ### 3.3 Agent identity and enterprise-ready security @@ -212,13 +213,13 @@ client for the whole identity chain. The first draft's audit trails, gateway mod configuration portability are **no longer on the MCP roadmap**; OTLP export and the audit transcript are still worth building, but as our own Track B work (§5.7), not as spec-following. -| Feature | Confidence | Notes | -| --------------------------------------------------------------------------------------------------------- | ---------- | ----------------------------------------------------------------------------------------------- | -| **OAuth Client Credentials extension** — client-secret and JWT-bearer assertion flows | 🟢 | An **approved** official extension (§4) we do not support. No upstream dependency. | -| **Token exchange (RFC 8693) test flow** | 🟡 | Named in the roadmap; the RFC is stable, the MCP profile of it is not. | -| **DPoP** — generate a proof key, send `DPoP` proofs, show proof/nonce exchange in the Network view | 🟡 | Design against SEP-1932; build when it is Final or has a Tier-1 SDK impl. | -| **Workload Identity Federation** | 🟡 | SEP-1933. Needs a way to present a workload credential from a developer machine — design first. | -| **Human-presence attestation** | 🔴 | "Beyond". | +| Feature | Confidence | Notes | +| -------------------------------------------------------------------------------------------------- | ---------- | ----------------------------------------------------------------------------------------------- | +| **OAuth Client Credentials extension** — client-secret and JWT-bearer assertion flows | 🟢 | An **approved** official extension (§4) we do not support. No upstream dependency. | +| **Token exchange (RFC 8693) test flow** | 🟡 | Named in the roadmap; the RFC is stable, the MCP profile of it is not. | +| **DPoP** — generate a proof key, send `DPoP` proofs, show proof/nonce exchange in the Network view | 🟡 | Design against SEP-1932; build when it is Final or has a Tier-1 SDK impl. | +| **Workload Identity Federation** | 🟡 | SEP-1933. Needs a way to present a workload credential from a developer machine — design first. | +| **Human-presence attestation** | 🔴 | "Beyond". | ### 3.4 Improved primitives @@ -239,14 +240,14 @@ and §3.8 (the SEP-2356 file picker) are **not on the published roadmap** and mo What we _can_ do now is show the problem the redesign is solving: a server returning `content` and `structuredContent` that disagree is a real bug today. -| Feature | Confidence | Notes | -| ------------------------------------------------------------------------------------------------------------------------ | ---------- | ------------------------------------------------------------------------------------------------------------------------ | -| **`content` / `structuredContent` consistency check** — flag results where the two disagree or one is missing | 🟢 | Useful today, and implementation evidence for the Core Primitives WG. | -| **New tool result shape** | 🔴 | WG still forming. Keep both renderings behind the era seam when it lands. | -| **Progressive discovery** | 🔴 | Design the lists (§5.10) so "not loaded yet" is a state, not an empty list. | -| **Annotation-driven confirmation** before a `destructiveHint` call | 🟢 | Tool annotations are not the audience/priority content annotations under review. Small and obviously correct. | -| **Richer audience / priority annotation rendering** | 🔴 | Paused: may be deprecated. | -| **Range reads and hierarchical resource listing** | 🟡 | We already render `resources/directory/read` for Skills (#2248); generalize it when the File Uploads WG publishes a SEP. | +| Feature | Confidence | Notes | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------ | +| **`content` / `structuredContent` consistency check** — flag results where both are present and disagree, or where a declared `outputSchema` requires `structuredContent` and it is missing | 🟢 | Useful today, and implementation evidence for the Core Primitives WG. | +| **New tool result shape** | 🔴 | WG still forming. Keep both renderings behind the era seam when it lands. | +| **Progressive discovery** | 🔴 | Design the lists (§5.10) so "not loaded yet" is a state, not an empty list. | +| **Annotation-driven confirmation** before a `destructiveHint` call | 🟢 | Tool annotations are not the audience/priority content annotations under review. Small and obviously correct. | +| **Richer audience / priority annotation rendering** | 🔴 | Paused: may be deprecated. | +| **Range reads and hierarchical resource listing** | 🟡 | We already render `resources/directory/read` for Skills (#2248); generalize it when the File Uploads WG publishes a SEP. | ### 3.5 Improved SDK developer experience @@ -261,11 +262,11 @@ lists advertised extension ids, and a contract that names roles and versions giv something to validate declarations against. The generated-artifacts experiment makes the conformance suite central, which strengthens §3.6. -| Feature | Confidence | Notes | -| ------------------------------------------------------------------------------------------------------------------------------- | ---------- | ---------------------------------------------------------------------------------------- | +| Feature | Confidence | Notes | +| ------------------------------------------------------------------------------------------------------------------------------ | ---------- | ----------------------------------------------------------------------------------------------- | | **Extension declaration view** — for each advertised extension: identifier, settings object, whether the Inspector supports it | 🟢 | Buildable on today's negotiation (#1738); extend with role and version once the contract lands. | -| **Extension contract validation** | 🟡 | Validate a server's declaration against the contract once published. | -| **Run generated quickstart servers as fixtures** | 🔴 | If the experiment publishes them, they are free test servers. | +| **Extension contract validation** | 🟡 | Validate a server's declaration against the contract once published. | +| **Run generated quickstart servers as fixtures** | 🔴 | If the experiment publishes them, they are free test servers. | ### 3.6 Conformance and validation @@ -280,10 +281,10 @@ already have a CLI that exits non-zero. The runner itself needs agreement with t maintainers on a programmatic interface; the **assertion engine** it would share with §5.6 does not. -| Feature | Confidence | Notes | -| ------------------------------------------------------------------------------------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------------------------- | -| **Conformance runner** — run the suite against a connected server, render pass/fail per assertion | 🟡 | **Action: open a conversation with the conformance maintainers.** Build the shared assertion engine (§5.6) first. | -| **`mcp-inspector --conformance` for CI** | 🟡 | Same engine, CLI report, exit code. | +| Feature | Confidence | Notes | +| ------------------------------------------------------------------------------------------------- | ---------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- | +| **Conformance runner** — run the suite against a connected server, render pass/fail per assertion | 🟡 | **Action: open a conversation with the conformance maintainers.** Build the shared assertion engine (§5.6) first. | +| **`mcp-inspector --conformance` for CI** | 🟡 | Same engine, CLI report, exit code. | | **Strict schema validation with actionable errors** | ✅ | Shipped — [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015). | ### 3.7 Off the published roadmap — watch only @@ -293,14 +294,14 @@ list. They are not cancelled upstream — WGs keep working outside the priority roadmap says SEPs outside those areas "expect a longer queue", so **we do not schedule build work for them this horizon**. Each keeps a tracking issue and a liaison. -| Effort | First-draft plan | Now | -| ---------------------------------------------------------------------------------------- | ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| **Server Cards** (SEP-2127) | Card preview, card-vs-reality diff, `--card-lint` in Phase 3 | 🔴 Watch. [#1857](https://github.com/modelcontextprotocol/inspector/issues/1857)'s **registry** half does not depend on it (§5.9). | -| **Interceptors** (SEP-1763) | Test bench, audit mode, CLI invocation in Phase 4 | 🔴 Watch. The WG's unowned "CLI client for interceptor invocation" is still worth raising (§8). | -| **Primitive grouping** (IG) | Grouped sidebars | The **UX** half proceeds as Track B (§5.10) on client-side heuristics; no spec data source is expected this horizon. | -| **Streamed and reference results** | Incremental rendering, reference handles | 🔴 Watch. Payload truncation in §5.10 covers the large-result case today. | -| **File picker from `FileInputDescriptor`** (SEP-2356) | `SchemaForm` + elicitation picker | 🔴 Watch. The File Uploads WG's published direction is now filesystem-like resources (§3.4). | -| **Gateways, audit trails, configuration portability** | Gateway mode; OTLP as spec work | Gateway mode dropped. OTLP and the audit transcript continue as Track B (§5.7). | +| Effort | First-draft plan | Now | +| ----------------------------------------------------- | ------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------- | +| **Server Cards** (SEP-2127) | Card preview, card-vs-reality diff, `--card-lint` in Phase 3 | 🔴 Watch. [#1857](https://github.com/modelcontextprotocol/inspector/issues/1857)'s **registry** half does not depend on it (§5.9). | +| **Interceptors** (SEP-1763) | Test bench, audit mode, CLI invocation in Phase 4 | 🔴 Watch. The WG's unowned "CLI client for interceptor invocation" is still worth raising (§8). | +| **Primitive grouping** (IG) | Grouped sidebars | The **UX** half proceeds as Track B (§5.10) on client-side heuristics; no spec data source is expected this horizon. | +| **Streamed and reference results** | Incremental rendering, reference handles | 🔴 Watch. Payload truncation in §5.10 covers the large-result case today. | +| **File picker from `FileInputDescriptor`** (SEP-2356) | `SchemaForm` + elicitation picker | 🔴 Watch. The File Uploads WG's published direction is now filesystem-like resources (§3.4). | +| **Gateways, audit trails, configuration portability** | Gateway mode; OTLP as spec work | Gateway mode dropped. OTLP and the audit transcript continue as Track B (§5.7). | --- @@ -317,13 +318,13 @@ official status through the Extensions Track of ### Current support (as of 2026-09-16) -| Extension | Identifier | Web | CLI | TUI | Upstream matrix | Notes | -| -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ------------------------ | ------------------------------------------------------------------------------------------------------- | -| MCP Apps | `io.modelcontextprotocol/ui` | ✅ | — | — | ❌ not listed | Apps tab. Rendering an app needs a browser, so CLI/TUI absence is by design. | -| Tasks | `io.modelcontextprotocol/tasks` | ✅ | ✅ | ❌ | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). No TUI Tasks pane yet. | -| Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | -| Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | ✅ | ✅ | ❌ not listed | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). | -| OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | ❌ | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | +| Extension | Identifier | Web | CLI | TUI | Upstream matrix | Notes | +| -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| MCP Apps | `io.modelcontextprotocol/ui` | ✅ | 🟡 | — | ❌ not listed | Apps tab. Columns are rendering support: rendering needs a browser, so the CLI has only the `--app-info` metadata probe and the TUI nothing. The shared client still advertises the extension from CLI and TUI. | +| Tasks | `io.modelcontextprotocol/tasks` | ✅ | ❌ | ❌ | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). The CLI's one-shot mode rejects `tasks/*`; no TUI Tasks pane yet. | +| Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | +| Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | ✅ | ✅ | ❌ not listed | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). | +| OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | ❌ | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | **Actions:** implement OAuth Client Credentials; and, with maintainer sign-off, open a PR on `modelcontextprotocol/modelcontextprotocol` to correct the Inspector's row in the client matrix. @@ -513,7 +514,7 @@ items that need no upstream work._ - 🅑 **Session record / replay / share** (§5.2) — format shared with the audit transcript - 🅑 **Diff primitive** (§5.3) — then capability diff (#1034) - 🅑 **Command palette and global search** (§5.4); **Connection Doctor** (§5.8) -- 🅐 **Cache hint display and checks** (§3.2) — SEP-2549 is Final +- 🅐 **Cache hint display and observations** (§3.2) — SEP-2549 is Final - 🅐 **OAuth Client Credentials extension** (§3.3, §4) - 🅐 **`content` / `structuredContent` consistency check** and **destructive-call confirmation** (§3.4) - 🅐 **Extension-watch sweep** (§4) @@ -526,7 +527,7 @@ _Turn the Inspector into something you can run in CI._ - 🅐 **Conformance runner** (§3.6) — shares the assertion engine, if the maintainers agree an interface - 🅑 **OTLP export** (§5.7); **registry browsing** (§5.9) - 🅑 **Grouping and performance at scale** (§5.10); accessibility pass (§5.12) -- 🅐 **State handle view** (§3.2); **extension declaration view** (§3.5) +- 🅐 **Stateful-tool workflow investigation** (§3.2); **extension declaration view** (§3.5) ### Phase 4 — Frontier (~`v2.22` – `v2.27`, Jan–Feb 2027) @@ -560,7 +561,8 @@ Stating these so they are decisions rather than oversights. - **Not chasing pre-Draft SEPs.