Skip to content

Python SDK — Tier 1 Assessment #3267

Description

@maxisbey

Python SDK — Tier 1 Assessment

SDK: modelcontextprotocol/python-sdk
Version: 2.0.0 (GA 2026-07-28) · assessed on main @ 9057285 (2.0.0 plus documentation and policy files; no API changes)
Assessed: 2026-08-17
Requested tier: Tier 1 (unchanged — previous assessment #2304, v1.26.0, 2026-02-23)
Tool: @modelcontextprotocol/conformance tier-check 0.2.0-alpha.11 (conformance main @ 74edef3), --requirements 2025-11-25,2026-07-28, plus the mcp-sdk-tier-audit skill's documentation and policy evaluations

Result

All Tier 1 requirements are met. tier-check: "implied_tier": {"tier": 1, "tier1_blockers": [], "tier2_met": true}.

# Requirement Tier 1 Standard Value Status
1 Server Conformance 100% pass rate 67/67 scored (30/30 @ 2025-11-25 + 37/37 @ 2026-07-28)
2 Client Conformance 100% pass rate 50/50 scored (18/18 @ 2025-11-25 + 32/32 @ 2026-07-28)
3 Issue Triage Within 2 business days 99.5% (196/197); labels 12/12
4 P0 Resolution Within 7 days 0 open; 1/1 closed within 7d
5 Stable Release Required + clear versioning 2.0.0
6 Spec Tracking Before spec release 2.0.0 published 2026-07-28, 3h before the 2026-07-28 spec tag (0d gap)
7 Documentation Comprehensive w/ examples 48/48 features
8 Dependency Policy Published update policy DEPENDENCY_POLICY.md + dependabot.yml
9 Roadmap Published roadmap ROADMAP.md
10 Versioning Policy Documented breaking changes VERSIONING.md

Requirements Detail

1–2. Conformance — ✅ server 67/67, client 50/50

Scored against the frozen 2025-11-25 and 2026-07-28 requirement sets, each run at its own wire, with examples/servers/everything-server as the server under test and .github/actions/conformance/client.py as the client. The SDK's CI runs the same suites on every push to main (workflow; green run at the assessed commit).

Not scored (informational, all extension-tagged and listed in the SDK's expected-failures baseline): server tasks-* (SEP-2663 Tasks extension, not yet implemented — python-sdk#2806); client auth/dpop, auth/dpop-nonce, auth/wif-jwt-bearer (DPoP / jwt-bearer grant not yet implemented). Every dated scenario passes; the per-revision baselines (expected-failures.2025-11-25.yml, .2026-07-28.yml) are empty.

All 62 scored server scenarios
Scenario Status Checks Scored at
caching PASS 8/8 2026-07-28
completion-complete PASS 4/4 2025-11-25, 2026-07-28
dns-rebinding-protection PASS 4/4 2025-11-25, 2026-07-28
elicitation-sep1034-defaults PASS 6/6 2025-11-25
elicitation-sep1330-enums PASS 6/6 2025-11-25
http-custom-header-server-validation PASS 10/10 2026-07-28
http-header-validation PASS 14/14 2026-07-28
input-required-result-basic-elicitation PASS 3/3 2026-07-28
input-required-result-basic-list-roots PASS 3/3 2026-07-28
input-required-result-basic-sampling PASS 3/3 2026-07-28
input-required-result-capability-check PASS 2/2 2026-07-28
input-required-result-ignore-extra-params PASS 2/2 2026-07-28
input-required-result-missing-input-response PASS 2/2 2026-07-28
input-required-result-multi-round PASS 4/4 2026-07-28
input-required-result-multiple-input-requests PASS 3/3 2026-07-28
input-required-result-non-tool-request PASS 3/3 2026-07-28
input-required-result-request-state PASS 3/3 2026-07-28
input-required-result-result-type PASS 2/2 2026-07-28
input-required-result-tampered-state PASS 2/2 2026-07-28
input-required-result-unsupported-methods PASS 2/2 2026-07-28
input-required-result-validate-input PASS 3/3 2026-07-28
json-schema-2020-12 PASS 16/16 2025-11-25, 2026-07-28
logging-set-level PASS 2/2 2025-11-25
ping PASS 2/2 2025-11-25
prompts-get-embedded-resource PASS 4/4 2025-11-25, 2026-07-28
prompts-get-simple PASS 4/4 2025-11-25, 2026-07-28
prompts-get-with-args PASS 4/4 2025-11-25, 2026-07-28
prompts-get-with-image PASS 4/4 2025-11-25, 2026-07-28
prompts-list PASS 4/4 2025-11-25, 2026-07-28
resources-list PASS 4/4 2025-11-25, 2026-07-28
resources-read-binary PASS 4/4 2025-11-25, 2026-07-28
resources-read-text PASS 4/4 2025-11-25, 2026-07-28
resources-subscribe PASS 2/2 2025-11-25
resources-templates-read PASS 4/4 2025-11-25, 2026-07-28
resources-unsubscribe PASS 2/2 2025-11-25
sep-2164-resource-not-found PASS 4/4 2026-07-28
server-initialize PASS 3/3 2025-11-25
server-session-lifecycle PASS 3/3 2025-11-25
server-sse-multiple-streams PASS 3/3 2025-11-25, 2026-07-28
server-sse-polling PASS 3/3 2025-11-25
server-stateless PASS 30/30 2026-07-28
tasks-capability-negotiation FAIL 2/5 2026-07-28
tasks-dispatch-and-envelope FAIL 6/9 2026-07-28
tasks-lifecycle FAIL 2/9 2026-07-28
tasks-mrtr-composition FAIL 1/2 2026-07-28
tasks-mrtr-input FAIL 1/4 2026-07-28
tasks-request-headers FAIL 2/5 2026-07-28
tasks-request-state-removal FAIL 1/