** 🔴 items get a tracking issue and a WG liaison, not code. We were burned by this in v1. - **Not scheduling build work outside the published priority areas** (§3.7). A WG effort that - the roadmap does not list gets a liaison, not milestones. + the roadmap does not list gets a liaison, not milestones. Approved official extensions (§4) + are exempt: they count as spec-following work even though the roadmap does not list them. - **Not publishing `core/` as a package this cycle.** [#1636](https://github.com/modelcontextprotocol/inspector/issues/1636) stays deferred; it adds an API compatibility obligation we cannot yet afford. - **Not adding transports beyond what the spec blesses.** Custom transports were closed as not From 3961bd17cc8a892f65799041d78494326b3153ae Mon Sep 17 00:00:00 2001 From: cliffhall Date: Wed, 16 Sep 2026 19:47:24 -0400 Subject: [PATCH 04/17] docs: address Copilot round 2 on the roadmap realignment (#2401 review) Admit approved official extensions in the Track A trigger, drop the already-shipped missing-structuredContent case from the consistency check, describe the upstream matrix's Inspector cells as blank rather than unlisted, and file extension-watch issues with the current milestone as sdk-watch does. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 96d46552c9..299e70536c 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -101,7 +101,7 @@ Closed as **not planned**, so not carried forward: custom transports ([#1741](ht | | **Track A — Spec-following** | **Track B — Experience** | | --------------------------- | ----------------------------------------------------------------- | ------------------------------------------- | | **Driver** | MCP roadmap, WG deliverables, SEP acceptance, approved extensions | Our own judgment about the tool | -| **Trigger to start** | A SEP reaches Draft with a Tier-1 SDK reference impl, or is Final | Whenever we have capacity | +| **Trigger to start** | A SEP reaches Draft with a Tier-1 SDK reference impl, or is Final; or an extension is approved as official (§4) | Whenever we have capacity | | **Risk** | Slips when upstream slips; we cannot control the date | We control the date entirely | | **Failure mode if starved** | Inspector stops being the reference test client | Inspector stays a protocol dump, not a tool | | **Target capacity** | ~50% | ~50% | @@ -242,7 +242,7 @@ What we _can_ do now is show the problem the redesign is solving: a server retur | Feature | Confidence | Notes | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------ | -| **`content` / `structuredContent` consistency check** — flag results where both are present and disagree, or where a declared `outputSchema` requires `structuredContent` and it is missing | 🟢 | Useful today, and implementation evidence for the Core Primitives WG. | +| **`content` / `structuredContent` consistency check** — flag results where both are present and disagree | 🟢 | Useful today, and implementation evidence for the Core Primitives WG. A missing `structuredContent` under a declared `outputSchema` is already flagged by `validateToolOutput` (shipped). | | **New tool result shape** | 🔴 | WG still forming. Keep both renderings behind the era seam when it lands. | | **Progressive discovery** | 🔴 | Design the lists (§5.10) so "not loaded yet" is a state, not an empty list. | | **Annotation-driven confirmation** before a `destructiveHint` call | 🟢 | Tool annotations are not the audience/priority content annotations under review. Small and obviously correct. | @@ -320,14 +320,14 @@ official status through the Extensions Track of | Extension | Identifier | Web | CLI | TUI | Upstream matrix | Notes | | -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| MCP Apps | `io.modelcontextprotocol/ui` | ✅ | 🟡 | — | ❌ not listed | Apps tab. Columns are rendering support: rendering needs a browser, so the CLI has only the `--app-info` metadata probe and the TUI nothing. The shared client still advertises the extension from CLI and TUI. | +| MCP Apps | `io.modelcontextprotocol/ui` | ✅ | 🟡 | — | Inspector row, cell blank | Apps tab. Columns are rendering support: rendering needs a browser, so the CLI has only the `--app-info` metadata probe and the TUI nothing. The shared client still advertises the extension from CLI and TUI. | | Tasks | `io.modelcontextprotocol/tasks` | ✅ | ❌ | ❌ | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). The CLI's one-shot mode rejects `tasks/*`; no TUI Tasks pane yet. | | Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | -| Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | ✅ | ✅ | ❌ not listed | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). | +| Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | ✅ | ✅ | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). | | OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | ❌ | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | **Actions:** implement OAuth Client Credentials; and, with maintainer sign-off, open a PR on -`modelcontextprotocol/modelcontextprotocol` to correct the Inspector's row in the client matrix. +`modelcontextprotocol/modelcontextprotocol` to fill in the Inspector row's blank Apps and Enterprise Auth cells and update its Skills cell in the client matrix. ### Keeping up as extensions are approved @@ -339,7 +339,7 @@ mechanism, the way SDK releases already are: `/extensions/overview`, compare with a committed list of the ones we have assessed, and file one issue per new entry. It **files issues, never PRs**, and trusts only markers the automation wrote, exactly as the SDK watch does. -- **Official extension** → a `v2` + `enhancement` issue to implement it, milestoned at triage. +- **Official extension** → a `v2` + `enhancement` issue to implement it, filed with the current milestone as `sdk-watch` does; only when no dated milestone is open is it left unmilestoned for triage to place in Incoming. - **Experimental extension** → a `v2` + `question` tracking issue, so we can design against it before its SEP (the 🟡 rule) without committing build capacity. - **This table is the record.** An extension is added here when its issue is filed, and its From 9741759d8687eacf567e7000b5aaa33cb56f9c10 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Wed, 16 Sep 2026 20:00:02 -0400 Subject: [PATCH 05/17] docs: address Copilot round 3 on the roadmap realignment (#2401 review) Scope the tool result check to the one relationship the spec defines (structuredContent SHOULD be accompanied by its serialized JSON in a TextContent block), and describe the upstream matrix update as partial-support notation, since its single Inspector row cannot express per-client support. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 299e70536c..3674eab1e9 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -237,12 +237,13 @@ result view; progressive discovery breaks the assumption behind every list we re in richer annotation rendering now. The first draft's §3.6 (streamed and reference results) and §3.8 (the SEP-2356 file picker) are **not on the published roadmap** and move to watch. -What we _can_ do now is show the problem the redesign is solving: a server returning -`content` and `structuredContent` that disagree is a real bug today. +What we _can_ do now is show one concrete symptom of the problem the redesign is solving: a +server that returns `structuredContent` without the serialized-JSON text block the spec asks +for breaks older clients today. | Feature | Confidence | Notes | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------ | -| **`content` / `structuredContent` consistency check** — flag results where both are present and disagree | 🟢 | Useful today, and implementation evidence for the Core Primitives WG. A missing `structuredContent` under a declared `outputSchema` is already flagged by `validateToolOutput` (shipped). | +| **Serialized-JSON check for `structuredContent`** — when a result carries `structuredContent`, flag the absence of a `TextContent` block holding its serialized JSON, the one relationship the spec defines (a SHOULD, "for backwards compatibility"). Reported as a diagnostic, never an error; any other text is a legitimate summary and is not compared | 🟢 | Useful today, and implementation evidence for the Core Primitives WG. A missing `structuredContent` under a declared `outputSchema` is already flagged by `validateToolOutput` (shipped). | | **New tool result shape** | 🔴 | WG still forming. Keep both renderings behind the era seam when it lands. | | **Progressive discovery** | 🔴 | Design the lists (§5.10) so "not loaded yet" is a state, not an empty list. | | **Annotation-driven confirmation** before a `destructiveHint` call | 🟢 | Tool annotations are not the audience/priority content annotations under review. Small and obviously correct. | @@ -327,7 +328,9 @@ official status through the Extensions Track of | OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | ❌ | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | **Actions:** implement OAuth Client Credentials; and, with maintainer sign-off, open a PR on -`modelcontextprotocol/modelcontextprotocol` to fill in the Inspector row's blank Apps and Enterprise Auth cells and update its Skills cell in the client matrix. +`modelcontextprotocol/modelcontextprotocol` to update the Inspector row. That matrix has one row per client, +so it cannot show per-client support: mark Apps and Skills as partial with a link explaining the split (Apps renders in +Web only; the CLI has a metadata probe), or propose separate Web/CLI/TUI rows. Enterprise Auth can be a plain check. ### Keeping up as extensions are approved @@ -516,7 +519,7 @@ items that need no upstream work._ - 🅑 **Command palette and global search** (§5.4); **Connection Doctor** (§5.8) - 🅐 **Cache hint display and observations** (§3.2) — SEP-2549 is Final - 🅐 **OAuth Client Credentials extension** (§3.3, §4) -- 🅐 **`content` / `structuredContent` consistency check** and **destructive-call confirmation** (§3.4) +- 🅐 **Serialized-JSON check for `structuredContent`** and **destructive-call confirmation** (§3.4) - 🅐 **Extension-watch sweep** (§4) ### Phase 3 — Automation (~`v2.16` – `v2.21`, Nov 2026 – Jan 2027) From a9453bda5459fe0c8197a8053600365402f955d3 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 10:17:02 -0400 Subject: [PATCH 06/17] docs: address Copilot round 4 on the roadmap realignment (#2401 review) Accuracy fixes: Last-Event-ID is legacy-only; #1005/#1015 shipped a schema portability lint, not a validator; Tasks is an extension, not base spec; the session lifecycle lane is obsolete only for modern connections; streamed results are deprioritized, not absent; payload truncation is planned; the extension sweep is idempotent via issue markers with a maintainer-kept table; the matrix's OAuth cell is blank, not unsupported. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 36 +++++++++++++++++-------------- 1 file changed, 20 insertions(+), 16 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 3674eab1e9..2e2e085134 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -82,10 +82,10 @@ be re-planned: | Item | Issue(s) | | ------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `Last-Event-ID` resumption | [#920](https://github.com/modelcontextprotocol/inspector/issues/920) | +| `Last-Event-ID` resumption (legacy Streamable HTTP only; the 2026-07-28 era removed SSE resumability) | [#920](https://github.com/modelcontextprotocol/inspector/issues/920) | | `server.json` support | [#922](https://github.com/modelcontextprotocol/inspector/issues/922) | | Discover checkmarks for task extensions | [#1887](https://github.com/modelcontextprotocol/inspector/issues/1887) | -| Strict JSON Schema validation | [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015) | +| Tool-schema portability lint (`--strict`) | [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015) | | The argument editor workstream (all six issues) | [#1853](https://github.com/modelcontextprotocol/inspector/issues/1853), [#1856](https://github.com/modelcontextprotocol/inspector/issues/1856), [#1885](https://github.com/modelcontextprotocol/inspector/issues/1885), [#1928](https://github.com/modelcontextprotocol/inspector/issues/1928), [#1919](https://github.com/modelcontextprotocol/inspector/issues/1919), [#1910](https://github.com/modelcontextprotocol/inspector/issues/1910) | | Connection fixes (version-negotiation DX, `https://localhost`, dev containers, ghost entry) | [#962](https://github.com/modelcontextprotocol/inspector/issues/962), [#1936](https://github.com/modelcontextprotocol/inspector/issues/1936), [#1951](https://github.com/modelcontextprotocol/inspector/issues/1951), [#1914](https://github.com/modelcontextprotocol/inspector/issues/1914) | | Server config: paste-JSON, custom headers, auth URL overrides, file-backed secrets | [#904](https://github.com/modelcontextprotocol/inspector/issues/904), [#1915](https://github.com/modelcontextprotocol/inspector/issues/1915), [#1906](https://github.com/modelcontextprotocol/inspector/issues/1906), [#1950](https://github.com/modelcontextprotocol/inspector/issues/1950) | @@ -161,7 +161,7 @@ conversation now and bring it to the WG as implementation feedback. | Feature | Confidence | Notes | | -------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | -| **In-flight work lane** — tasks, open `subscriptions/listen` streams and progress-reporting requests as spans on one timeline lane (§5.1) | 🟢 | All three already exist in the 2026-07-28 spec. Makes composition gaps (mismatched cancellation, divergent errors) visible, which the WG can use. | +| **In-flight work lane** — tasks, open `subscriptions/listen` streams and progress-reporting requests as spans on one timeline lane (§5.1) | 🟢 | `subscriptions/listen` and progress are in the 2026-07-28 spec; Tasks is the official `io.modelcontextprotocol/tasks` extension (§4). Makes composition gaps (mismatched cancellation, divergent errors) visible, which the WG can use. | | **Cancellation and error comparison** — show how each in-flight kind ended (completed, cancelled, errored, server-closed) with the same vocabulary | 🟢 | A small, direct contribution to the composition review. | | **Callback receiver** — backend-hosted endpoint registered as a push target | 🔴 | Design now, build when the SEP lands. Security review mandatory: an inbound public endpoint on a process that spawns subprocesses. | | **Local reachability story** — tunnel integration or documented guidance | 🔴 | Likely the hardest UX problem of the six months. | @@ -179,10 +179,12 @@ including for tool-call results. **Beyond:** standardized error handling across capability scoping for tool lists after SEP-2575, and a secure way to hand servers configuration. -**Read:** The first draft's §3.1 (stateless Streamable HTTP, session creation / resumption / -migration) is **largely obsolete**: SEP-2575 (stateless) and SEP-2567 (sessionless, explicit -state handles) are Final and already shipped. A "session lifecycle lane" describes a model the -spec has left behind; what remains to show is **state handles**. Caching, on the other hand, is +**Read:** For **modern** (2026-07-28) connections, the first draft's §3.1 (stateless Streamable +HTTP, session creation / resumption / migration) is **largely obsolete**: SEP-2575 (stateless) +and SEP-2567 (sessionless) are Final and already shipped, so a session lifecycle lane has nothing +to show there. The Inspector is still a dual-era client, though, and **legacy** Streamable HTTP +keeps `initialize` and session-scoped state; a session lifecycle lane for legacy connections stays +a valid, **deferred** timeline follow-up (§5.1) rather than being dropped. Caching, on the other hand, is Final and we already parse the fields — we just do not render them, and a client that shows cache hints is exactly how a server author finds out theirs are wrong. @@ -235,7 +237,8 @@ filesystem-like resource semantics** (range reads, hierarchical listing). result view; progressive discovery breaks the assumption behind every list we render (that `*/list` returns everything); and a possible annotation deprecation means we should not invest in richer annotation rendering now. The first draft's §3.6 (streamed and reference results) -and §3.8 (the SEP-2356 file picker) are **not on the published roadmap** and move to watch. +and §3.8 (the SEP-2356 file picker) are **not prioritized deliverables for this period** — the +roadmap mentions "results that stream" only in framing — so they move to watch. What we _can_ do now is show one concrete symptom of the problem the redesign is solving: a server that returns `structuredContent` without the serialized-JSON text block the spec asks @@ -300,7 +303,7 @@ work for them this horizon**. Each keeps a tracking issue and a liaison. | **Server Cards** (SEP-2127) | Card preview, card-vs-reality diff, `--card-lint` in Phase 3 | 🔴 Watch. [#1857](https://github.com/modelcontextprotocol/inspector/issues/1857)'s **registry** half does not depend on it (§5.9). | | **Interceptors** (SEP-1763) | Test bench, audit mode, CLI invocation in Phase 4 | 🔴 Watch. The WG's unowned "CLI client for interceptor invocation" is still worth raising (§8). | | **Primitive grouping** (IG) | Grouped sidebars | The **UX** half proceeds as Track B (§5.10) on client-side heuristics; no spec data source is expected this horizon. | -| **Streamed and reference results** | Incremental rendering, reference handles | 🔴 Watch. Payload truncation in §5.10 covers the large-result case today. | +| **Streamed and reference results** | Incremental rendering, reference handles | 🔴 Watch. Planned payload truncation (§5.10) will cover the large-result case; result views render full payloads today. | | **File picker from `FileInputDescriptor`** (SEP-2356) | `SchemaForm` + elicitation picker | 🔴 Watch. The File Uploads WG's published direction is now filesystem-like resources (§3.4). | | **Gateways, audit trails, configuration portability** | Gateway mode; OTLP as spec work | Gateway mode dropped. OTLP and the audit transcript continue as Track B (§5.7). | @@ -325,7 +328,7 @@ official status through the Extensions Track of | Tasks | `io.modelcontextprotocol/tasks` | ✅ | ❌ | ❌ | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). The CLI's one-shot mode rejects `tasks/*`; no TUI Tasks pane yet. | | Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | | Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | ✅ | ✅ | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). | -| OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | ❌ | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | +| OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | Inspector row, cell blank | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | **Actions:** implement OAuth Client Credentials; and, with maintainer sign-off, open a PR on `modelcontextprotocol/modelcontextprotocol` to update the Inspector row. That matrix has one row per client, @@ -339,14 +342,15 @@ mechanism, the way SDK releases already are: - **An extension-watch sweep**, modelled on `scripts/sdk-watch.mjs`: on a schedule, list the org's `ext-*` and `experimental-ext-*` repositories and the extension identifiers on - `/extensions/overview`, compare with a committed list of the ones we have assessed, and file - one issue per new entry. It **files issues, never PRs**, and trusts only markers the - automation wrote, exactly as the SDK watch does. + `/extensions/overview`, and file one issue per entry it has not filed before. As in the SDK watch, the **issue markers + are the source of truth** for idempotency: an entry whose marker is on an existing issue (open or + closed) authored by the automation is skipped, so nothing needs committing back. It **files + issues, never PRs**, and trusts only markers the automation wrote. - **Official extension** → a `v2` + `enhancement` issue to implement it, filed with the current milestone as `sdk-watch` does; only when no dated milestone is open is it left unmilestoned for triage to place in Incoming. - **Experimental extension** → a `v2` + `question` tracking issue, so we can design against it before its SEP (the 🟡 rule) without committing build capacity. -- **This table is the record.** An extension is added here when its issue is filed, and its - cells move as support lands. +- **This table is maintainer-maintained.** The sweep never edits it; a maintainer adds a row when + an extension's issue is triaged and moves its cells as support lands. --- @@ -502,7 +506,7 @@ annotated with what has already shipped. ### Phase 1 — Foundations (~`v2.2` – `v2.9`, Aug–Sep 2026) -- ✅ `Last-Event-ID` resumption (#920); discover checkmarks (#1887); `server.json` (#922) +- ✅ `Last-Event-ID` resumption, legacy only (#920); discover checkmarks (#1887); `server.json` (#922) - ✅ Argument editor workstream (six issues); connection fixes (§1) - ✅ Skills over MCP (#2234, #2248); Enterprise-Managed Authorization (#1509) - 🅑 **Zoomable timeline v1** — carried into Phase 2 From 5157b0a16cfb6980c7ca2a77687bd71c1447a9c8 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 10:35:31 -0400 Subject: [PATCH 07/17] docs: address Copilot round 5 on the roadmap realignment (#2401 review) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Correct the shipped history (EMA predates the first draft; #1936 shipped guidance, not a fix), finish the portability-lint rename in §3.6, note Phase 1 is selective, clarify the roadmap's extension coverage, add the Transports WG charter, fix a comma splice, and defer the extension sweep's marker-label and bootstrap rules to its own design issue. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 20 +++++++++++--------- 1 file changed, 11 insertions(+), 9 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 2e2e085134..85b10016a1 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -87,9 +87,9 @@ be re-planned: | Discover checkmarks for task extensions | [#1887](https://github.com/modelcontextprotocol/inspector/issues/1887) | | Tool-schema portability lint (`--strict`) | [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015) | | The argument editor workstream (all six issues) | [#1853](https://github.com/modelcontextprotocol/inspector/issues/1853), [#1856](https://github.com/modelcontextprotocol/inspector/issues/1856), [#1885](https://github.com/modelcontextprotocol/inspector/issues/1885), [#1928](https://github.com/modelcontextprotocol/inspector/issues/1928), [#1919](https://github.com/modelcontextprotocol/inspector/issues/1919), [#1910](https://github.com/modelcontextprotocol/inspector/issues/1910) | -| Connection fixes (version-negotiation DX, `https://localhost`, dev containers, ghost entry) | [#962](https://github.com/modelcontextprotocol/inspector/issues/962), [#1936](https://github.com/modelcontextprotocol/inspector/issues/1936), [#1951](https://github.com/modelcontextprotocol/inspector/issues/1951), [#1914](https://github.com/modelcontextprotocol/inspector/issues/1914) | +| Connection fixes (version-negotiation DX, dev containers, ghost entry) and self-signed `https://localhost` guidance (documented trust configuration, not a code fix) | [#962](https://github.com/modelcontextprotocol/inspector/issues/962), [#1936](https://github.com/modelcontextprotocol/inspector/issues/1936), [#1951](https://github.com/modelcontextprotocol/inspector/issues/1951), [#1914](https://github.com/modelcontextprotocol/inspector/issues/1914) | | Server config: paste-JSON, custom headers, auth URL overrides, file-backed secrets | [#904](https://github.com/modelcontextprotocol/inspector/issues/904), [#1915](https://github.com/modelcontextprotocol/inspector/issues/1915), [#1906](https://github.com/modelcontextprotocol/inspector/issues/1906), [#1950](https://github.com/modelcontextprotocol/inspector/issues/1950) | -| Enterprise-Managed Authorization; IdP OIDC option | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509), [#1937](https://github.com/modelcontextprotocol/inspector/issues/1937) | +| IdP OIDC option (EMA itself, #1509, predates the first draft) | [#1937](https://github.com/modelcontextprotocol/inspector/issues/1937) | | Skills over MCP (SEP-2640) across web, CLI and TUI | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248) | Closed as **not planned**, so not carried forward: custom transports ([#1741](https://github.com/modelcontextprotocol/inspector/issues/1741)), the configurable-proxy base ([#1684](https://github.com/modelcontextprotocol/inspector/issues/1684)), the readiness summary ([#1916](https://github.com/modelcontextprotocol/inspector/issues/1916)), full panel collapse ([#928](https://github.com/modelcontextprotocol/inspector/issues/928)), `*.localhost` domains ([#1944](https://github.com/modelcontextprotocol/inspector/issues/1944)), and the trusted-local-host OAuth HTTP exception ([#1911](https://github.com/modelcontextprotocol/inspector/issues/1911)). @@ -289,7 +289,7 @@ does not. | ------------------------------------------------------------------------------------------------- | ---------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Conformance runner** — run the suite against a connected server, render pass/fail per assertion | 🟡 | **Action: open a conversation with the conformance maintainers.** Build the shared assertion engine (§5.6) first. | | **`mcp-inspector --conformance` for CI** | 🟡 | Same engine, CLI report, exit code. | -| **Strict schema validation with actionable errors** | ✅ | Shipped — [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015). | +| **Tool-schema portability lint (`--strict`)** — not a full JSON Schema validator | ✅ | Shipped — [#1005](https://github.com/modelcontextprotocol/inspector/issues/1005), [#1015](https://github.com/modelcontextprotocol/inspector/issues/1015). | ### 3.7 Off the published roadmap — watch only @@ -311,9 +311,9 @@ work for them this horizon**. Each keeps a tracking issue and a liaison. ## 4. Official extensions -The MCP roadmap does not list extensions, but **approved extensions are spec-following work** — +The MCP roadmap mentions Tasks (§3.1) but carries no inventory of official extensions, and **approved extensions are spec-following work** — a client that ignores them stops being a reference client. The list lives at -[`/extensions/overview`](https://modelcontextprotocol.io/extensions/overview), implementations +[`/extensions/overview`](https://modelcontextprotocol.io/extensions/overview); implementations are recorded in the community-maintained [client matrix](https://modelcontextprotocol.io/extensions/client-matrix), and extensions reach official status through the Extensions Track of @@ -345,7 +345,9 @@ mechanism, the way SDK releases already are: `/extensions/overview`, and file one issue per entry it has not filed before. As in the SDK watch, the **issue markers are the source of truth** for idempotency: an entry whose marker is on an existing issue (open or closed) authored by the automation is skipped, so nothing needs committing back. It **files - issues, never PRs**, and trusts only markers the automation wrote. + issues, never PRs**. Two details are left to the sweep's own design issue: which labels a trusted + marker issue must also carry (as `sdk-watch` requires), and the first-run bootstrap for extensions + already tracked by hand-filed issues (Skills, EMA), so that it does not file duplicates. - **Official extension** → a `v2` + `enhancement` issue to implement it, filed with the current milestone as `sdk-watch` does; only when no dated milestone is open is it left unmilestoned for triage to place in Incoming. - **Experimental extension** → a `v2` + `question` tracking issue, so we can design against it before its SEP (the 🟡 rule) without committing build capacity. @@ -502,13 +504,13 @@ diff, and session format exist would mean designing it against the wrong surface Four phases of roughly six weekly milestones each. Track A items appear where their upstream signal is expected; Track B items are placed to unblock Track A wherever possible. Phase 1 is -annotated with what has already shipped. +annotated with a selection of what has already shipped; §1 has the full list. ### Phase 1 — Foundations (~`v2.2` – `v2.9`, Aug–Sep 2026) - ✅ `Last-Event-ID` resumption, legacy only (#920); discover checkmarks (#1887); `server.json` (#922) - ✅ Argument editor workstream (six issues); connection fixes (§1) -- ✅ Skills over MCP (#2234, #2248); Enterprise-Managed Authorization (#1509) +- ✅ Skills over MCP (#2234, #2248) - 🅑 **Zoomable timeline v1** — carried into Phase 2 - 🅑 **Connection Doctor** (§5.8) — carried into Phase 2 @@ -608,7 +610,7 @@ For WG discussion. - [MCP Roadmap](https://modelcontextprotocol.io/development/roadmap) (last updated 2026-08-22) - [Extensions overview](https://modelcontextprotocol.io/extensions/overview) · [Extension support matrix](https://modelcontextprotocol.io/extensions/client-matrix) · [SEP-2133: Extensions](https://modelcontextprotocol.io/seps/2133-extensions) - Final SEPs cited: [SEP-2549 (TTL for list results)](https://modelcontextprotocol.io/seps/2549-TTL-for-list-results) · [SEP-2567 (sessionless)](https://modelcontextprotocol.io/seps/2567-sessionless-mcp) · [SEP-2575 (stateless)](https://modelcontextprotocol.io/seps/2575-stateless-mcp) · [SEP-2663 (Tasks extension)](https://modelcontextprotocol.io/seps/2663-tasks-extension) · [SEP-2640 (Skills extension)](https://modelcontextprotocol.io/seps/2640-skills-extension) · [SEP-2484 (conformance tests)](https://modelcontextprotocol.io/seps/2484-conformance-tests-required-for-final-seps) -- WG charters: [Inspector V2](https://modelcontextprotocol.io/community/working-groups/inspector-v2) · [Triggers & Events](https://modelcontextprotocol.io/community/working-groups/triggers-events) · [Agents](https://modelcontextprotocol.io/community/working-groups/agents) · [File Uploads](https://modelcontextprotocol.io/community/working-groups/file-uploads) · [SDK](https://modelcontextprotocol.io/community/working-groups/sdk) +- WG charters: [Inspector V2](https://modelcontextprotocol.io/community/working-groups/inspector-v2) · [Triggers & Events](https://modelcontextprotocol.io/community/working-groups/triggers-events) · [Agents](https://modelcontextprotocol.io/community/working-groups/agents) · [Transports](https://modelcontextprotocol.io/community/working-groups/transports) · [File Uploads](https://modelcontextprotocol.io/community/working-groups/file-uploads) · [SDK](https://modelcontextprotocol.io/community/working-groups/sdk) - [SDK tiers and conformance testing](https://modelcontextprotocol.io/community/sdk-tiers) - Internal: [`specification/v2_new_spec_impact.md`](../specification/v2_new_spec_impact.md) · [`specification/v2_scope.md`](../specification/v2_scope.md) · [`specification/v2_ux_features.md`](../specification/v2_ux_features.md) - [Inspector V2 project board (#28)](https://github.com/orgs/modelcontextprotocol/projects/28) From a2430e70a6e7a30a47d0196100c4064d730b8831 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 10:53:57 -0400 Subject: [PATCH 08/17] docs: address Copilot round 6 on the roadmap realignment (#2401 review) Scope cache hints to the SEP-2549 methods, mark CLI/TUI Tasks as partial (shared-client polling without direct controls), link the CLI/TUI Apps advertisement bug (#2403), complete the sweep's bootstrap list, and describe experimental incubation as optional per SEP-2133. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 85b10016a1..fb98856f43 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -193,7 +193,7 @@ where the Inspector is thinnest over the SDK. Watch closely. | Feature | Confidence | Notes | | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Cache hint display** — `ttlMs` / `cacheScope` on every list and resource read, with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. The runtime already parses the hints and honors them through the SDK list cache; the gap is showing them. | +| **Cache hint display** — `ttlMs` / `cacheScope` on the SEP-2549 surfaces (`tools/list`, `prompts/list`, `resources/list`, `resources/templates/list`, `resources/read`; extension methods such as `skills/list` carry none), with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. The runtime already parses the hints and honors them through the SDK list cache; the gap is showing them. | | **Cache behavior observations** — note a re-fetch of a still-fresh result, and a list that changed inside its declared TTL, as diagnostics rather than errors | 🟢 | Inspector-shaped: nobody else observes both the hint and the reality. `ttlMs` is a freshness hint, so both are compliant. | | **Stateful-tool workflow investigation** — how to help a user carry an SEP-2567-style handle from one tool result into the next call | 🟡 | Replaces the first draft's "session lifecycle lane". The protocol has no concept of a handle (it is ordinary tool data), so a generic view would be inference; investigate before designing. | | **ETag support** — send `If-None-Match`, show 304s and version changes | 🟡 | Build when the SEP reaches Draft with an SDK impl. | @@ -317,15 +317,15 @@ a client that ignores them stops being a reference client. The list lives at are recorded in the community-maintained [client matrix](https://modelcontextprotocol.io/extensions/client-matrix), and extensions reach official status through the Extensions Track of -[SEP-2133](https://modelcontextprotocol.io/seps/2133-extensions), usually after incubating in an -`experimental-ext-*` repository. +[SEP-2133](https://modelcontextprotocol.io/seps/2133-extensions), optionally after incubating in an +`experimental-ext-*` repository (encouraged, not required). ### Current support (as of 2026-09-16) | Extension | Identifier | Web | CLI | TUI | Upstream matrix | Notes | | -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| MCP Apps | `io.modelcontextprotocol/ui` | ✅ | 🟡 | — | Inspector row, cell blank | Apps tab. Columns are rendering support: rendering needs a browser, so the CLI has only the `--app-info` metadata probe and the TUI nothing. The shared client still advertises the extension from CLI and TUI. | -| Tasks | `io.modelcontextprotocol/tasks` | ✅ | ❌ | ❌ | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). The CLI's one-shot mode rejects `tasks/*`; no TUI Tasks pane yet. | +| MCP Apps | `io.modelcontextprotocol/ui` | ✅ | 🟡 | — | Inspector row, cell blank | Apps tab. Columns are rendering support: rendering needs a browser, so the CLI has only the `--app-info` metadata probe and the TUI nothing. The shared client still advertises the extension from CLI and TUI, which is a compatibility bug tracked in [#2403](https://github.com/modelcontextprotocol/inspector/issues/2403). | +| Tasks | `io.modelcontextprotocol/tasks` | ✅ | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). CLI and TUI advertise the extension and poll server-directed task handles through the shared client, but have no direct `tasks/*` controls: the CLI's one-shot mode rejects them, and the TUI has no Tasks pane. | | Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | | Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | ✅ | ✅ | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). | | OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | Inspector row, cell blank | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | @@ -347,7 +347,7 @@ mechanism, the way SDK releases already are: closed) authored by the automation is skipped, so nothing needs committing back. It **files issues, never PRs**. Two details are left to the sweep's own design issue: which labels a trusted marker issue must also carry (as `sdk-watch` requires), and the first-run bootstrap for extensions - already tracked by hand-filed issues (Skills, EMA), so that it does not file duplicates. + already tracked by hand-filed issues (Apps #1740, Tasks #1887, Skills #2234, EMA #1509), so that it does not file duplicates. - **Official extension** → a `v2` + `enhancement` issue to implement it, filed with the current milestone as `sdk-watch` does; only when no dated milestone is open is it left unmilestoned for triage to place in Incoming. - **Experimental extension** → a `v2` + `question` tracking issue, so we can design against it before its SEP (the 🟡 rule) without committing build capacity. From 223579856f11f9f20f615b101786c2c08b81a5a4 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 11:12:40 -0400 Subject: [PATCH 09/17] docs: address Copilot round 7 on the roadmap realignment (#2401 review) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Include modern skills/list (SEP-2640 requires ttlMs/cacheScope) in the cache-hint surfaces, soften the serialized-JSON consequence to match its SHOULD, describe CLI/TUI Tasks as core support with no user-facing surface, and note that #1857 continues in §5.9. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index fb98856f43..563f746ce8 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -193,7 +193,7 @@ where the Inspector is thinnest over the SDK. Watch closely. | Feature | Confidence | Notes | | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Cache hint display** — `ttlMs` / `cacheScope` on the SEP-2549 surfaces (`tools/list`, `prompts/list`, `resources/list`, `resources/templates/list`, `resources/read`; extension methods such as `skills/list` carry none), with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. The runtime already parses the hints and honors them through the SDK list cache; the gap is showing them. | +| **Cache hint display** — `ttlMs` / `cacheScope` on the SEP-2549 surfaces (`tools/list`, `prompts/list`, `resources/list`, `resources/templates/list`, `resources/read`), plus modern (2026-07-28+) `skills/list`, which SEP-2640 requires to carry both fields; legacy `skills/list` and `skills/get` carry none, with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. The runtime already parses the hints and honors them through the SDK list cache; the gap is showing them. | | **Cache behavior observations** — note a re-fetch of a still-fresh result, and a list that changed inside its declared TTL, as diagnostics rather than errors | 🟢 | Inspector-shaped: nobody else observes both the hint and the reality. `ttlMs` is a freshness hint, so both are compliant. | | **Stateful-tool workflow investigation** — how to help a user carry an SEP-2567-style handle from one tool result into the next call | 🟡 | Replaces the first draft's "session lifecycle lane". The protocol has no concept of a handle (it is ordinary tool data), so a generic view would be inference; investigate before designing. | | **ETag support** — send `If-None-Match`, show 304s and version changes | 🟡 | Build when the SEP reaches Draft with an SDK impl. | @@ -242,7 +242,7 @@ roadmap mentions "results that stream" only in framing — so they move to watch What we _can_ do now is show one concrete symptom of the problem the redesign is solving: a server that returns `structuredContent` without the serialized-JSON text block the spec asks -for breaks older clients today. +for can hide its structured data from older clients today. | Feature | Confidence | Notes | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------ | @@ -305,7 +305,7 @@ work for them this horizon**. Each keeps a tracking issue and a liaison. | **Primitive grouping** (IG) | Grouped sidebars | The **UX** half proceeds as Track B (§5.10) on client-side heuristics; no spec data source is expected this horizon. | | **Streamed and reference results** | Incremental rendering, reference handles | 🔴 Watch. Planned payload truncation (§5.10) will cover the large-result case; result views render full payloads today. | | **File picker from `FileInputDescriptor`** (SEP-2356) | `SchemaForm` + elicitation picker | 🔴 Watch. The File Uploads WG's published direction is now filesystem-like resources (§3.4). | -| **Gateways, audit trails, configuration portability** | Gateway mode; OTLP as spec work | Gateway mode dropped. OTLP and the audit transcript continue as Track B (§5.7). | +| **Gateways, audit trails, configuration portability** | Gateway mode; OTLP as spec work | Gateway mode dropped. OTLP and the audit transcript continue as Track B (§5.7); rich server configuration and registry browsing (#1857) continue in §5.9. | --- @@ -325,7 +325,7 @@ official status through the Extensions Track of | Extension | Identifier | Web | CLI | TUI | Upstream matrix | Notes | | -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | MCP Apps | `io.modelcontextprotocol/ui` | ✅ | 🟡 | — | Inspector row, cell blank | Apps tab. Columns are rendering support: rendering needs a browser, so the CLI has only the `--app-info` metadata probe and the TUI nothing. The shared client still advertises the extension from CLI and TUI, which is a compatibility bug tracked in [#2403](https://github.com/modelcontextprotocol/inspector/issues/2403). | -| Tasks | `io.modelcontextprotocol/tasks` | ✅ | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). CLI and TUI advertise the extension and poll server-directed task handles through the shared client, but have no direct `tasks/*` controls: the CLI's one-shot mode rejects them, and the TUI has no Tasks pane. | +| Tasks | `io.modelcontextprotocol/tasks` | ✅ | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). CLI and TUI advertise the extension and the shared core supports it, but neither exposes a user-facing task surface: the CLI's one-shot mode rejects `tasks/*`, and the TUI has no Tasks pane. | | Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | | Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | ✅ | ✅ | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). | | OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | Inspector row, cell blank | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | From 1683fa4ea383873b109e2c15218201b12f6d54dc Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 11:32:02 -0400 Subject: [PATCH 10/17] docs: address Copilot round 8 on the roadmap realignment (#2401 review) Qualify the 2026-07-28 baseline with #1917, move ETags to watch, scope what the runtime already honors for cache hints, file experimental-extension issues unmilestoned for Incoming, mark Skills as a plain matrix check, and describe server configuration as a Beyond item rather than absent. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 22 ++++++++++++---------- 1 file changed, 12 insertions(+), 10 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 563f746ce8..21067fb4b0 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -55,7 +55,7 @@ Through v1, the Inspector was a **follow-along project**. The spec moved, we cha whatever planning capacity remained went to keeping up rather than to the tool's own design. Every release was reactive by necessity. -That constraint has lifted. v2 meets the 2026-07-28 spec across all three clients, on SDK v2, +That constraint has lifted. v2 meets the 2026-07-28 spec across all three clients (one known exception, #1917, waits on an SDK release), on SDK v2, with a shared `core/`, a ≥90% per-file coverage gate, and a smoke/e2e apparatus that catches packaging failures. For the first time we can spend planned effort on **what the Inspector should be**, not only on what the spec just became. @@ -166,7 +166,7 @@ conversation now and bring it to the WG as implementation feedback. | **Callback receiver** — backend-hosted endpoint registered as a push target | 🔴 | Design now, build when the SEP lands. Security review mandatory: an inbound public endpoint on a process that spawns subprocesses. | | **Local reachability story** — tunnel integration or documented guidance | 🔴 | Likely the hardest UX problem of the six months. | | **Delivery log with ordering and duplicate assertions** | 🔴 | The conformance value: did events arrive in order? were any redelivered? | -| **`Mcp-Name` header on Tasks over Streamable HTTP** | 🟡 | [#1917](https://github.com/modelcontextprotocol/inspector/issues/1917) — blocked upstream. | +| **`Mcp-Name` header on Tasks over Streamable HTTP** | 🟡 | [#1917](https://github.com/modelcontextprotocol/inspector/issues/1917) — a current non-conformance: the fix is merged upstream but unreleased, so the pinned SDK still omits the header SEP-2663 requires. Waits on the next SDK release. | | **Tasks extension → core migration** | 🔴 | Moved to "Beyond" upstream. Keep the era-conditional exposure; the legacy `capabilities.tasks` path must keep working. | ### 3.2 HTTP-native transport unification and hardening @@ -193,10 +193,10 @@ where the Inspector is thinnest over the SDK. Watch closely. | Feature | Confidence | Notes | | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Cache hint display** — `ttlMs` / `cacheScope` on the SEP-2549 surfaces (`tools/list`, `prompts/list`, `resources/list`, `resources/templates/list`, `resources/read`), plus modern (2026-07-28+) `skills/list`, which SEP-2640 requires to carry both fields; legacy `skills/list` and `skills/get` carry none, with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. The runtime already parses the hints and honors them through the SDK list cache; the gap is showing them. | +| **Cache hint display** — `ttlMs` / `cacheScope` on the SEP-2549 surfaces (`tools/list`, `prompts/list`, `resources/list`, `resources/templates/list`, `resources/read`), plus modern (2026-07-28+) `skills/list`, which SEP-2640 requires to carry both fields; legacy `skills/list` and `skills/get` carry none, with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. The runtime parses the hints everywhere and honors them through the SDK cache for the four `*/list` methods; `resources/read` and `skills/list` go through plain requests that validate but do not honor them, so this item includes that plumbing as well as the display. | | **Cache behavior observations** — note a re-fetch of a still-fresh result, and a list that changed inside its declared TTL, as diagnostics rather than errors | 🟢 | Inspector-shaped: nobody else observes both the hint and the reality. `ttlMs` is a freshness hint, so both are compliant. | | **Stateful-tool workflow investigation** — how to help a user carry an SEP-2567-style handle from one tool result into the next call | 🟡 | Replaces the first draft's "session lifecycle lane". The protocol has no concept of a handle (it is ordinary tool data), so a generic view would be inference; investigate before designing. | -| **ETag support** — send `If-None-Match`, show 304s and version changes | 🟡 | Build when the SEP reaches Draft with an SDK impl. | +| **ETag support** — send `If-None-Match`, show 304s and version changes | 🔴 | Watch until a SEP reaches Draft with an SDK impl. | | **HTTP over stdio** | 🔴 | Watch. If it lands, the Network screen becomes meaningful for stdio servers too — a large win. | | **Standardized error rendering** | 🔴 | "Beyond". Our Protocol-vs-Network error split (#1628) is the seam to adopt it into. | @@ -211,8 +211,9 @@ human-presence attestation. **Read:** DPoP was 🔴 in the first draft and is now a named deliverable, so it moves up. Our EMA work (#1509) already gives us the ID-JAG leg, which makes the Inspector a credible test -client for the whole identity chain. The first draft's audit trails, gateway mode and -configuration portability are **no longer on the MCP roadmap**; OTLP export and the audit +client for the whole identity chain. The first draft's audit trails and gateway mode are **no longer on the MCP roadmap**, and +configuration ("providing servers with configuration options in a secure way") is now a +"Beyond" item (§3.2), outside this horizon; OTLP export and the audit transcript are still worth building, but as our own Track B work (§5.7), not as spec-following. | Feature | Confidence | Notes | @@ -332,8 +333,8 @@ official status through the Extensions Track of **Actions:** implement OAuth Client Credentials; and, with maintainer sign-off, open a PR on `modelcontextprotocol/modelcontextprotocol` to update the Inspector row. That matrix has one row per client, -so it cannot show per-client support: mark Apps and Skills as partial with a link explaining the split (Apps renders in -Web only; the CLI has a metadata probe), or propose separate Web/CLI/TUI rows. Enterprise Auth can be a plain check. +so it cannot show per-client support: mark Apps as partial with a link explaining the split (Apps renders in +Web only; the CLI has a metadata probe), or propose separate Web/CLI/TUI rows. Skills and Enterprise Auth can be plain checks. ### Keeping up as extensions are approved @@ -349,8 +350,9 @@ mechanism, the way SDK releases already are: marker issue must also carry (as `sdk-watch` requires), and the first-run bootstrap for extensions already tracked by hand-filed issues (Apps #1740, Tasks #1887, Skills #2234, EMA #1509), so that it does not file duplicates. - **Official extension** → a `v2` + `enhancement` issue to implement it, filed with the current milestone as `sdk-watch` does; only when no dated milestone is open is it left unmilestoned for triage to place in Incoming. -- **Experimental extension** → a `v2` + `question` tracking issue, so we can design against it - before its SEP (the 🟡 rule) without committing build capacity. +- **Experimental extension** → a `v2` + `question` tracking issue, filed **unmilestoned and + unboarded** so triage places it in Incoming (the documented exception for unapproved work); it + gets a milestone only if a maintainer approves design work against it before its SEP. - **This table is maintainer-maintained.** The sweep never edits it; a maintainer adds a row when an extension's issue is triaged and moves its cells as support lands. From 070fe36e6e8cccb8db92b35193fef5cf82bbd85f Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 11:50:19 -0400 Subject: [PATCH 11/17] docs: address Copilot round 9 on the roadmap realignment (#2401 review) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Date the support snapshot 2026-09-17, mark web Tasks partial pending #1917, keep server configuration out of the off-roadmap row, source extension ids from each spec, make Phase 4 ETags and contract validation conditional, and tighten the §3.7 and client-matrix wording. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 21 +++++++++++---------- 1 file changed, 11 insertions(+), 10 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 21067fb4b0..6e45fa62da 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -294,8 +294,8 @@ does not. ### 3.7 Off the published roadmap — watch only -The first draft planned build work for several WG efforts that the 2026-08-22 roadmap does not -list. They are not cancelled upstream — WGs keep working outside the priority areas — but the +The first draft planned build work for several WG efforts that are not priority deliverables in +the 2026-08-22 roadmap (some, such as streamed results, appear only in its framing). They are not cancelled upstream — WGs keep working outside the priority areas — but the roadmap says SEPs outside those areas "expect a longer queue", so **we do not schedule build work for them this horizon**. Each keeps a tracking issue and a liaison. @@ -306,7 +306,7 @@ work for them this horizon**. Each keeps a tracking issue and a liaison. | **Primitive grouping** (IG) | Grouped sidebars | The **UX** half proceeds as Track B (§5.10) on client-side heuristics; no spec data source is expected this horizon. | | **Streamed and reference results** | Incremental rendering, reference handles | 🔴 Watch. Planned payload truncation (§5.10) will cover the large-result case; result views render full payloads today. | | **File picker from `FileInputDescriptor`** (SEP-2356) | `SchemaForm` + elicitation picker | 🔴 Watch. The File Uploads WG's published direction is now filesystem-like resources (§3.4). | -| **Gateways, audit trails, configuration portability** | Gateway mode; OTLP as spec work | Gateway mode dropped. OTLP and the audit transcript continue as Track B (§5.7); rich server configuration and registry browsing (#1857) continue in §5.9. | +| **Gateways, audit trails** | Gateway mode; OTLP as spec work | Gateway mode dropped. OTLP and the audit transcript continue as Track B (§5.7). (Secure server configuration is not off the roadmap: it is a "Beyond" item, §3.2; our rich server configuration and registry browsing, #1857, continue in §5.9.) | --- @@ -321,19 +321,19 @@ official status through the Extensions Track of [SEP-2133](https://modelcontextprotocol.io/seps/2133-extensions), optionally after incubating in an `experimental-ext-*` repository (encouraged, not required). -### Current support (as of 2026-09-16) +### Current support (as of 2026-09-17) | Extension | Identifier | Web | CLI | TUI | Upstream matrix | Notes | | -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | MCP Apps | `io.modelcontextprotocol/ui` | ✅ | 🟡 | — | Inspector row, cell blank | Apps tab. Columns are rendering support: rendering needs a browser, so the CLI has only the `--app-info` metadata probe and the TUI nothing. The shared client still advertises the extension from CLI and TUI, which is a compatibility bug tracked in [#2403](https://github.com/modelcontextprotocol/inspector/issues/2403). | -| Tasks | `io.modelcontextprotocol/tasks` | ✅ | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). CLI and TUI advertise the extension and the shared core supports it, but neither exposes a user-facing task surface: the CLI's one-shot mode rejects `tasks/*`, and the TUI has no Tasks pane. | +| Tasks | `io.modelcontextprotocol/tasks` | 🟡 | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). Web is partial until #1917 ships: modern `tasks/*` requests omit the required `Mcp-Name` header, so strict servers reject them. CLI and TUI advertise the extension and the shared core supports it, but neither exposes a user-facing task surface: the CLI's one-shot mode rejects `tasks/*`, and the TUI has no Tasks pane. | | Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | | Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | ✅ | ✅ | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). | | OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | Inspector row, cell blank | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | **Actions:** implement OAuth Client Credentials; and, with maintainer sign-off, open a PR on -`modelcontextprotocol/modelcontextprotocol` to update the Inspector row. That matrix has one row per client, -so it cannot show per-client support: mark Apps as partial with a link explaining the split (Apps renders in +`modelcontextprotocol/modelcontextprotocol` to update the Inspector row. That matrix has one row per product, +so it cannot represent the Inspector's separate Web, CLI and TUI clients: mark Apps as partial with a link explaining the split (Apps renders in Web only; the CLI has a metadata probe), or propose separate Web/CLI/TUI rows. Skills and Enterprise Auth can be plain checks. ### Keeping up as extensions are approved @@ -342,8 +342,9 @@ We picked up Skills because someone noticed, not because anything told us. Make mechanism, the way SDK releases already are: - **An extension-watch sweep**, modelled on `scripts/sdk-watch.mjs`: on a schedule, list the - org's `ext-*` and `experimental-ext-*` repositories and the extension identifiers on - `/extensions/overview`, and file one issue per entry it has not filed before. As in the SDK watch, the **issue markers + org's `ext-*` and `experimental-ext-*` repositories, use `/extensions/overview` for official + membership and read each extension's identifier from its own specification or repository (the + overview lists names and links, not identifiers), and file one issue per entry it has not filed before. As in the SDK watch, the **issue markers are the source of truth** for idempotency: an entry whose marker is on an existing issue (open or closed) authored by the automation is skipped, so nothing needs committing back. It **files issues, never PRs**. Two details are left to the sweep's own design issue: which labels a trusted @@ -546,7 +547,7 @@ _The items whose shape we cannot yet commit to, plus the multiplier._ - 🅐 **DPoP**, **token exchange**, **Workload Identity Federation** (§3.3) — as each reaches Final or a Tier-1 SDK impl - 🅐 **Server-initiated events receiver** (§3.1) — design throughout, build only if the SEP lands -- 🅐 **ETags** (§3.2); **extension contract validation** (§3.5) +- 🅐 **ETags** (§3.2), only if a SEP reaches Draft with an SDK impl; **extension contract validation** (§3.5), only once the contract is published - 🅑 **Plugin architecture** (§5.14) — designed against surfaces that now exist - 🅑 Workspace and layout (§5.11); onboarding (§5.13) From 1a6df1450170aa85ed3b89e7054d2f78b79e6a04 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 12:10:15 -0400 Subject: [PATCH 12/17] docs: address Copilot round 10 on the roadmap realignment (#2401 review) Make #1917 a three-client Tasks limitation, mark CLI/TUI EMA partial, add modern skills/get to the cache surfaces (#2404), link SEP-1932/1933, keep spill-to-disk so capped history still reaches the session file, and qualify Track B's no-dependency claim. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 6e45fa62da..a03ca2eee3 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -193,7 +193,7 @@ where the Inspector is thinnest over the SDK. Watch closely. | Feature | Confidence | Notes | | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Cache hint display** — `ttlMs` / `cacheScope` on the SEP-2549 surfaces (`tools/list`, `prompts/list`, `resources/list`, `resources/templates/list`, `resources/read`), plus modern (2026-07-28+) `skills/list`, which SEP-2640 requires to carry both fields; legacy `skills/list` and `skills/get` carry none, with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. The runtime parses the hints everywhere and honors them through the SDK cache for the four `*/list` methods; `resources/read` and `skills/list` go through plain requests that validate but do not honor them, so this item includes that plumbing as well as the display. | +| **Cache hint display** — `ttlMs` / `cacheScope` on the SEP-2549 surfaces (`tools/list`, `prompts/list`, `resources/list`, `resources/templates/list`, `resources/read`), plus modern (2026-07-28+) `skills/list` and `skills/get`, which the stable ext-skills spec requires to carry both fields (our `skills/get` validation still treats them as optional: [#2404](https://github.com/modelcontextprotocol/inspector/issues/2404)); legacy results carry none, with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. The runtime parses the hints everywhere and honors them through the SDK cache for the four `*/list` methods; `resources/read`, `skills/list` and `skills/get` go through plain requests that validate but do not honor them, so this item includes that plumbing as well as the display. | | **Cache behavior observations** — note a re-fetch of a still-fresh result, and a list that changed inside its declared TTL, as diagnostics rather than errors | 🟢 | Inspector-shaped: nobody else observes both the hint and the reality. `ttlMs` is a freshness hint, so both are compliant. | | **Stateful-tool workflow investigation** — how to help a user carry an SEP-2567-style handle from one tool result into the next call | 🟡 | Replaces the first draft's "session lifecycle lane". The protocol has no concept of a handle (it is ordinary tool data), so a generic view would be inference; investigate before designing. | | **ETag support** — send `If-None-Match`, show 304s and version changes | 🔴 | Watch until a SEP reaches Draft with an SDK impl. | @@ -205,7 +205,7 @@ where the Inspector is thinnest over the SDK. Watch closely. **Upstream:** Agent Identity WG (forming this period), coordinated with the IETF OAuth and WIMSE WGs. MCP authorization assumes a person at a browser; increasingly the caller is an agent. This period: **finalize DPoP** and drive adoption; an opinionated **agent identity and -delegation** model built on **Workload Identity Federation** (SEP-1933), **ID-JAG** as used by +delegation** model built on **Workload Identity Federation** ([SEP-1933](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/1933)), **ID-JAG** as used by Enterprise-Managed Authorization, and **RFC 8693 token exchange**. **Beyond:** human-presence attestation. @@ -220,7 +220,7 @@ transcript are still worth building, but as our own Track B work (§5.7), not as | -------------------------------------------------------------------------------------------------- | ---------- | ----------------------------------------------------------------------------------------------- | | **OAuth Client Credentials extension** — client-secret and JWT-bearer assertion flows | 🟢 | An **approved** official extension (§4) we do not support. No upstream dependency. | | **Token exchange (RFC 8693) test flow** | 🟡 | Named in the roadmap; the RFC is stable, the MCP profile of it is not. | -| **DPoP** — generate a proof key, send `DPoP` proofs, show proof/nonce exchange in the Network view | 🟡 | Design against SEP-1932; build when it is Final or has a Tier-1 SDK impl. | +| **DPoP** — generate a proof key, send `DPoP` proofs, show proof/nonce exchange in the Network view | 🟡 | Design against [SEP-1932](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/1932); build when it is Final or has a Tier-1 SDK impl. | | **Workload Identity Federation** | 🟡 | SEP-1933. Needs a way to present a workload credential from a developer machine — design first. | | **Human-presence attestation** | 🔴 | "Beyond". | @@ -326,9 +326,9 @@ official status through the Extensions Track of | Extension | Identifier | Web | CLI | TUI | Upstream matrix | Notes | | -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | MCP Apps | `io.modelcontextprotocol/ui` | ✅ | 🟡 | — | Inspector row, cell blank | Apps tab. Columns are rendering support: rendering needs a browser, so the CLI has only the `--app-info` metadata probe and the TUI nothing. The shared client still advertises the extension from CLI and TUI, which is a compatibility bug tracked in [#2403](https://github.com/modelcontextprotocol/inspector/issues/2403). | -| Tasks | `io.modelcontextprotocol/tasks` | 🟡 | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). Web is partial until #1917 ships: modern `tasks/*` requests omit the required `Mcp-Name` header, so strict servers reject them. CLI and TUI advertise the extension and the shared core supports it, but neither exposes a user-facing task surface: the CLI's one-shot mode rejects `tasks/*`, and the TUI has no Tasks pane. | +| Tasks | `io.modelcontextprotocol/tasks` | 🟡 | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). All three clients are partial until #1917 ships: the shared `InspectorClient` issues modern `tasks/*` requests without the required `Mcp-Name` header, so strict servers reject them. Separately, CLI and TUI advertise the extension and the shared core supports it, but neither exposes a user-facing task surface: the CLI's one-shot mode rejects `tasks/*`, and the TUI has no Tasks pane. | | Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | -| Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | ✅ | ✅ | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). | +| Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | 🟡 | 🟡 | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). CLI and TUI work only from hand-edited `client.json` / `mcp.json`: there is no Client Settings surface, and terminal EMA follow-ups remain (`specification/v2_auth_ema.md`). | | OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | Inspector row, cell blank | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | **Actions:** implement OAuth Client Credentials; and, with maintainer sign-off, open a PR on @@ -361,7 +361,7 @@ mechanism, the way SDK releases already are: ## 5. Track B — experience work we choose -Nothing in this section waits on a SEP or another project. Ordered by leverage, not by effort. +No item here waits on a SEP or another project to **start**. Some later parts depend on each other or on Track A (for example, cross-server timeline correlation needs §5.11, and the assertion engine is shared with §3.6). Ordered by leverage, not by effort. ### 5.1 The zoomable timeline (headline) @@ -472,7 +472,7 @@ A 1000-tool server or a long-running session should not degrade. - **Grouped / tree lists with group-aware search**, built on client-side heuristics (name prefixes, annotations). No spec data source is expected this horizon (§3.7). -- **Virtualize** the long lists and logs; cap in-memory protocol history; truncate large +- **Virtualize** the long lists and logs; cap in-memory protocol history with spill-to-disk, so evicted entries still reach the §5.2 session file; truncate large payloads by default with explicit expansion. - Design lists so **"not loaded yet" is a state**, ready for progressive discovery (§3.4). From 8be1cd6f168de978a139520f33423ab1bcb99420 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 12:28:21 -0400 Subject: [PATCH 13/17] docs: address Copilot round 11 on the roadmap realignment (#2401 review) Split the Tasks row's two partial-support reasons (the Streamable-HTTP-only Mcp-Name gap fixed by #1917, and the CLI/TUI surface gap it does not fix), describe the CLI/TUI EMA limitation as a missing settings surface, name #1225's v1 closure in the sweep bootstrap, and cite SEP-414. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index a03ca2eee3..23fb7f5d82 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -326,9 +326,9 @@ official status through the Extensions Track of | Extension | Identifier | Web | CLI | TUI | Upstream matrix | Notes | | -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | MCP Apps | `io.modelcontextprotocol/ui` | ✅ | 🟡 | — | Inspector row, cell blank | Apps tab. Columns are rendering support: rendering needs a browser, so the CLI has only the `--app-info` metadata probe and the TUI nothing. The shared client still advertises the extension from CLI and TUI, which is a compatibility bug tracked in [#2403](https://github.com/modelcontextprotocol/inspector/issues/2403). | -| Tasks | `io.modelcontextprotocol/tasks` | 🟡 | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). All three clients are partial until #1917 ships: the shared `InspectorClient` issues modern `tasks/*` requests without the required `Mcp-Name` header, so strict servers reject them. Separately, CLI and TUI advertise the extension and the shared core supports it, but neither exposes a user-facing task surface: the CLI's one-shot mode rejects `tasks/*`, and the TUI has no Tasks pane. | +| Tasks | `io.modelcontextprotocol/tasks` | 🟡 | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). All three clients are currently partial, for two separate reasons. (1) Over Streamable HTTP, the shared `InspectorClient` sends modern `tasks/*` requests without the `Mcp-Name` header SEP-2663 requires, so strict servers reject them; stdio is unaffected. This is fixed by #1917. (2) CLI and TUI have no user-facing task surface: `mcp-inspector --cli` rejects `tasks/*` (they are not in `ONE_SHOT_METHODS`), and the TUI has no Tasks pane. #1917 does not change that. | | Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | -| Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | 🟡 | 🟡 | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). CLI and TUI work only from hand-edited `client.json` / `mcp.json`: there is no Client Settings surface, and terminal EMA follow-ups remain (`specification/v2_auth_ema.md`). | +| Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | 🟡 | 🟡 | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). CLI and TUI have no in-client Client Settings surface; they consume the `client.json` / `mcp.json` and keychain state the web settings flows write (or hand-edited files), and terminal EMA follow-ups remain (`specification/v2_auth_ema.md`). | | OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | Inspector row, cell blank | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | **Actions:** implement OAuth Client Credentials; and, with maintainer sign-off, open a PR on @@ -349,7 +349,7 @@ mechanism, the way SDK releases already are: closed) authored by the automation is skipped, so nothing needs committing back. It **files issues, never PRs**. Two details are left to the sweep's own design issue: which labels a trusted marker issue must also carry (as `sdk-watch` requires), and the first-run bootstrap for extensions - already tracked by hand-filed issues (Apps #1740, Tasks #1887, Skills #2234, EMA #1509), so that it does not file duplicates. + already tracked by hand-filed issues (Apps #1740, Tasks #1887, Skills #2234, EMA #1509), so that it does not file duplicates. OAuth Client Credentials is the exception: its only hand-filed issue, #1225, was closed on the frozen v1 line, so a new v2 issue is filed for it deliberately, cross-referencing #1225. - **Official extension** → a `v2` + `enhancement` issue to implement it, filed with the current milestone as `sdk-watch` does; only when no dated milestone is open is it left unmilestoned for triage to place in Incoming. - **Experimental extension** → a `v2` + `question` tracking issue, filed **unmilestoned and unboarded** so triage places it in Incoming (the documented exception for unapproved work); it @@ -612,7 +612,7 @@ For WG discussion. - [MCP Roadmap](https://modelcontextprotocol.io/development/roadmap) (last updated 2026-08-22) - [Extensions overview](https://modelcontextprotocol.io/extensions/overview) · [Extension support matrix](https://modelcontextprotocol.io/extensions/client-matrix) · [SEP-2133: Extensions](https://modelcontextprotocol.io/seps/2133-extensions) -- Final SEPs cited: [SEP-2549 (TTL for list results)](https://modelcontextprotocol.io/seps/2549-TTL-for-list-results) · [SEP-2567 (sessionless)](https://modelcontextprotocol.io/seps/2567-sessionless-mcp) · [SEP-2575 (stateless)](https://modelcontextprotocol.io/seps/2575-stateless-mcp) · [SEP-2663 (Tasks extension)](https://modelcontextprotocol.io/seps/2663-tasks-extension) · [SEP-2640 (Skills extension)](https://modelcontextprotocol.io/seps/2640-skills-extension) · [SEP-2484 (conformance tests)](https://modelcontextprotocol.io/seps/2484-conformance-tests-required-for-final-seps) +- Final SEPs cited: [SEP-2549 (TTL for list results)](https://modelcontextprotocol.io/seps/2549-TTL-for-list-results) · [SEP-2567 (sessionless)](https://modelcontextprotocol.io/seps/2567-sessionless-mcp) · [SEP-2575 (stateless)](https://modelcontextprotocol.io/seps/2575-stateless-mcp) · [SEP-2663 (Tasks extension)](https://modelcontextprotocol.io/seps/2663-tasks-extension) · [SEP-2640 (Skills extension)](https://modelcontextprotocol.io/seps/2640-skills-extension) · [SEP-2484 (conformance tests)](https://modelcontextprotocol.io/seps/2484-conformance-tests-required-for-final-seps) · [SEP-414 (request `_meta`, trace context)](https://modelcontextprotocol.io/seps/414-request-meta) - WG charters: [Inspector V2](https://modelcontextprotocol.io/community/working-groups/inspector-v2) · [Triggers & Events](https://modelcontextprotocol.io/community/working-groups/triggers-events) · [Agents](https://modelcontextprotocol.io/community/working-groups/agents) · [Transports](https://modelcontextprotocol.io/community/working-groups/transports) · [File Uploads](https://modelcontextprotocol.io/community/working-groups/file-uploads) · [SDK](https://modelcontextprotocol.io/community/working-groups/sdk) - [SDK tiers and conformance testing](https://modelcontextprotocol.io/community/sdk-tiers) - Internal: [`specification/v2_new_spec_impact.md`](../specification/v2_new_spec_impact.md) · [`specification/v2_scope.md`](../specification/v2_scope.md) · [`specification/v2_ux_features.md`](../specification/v2_ux_features.md) From b4efb47193889aed67855a50eaa3100d7693fbf6 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 12:45:58 -0400 Subject: [PATCH 14/17] docs: address Copilot round 12 on the roadmap realignment (#2401 review) Index the roadmap in the README, add the unblocked-work section to the ToC, propose a Tasks column in the upstream matrix, scope SEP-2484 to observable behavior, cite SEP-2624 for Interceptors, and tie the Mcp-Name fix to the SDK release #1917 tracks. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- README.md | 1 + docs/inspector-roadmap-2026-h2.md | 9 +++++---- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 29b74bd93b..4543a2f3db 100644 --- a/README.md +++ b/README.md @@ -81,6 +81,7 @@ Each client has its own README with client-specific detail: | [Reviewing an MCP App](./docs/mcp-app-review.md) | The CLI-first → one-shot-web recipe for automated App-tool review | | [Smoke-testing an MCP server](./docs/cli-smoke-testing.md) | The connect → list → call → assert workflow for a shell or CI job: `--format json` + `jq`, the exit-code map, and keeping OAuth non-interactive | | [Launcher and config consolidation](./docs/launcher-config-consolidation-plan.md) | Why the launcher runs a client in-process rather than spawning it | +| [Roadmap, Aug 2026 → Feb 2027](./docs/inspector-roadmap-2026-h2.md) | The six-month plan: spec-following work aligned to the published MCP roadmap, official extension support, and the experience work we choose | ## Testing and the quality gate diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 23fb7f5d82..7f54725283 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -16,6 +16,7 @@ ## Table of Contents +- [Work we can start now, no external blockers](#work-we-can-start-now-no-external-blockers) - [1. Why this document exists](#1-why-this-document-exists) - [2. The two tracks](#2-the-two-tracks) - [3. Track A — following the spec](#3-track-a--following-the-spec) @@ -116,7 +117,7 @@ general surfaces early so the spec work that lands later is cheap to display.** Worth stating plainly, because it shapes the priorities below. The roadmap's SDK area makes the **conformance test suite** the source of truth that SDKs and quickstarts are validated -against, and SEP-2484 (Final) requires conformance tests for Standards Track SEPs to reach +against, and SEP-2484 (Final) requires conformance tests for Standards Track SEPs that change observable protocol behavior to reach Final. The Inspector is the most visible MCP client in the ecosystem and is already the thing people reach for when a server misbehaves. @@ -302,7 +303,7 @@ work for them this horizon**. Each keeps a tracking issue and a liaison. | Effort | First-draft plan | Now | | ----------------------------------------------------- | ------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------- | | **Server Cards** (SEP-2127) | Card preview, card-vs-reality diff, `--card-lint` in Phase 3 | 🔴 Watch. [#1857](https://github.com/modelcontextprotocol/inspector/issues/1857)'s **registry** half does not depend on it (§5.9). | -| **Interceptors** (SEP-1763) | Test bench, audit mode, CLI invocation in Phase 4 | 🔴 Watch. The WG's unowned "CLI client for interceptor invocation" is still worth raising (§8). | +| **Interceptors** ([SEP-2624](https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2624); originally SEP-1763) | Test bench, audit mode, CLI invocation in Phase 4 | 🔴 Watch. The WG's unowned "CLI client for interceptor invocation" is still worth raising (§8). | | **Primitive grouping** (IG) | Grouped sidebars | The **UX** half proceeds as Track B (§5.10) on client-side heuristics; no spec data source is expected this horizon. | | **Streamed and reference results** | Incremental rendering, reference handles | 🔴 Watch. Planned payload truncation (§5.10) will cover the large-result case; result views render full payloads today. | | **File picker from `FileInputDescriptor`** (SEP-2356) | `SchemaForm` + elicitation picker | 🔴 Watch. The File Uploads WG's published direction is now filesystem-like resources (§3.4). | @@ -326,7 +327,7 @@ official status through the Extensions Track of | Extension | Identifier | Web | CLI | TUI | Upstream matrix | Notes | | -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | MCP Apps | `io.modelcontextprotocol/ui` | ✅ | 🟡 | — | Inspector row, cell blank | Apps tab. Columns are rendering support: rendering needs a browser, so the CLI has only the `--app-info` metadata probe and the TUI nothing. The shared client still advertises the extension from CLI and TUI, which is a compatibility bug tracked in [#2403](https://github.com/modelcontextprotocol/inspector/issues/2403). | -| Tasks | `io.modelcontextprotocol/tasks` | 🟡 | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). All three clients are currently partial, for two separate reasons. (1) Over Streamable HTTP, the shared `InspectorClient` sends modern `tasks/*` requests without the `Mcp-Name` header SEP-2663 requires, so strict servers reject them; stdio is unaffected. This is fixed by #1917. (2) CLI and TUI have no user-facing task surface: `mcp-inspector --cli` rejects `tasks/*` (they are not in `ONE_SHOT_METHODS`), and the TUI has no Tasks pane. #1917 does not change that. | +| Tasks | `io.modelcontextprotocol/tasks` | 🟡 | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). All three clients are currently partial, for two separate reasons. (1) Over Streamable HTTP, the shared `InspectorClient` sends modern `tasks/*` requests without the `Mcp-Name` header SEP-2663 requires, so strict servers reject them; stdio is unaffected. It is fixed once the upstream SDK change tracked by #1917 is released. (2) CLI and TUI have no user-facing task surface: `mcp-inspector --cli` rejects `tasks/*` (they are not in `ONE_SHOT_METHODS`), and the TUI has no Tasks pane. #1917 does not change that. | | Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | | Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | 🟡 | 🟡 | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). CLI and TUI have no in-client Client Settings surface; they consume the `client.json` / `mcp.json` and keychain state the web settings flows write (or hand-edited files), and terminal EMA follow-ups remain (`specification/v2_auth_ema.md`). | | OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | Inspector row, cell blank | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | @@ -334,7 +335,7 @@ official status through the Extensions Track of **Actions:** implement OAuth Client Credentials; and, with maintainer sign-off, open a PR on `modelcontextprotocol/modelcontextprotocol` to update the Inspector row. That matrix has one row per product, so it cannot represent the Inspector's separate Web, CLI and TUI clients: mark Apps as partial with a link explaining the split (Apps renders in -Web only; the CLI has a metadata probe), or propose separate Web/CLI/TUI rows. Skills and Enterprise Auth can be plain checks. +Web only; the CLI has a metadata probe), or propose separate Web/CLI/TUI rows. Skills and Enterprise Auth can be plain checks. The same PR should propose a **Tasks** column: Tasks is an official extension the matrix cannot currently represent at all. ### Keeping up as extensions are approved From 4bc4643dcd59b534cd3e400cc0fef173443bf5b3 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 13:06:42 -0400 Subject: [PATCH 15/17] docs: address Copilot round 13 on the roadmap realignment (#2401 review) Scope the spec-baseline exception to the base protocol, stop overstating the connection fixes, and make the extensions overview the authoritative official set for the extension-watch sweep. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 7f54725283..b1a1160038 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -56,7 +56,7 @@ Through v1, the Inspector was a **follow-along project**. The spec moved, we cha whatever planning capacity remained went to keeping up rather than to the tool's own design. Every release was reactive by necessity. -That constraint has lifted. v2 meets the 2026-07-28 spec across all three clients (one known exception, #1917, waits on an SDK release), on SDK v2, +That constraint has lifted. v2 meets the 2026-07-28 spec across all three clients (one known base-protocol exception, #1917, waits on an SDK release; open extension gaps are tracked in §4), on SDK v2, with a shared `core/`, a ≥90% per-file coverage gate, and a smoke/e2e apparatus that catches packaging failures. For the first time we can spend planned effort on **what the Inspector should be**, not only on what the spec just became. @@ -342,9 +342,10 @@ Web only; the CLI has a metadata probe), or propose separate Web/CLI/TUI rows. S We picked up Skills because someone noticed, not because anything told us. Make it a mechanism, the way SDK releases already are: -- **An extension-watch sweep**, modelled on `scripts/sdk-watch.mjs`: on a schedule, list the - org's `ext-*` and `experimental-ext-*` repositories, use `/extensions/overview` for official - membership and read each extension's identifier from its own specification or repository (the +- **An extension-watch sweep**, modelled on `scripts/sdk-watch.mjs`: on a schedule, treat + `/extensions/overview` as the authoritative set of official extensions (Tasks, for one, has no + `ext-*` repository), enumerate the org's `experimental-ext-*` repositories to discover + experimental entries and `ext-*` repositories only to enrich official ones, and read each extension's identifier from its own specification or repository (the overview lists names and links, not identifiers), and file one issue per entry it has not filed before. As in the SDK watch, the **issue markers are the source of truth** for idempotency: an entry whose marker is on an existing issue (open or closed) authored by the automation is skipped, so nothing needs committing back. It **files @@ -453,7 +454,7 @@ but we hold the entire session and cannot export it in any pipeline-shaped form. ### 5.8 Connection Doctor -The individual connection bugs have been fixed (§1), but a failure is still reported as a +The connection fixes listed in §1 have shipped (and #1944 and #1911 were closed as not planned), but a failure is still reported as a single error. Run an ordered checklist on failure — DNS · TCP · TLS (including local-cert cases) · `/.well-known` discovery · protocol version negotiation · auth — and report **which step failed and what to do about it**. First-connection success is the entire first impression From 85f4ecc165921e7d8c4742b11a56c248ecb96350 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 13:22:56 -0400 Subject: [PATCH 16/17] docs: address Copilot round 14 on the roadmap realignment (#2401 review) Label #1917 a Tasks-extension gap, date the revision 2026-09-17, show legacy cache hints when present, make the Apps columns strictly about rendering, and define Skills checks as inspection support (the Inspector is not a host). Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index b1a1160038..9a85d0b55f 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -6,7 +6,7 @@ **Horizon:** 2026-08-11 → 2027-02-11 (~26 weekly milestones, `v2.2.0` → ~`v2.27.0`) **Owner:** [Inspector V2 WG](https://modelcontextprotocol.io/community/working-groups/inspector-v2) -**Status:** Draft for WG review — **revised 2026-09-16** against the published MCP roadmap of 2026-08-22 (#2400) +**Status:** Draft for WG review — **revised 2026-09-17** against the published MCP roadmap of 2026-08-22 (#2400) ## Work we can start now, no external blockers @@ -56,7 +56,7 @@ Through v1, the Inspector was a **follow-along project**. The spec moved, we cha whatever planning capacity remained went to keeping up rather than to the tool's own design. Every release was reactive by necessity. -That constraint has lifted. v2 meets the 2026-07-28 spec across all three clients (one known base-protocol exception, #1917, waits on an SDK release; open extension gaps are tracked in §4), on SDK v2, +That constraint has lifted. v2 meets the 2026-07-28 spec across all three clients (the open gaps are in official extensions, not the base protocol: the Tasks-extension `Mcp-Name` header, #1917, waits on an SDK release, and the rest are tracked in §4), on SDK v2, with a shared `core/`, a ≥90% per-file coverage gate, and a smoke/e2e apparatus that catches packaging failures. For the first time we can spend planned effort on **what the Inspector should be**, not only on what the spec just became. @@ -194,7 +194,7 @@ where the Inspector is thinnest over the SDK. Watch closely. | Feature | Confidence | Notes | | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Cache hint display** — `ttlMs` / `cacheScope` on the SEP-2549 surfaces (`tools/list`, `prompts/list`, `resources/list`, `resources/templates/list`, `resources/read`), plus modern (2026-07-28+) `skills/list` and `skills/get`, which the stable ext-skills spec requires to carry both fields (our `skills/get` validation still treats them as optional: [#2404](https://github.com/modelcontextprotocol/inspector/issues/2404)); legacy results carry none, with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. The runtime parses the hints everywhere and honors them through the SDK cache for the four `*/list` methods; `resources/read`, `skills/list` and `skills/get` go through plain requests that validate but do not honor them, so this item includes that plumbing as well as the display. | +| **Cache hint display** — `ttlMs` / `cacheScope` on the SEP-2549 surfaces (`tools/list`, `prompts/list`, `resources/list`, `resources/templates/list`, `resources/read`), plus modern (2026-07-28+) `skills/list` and `skills/get`, which the stable ext-skills spec requires to carry both fields (our `skills/get` validation still treats them as optional: [#2404](https://github.com/modelcontextprotocol/inspector/issues/2404)); legacy results do not require the fields but are shown when a server sends them, with freshness countdown and "stale" marking | 🟢 | SEP-2549 is Final. The runtime parses the hints everywhere and honors them through the SDK cache for the four `*/list` methods; `resources/read`, `skills/list` and `skills/get` go through plain requests that validate but do not honor them, so this item includes that plumbing as well as the display. | | **Cache behavior observations** — note a re-fetch of a still-fresh result, and a list that changed inside its declared TTL, as diagnostics rather than errors | 🟢 | Inspector-shaped: nobody else observes both the hint and the reality. `ttlMs` is a freshness hint, so both are compliant. | | **Stateful-tool workflow investigation** — how to help a user carry an SEP-2567-style handle from one tool result into the next call | 🟡 | Replaces the first draft's "session lifecycle lane". The protocol has no concept of a handle (it is ordinary tool data), so a generic view would be inference; investigate before designing. | | **ETag support** — send `If-None-Match`, show 304s and version changes | 🔴 | Watch until a SEP reaches Draft with an SDK impl. | @@ -326,16 +326,16 @@ official status through the Extensions Track of | Extension | Identifier | Web | CLI | TUI | Upstream matrix | Notes | | -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| MCP Apps | `io.modelcontextprotocol/ui` | ✅ | 🟡 | — | Inspector row, cell blank | Apps tab. Columns are rendering support: rendering needs a browser, so the CLI has only the `--app-info` metadata probe and the TUI nothing. The shared client still advertises the extension from CLI and TUI, which is a compatibility bug tracked in [#2403](https://github.com/modelcontextprotocol/inspector/issues/2403). | +| MCP Apps | `io.modelcontextprotocol/ui` | ✅ | — | — | Inspector row, cell blank | Apps tab. Columns are rendering support: rendering needs a browser, so neither CLI nor TUI renders Apps (the CLI does offer an `--app-info` metadata probe). The shared client still advertises the extension from CLI and TUI, which is a compatibility bug tracked in [#2403](https://github.com/modelcontextprotocol/inspector/issues/2403). | | Tasks | `io.modelcontextprotocol/tasks` | 🟡 | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). All three clients are currently partial, for two separate reasons. (1) Over Streamable HTTP, the shared `InspectorClient` sends modern `tasks/*` requests without the `Mcp-Name` header SEP-2663 requires, so strict servers reject them; stdio is unaffected. It is fixed once the upstream SDK change tracked by #1917 is released. (2) CLI and TUI have no user-facing task surface: `mcp-inspector --cli` rejects `tasks/*` (they are not in `ONE_SHOT_METHODS`), and the TUI has no Tasks pane. #1917 does not change that. | -| Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). | +| Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). Checks mean full **inspection** support (list, get, digest verification). Host behaviors (activation, per-skill consent, content-bound approval) are out of scope by design, since the Inspector is not a host (`core/mcp/skills.ts`); that is also why the upstream matrix says "Partial". | | Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | 🟡 | 🟡 | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). CLI and TUI have no in-client Client Settings surface; they consume the `client.json` / `mcp.json` and keychain state the web settings flows write (or hand-edited files), and terminal EMA follow-ups remain (`specification/v2_auth_ema.md`). | | OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | Inspector row, cell blank | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. | **Actions:** implement OAuth Client Credentials; and, with maintainer sign-off, open a PR on `modelcontextprotocol/modelcontextprotocol` to update the Inspector row. That matrix has one row per product, so it cannot represent the Inspector's separate Web, CLI and TUI clients: mark Apps as partial with a link explaining the split (Apps renders in -Web only; the CLI has a metadata probe), or propose separate Web/CLI/TUI rows. Skills and Enterprise Auth can be plain checks. The same PR should propose a **Tasks** column: Tasks is an official extension the matrix cannot currently represent at all. +Web only; the CLI has a metadata probe), or propose separate Web/CLI/TUI rows. Enterprise Auth can be a plain check; Skills stays "Partial" upstream, because the Inspector is not a host. The same PR should propose a **Tasks** column: Tasks is an official extension the matrix cannot currently represent at all. ### Keeping up as extensions are approved From d7c1f9fb4d5a958e1cb1f7a6a380841db98657c5 Mon Sep 17 00:00:00 2001 From: cliffhall Date: Thu, 17 Sep 2026 13:41:38 -0400 Subject: [PATCH 17/17] docs: address Copilot round 15 on the roadmap realignment (#2401 review) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Scope §3.6's SEP-2484 restatement to observable protocol behavior, and name the open modern skills/get validation gap (#2404) in the Skills row. Co-Authored-By: Claude Opus 5 (1M context) Signed-off-by: cliffhall --- docs/inspector-roadmap-2026-h2.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/inspector-roadmap-2026-h2.md b/docs/inspector-roadmap-2026-h2.md index 9a85d0b55f..62a0a3a49a 100644 --- a/docs/inspector-roadmap-2026-h2.md +++ b/docs/inspector-roadmap-2026-h2.md @@ -279,7 +279,7 @@ conformance suite central, which strengthens §3.6. **Upstream:** Standing investment rather than a priority area — the conformance suite, SDK tiers ([SEP-1730](https://modelcontextprotocol.io/seps/1730-sdks-tiering-system)), and [SEP-2484](https://modelcontextprotocol.io/seps/2484-conformance-tests-required-for-final-seps) -(Final), which requires conformance tests for Standards Track SEPs to reach Final. §3.5 makes +(Final), which requires conformance tests for Standards Track SEPs that change observable protocol behavior to reach Final. §3.5 makes the suite the validation target for generated SDKs. **Read:** A conformance suite needs a driver and a report. We are the natural driver, and we @@ -328,7 +328,7 @@ official status through the Extensions Track of | -------------------------------- | ---------------------------------------------------------- | --- | --- | --- | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | MCP Apps | `io.modelcontextprotocol/ui` | ✅ | — | — | Inspector row, cell blank | Apps tab. Columns are rendering support: rendering needs a browser, so neither CLI nor TUI renders Apps (the CLI does offer an `--app-info` metadata probe). The shared client still advertises the extension from CLI and TUI, which is a compatibility bug tracked in [#2403](https://github.com/modelcontextprotocol/inspector/issues/2403). | | Tasks | `io.modelcontextprotocol/tasks` | 🟡 | 🟡 | 🟡 | No column in the matrix | Raw-wire channel; stays for the horizon (§3.1). All three clients are currently partial, for two separate reasons. (1) Over Streamable HTTP, the shared `InspectorClient` sends modern `tasks/*` requests without the `Mcp-Name` header SEP-2663 requires, so strict servers reject them; stdio is unaffected. It is fixed once the upstream SDK change tracked by #1917 is released. (2) CLI and TUI have no user-facing task surface: `mcp-inspector --cli` rejects `tasks/*` (they are not in `ONE_SHOT_METHODS`), and the TUI has no Tasks pane. #1917 does not change that. | -| Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). Checks mean full **inspection** support (list, get, digest verification). Host behaviors (activation, per-skill consent, content-bound approval) are out of scope by design, since the Inspector is not a host (`core/mcp/skills.ts`); that is also why the upstream matrix says "Partial". | +| Skills over MCP | `io.modelcontextprotocol/skills` | ✅ | ✅ | ✅ | "Partial" (CLI README) | [#2234](https://github.com/modelcontextprotocol/inspector/issues/2234), [#2248](https://github.com/modelcontextprotocol/inspector/issues/2248). Checks mean the inspection surface is complete (list, get, digest and frontmatter verification), with one open validation gap: modern `skills/get` results missing the now-required cache fields are still accepted ([#2404](https://github.com/modelcontextprotocol/inspector/issues/2404)). Host behaviors (activation, per-skill consent, content-bound approval) are out of scope by design, since the Inspector is not a host (`core/mcp/skills.ts`); that is also why the upstream matrix says "Partial". | | Enterprise-Managed Authorization | `io.modelcontextprotocol/enterprise-managed-authorization` | ✅ | 🟡 | 🟡 | Inspector row, cell blank | [#1509](https://github.com/modelcontextprotocol/inspector/issues/1509). CLI and TUI have no in-client Client Settings surface; they consume the `client.json` / `mcp.json` and keychain state the web settings flows write (or hand-edited files), and terminal EMA follow-ups remain (`specification/v2_auth_ema.md`). | | OAuth Client Credentials | `io.modelcontextprotocol/oauth-client-credentials` | ❌ | ❌ | ❌ | Inspector row, cell blank | **Gap** (§3.3). [#1225](https://github.com/modelcontextprotocol/inspector/issues/1225) was closed only because v1 is frozen. |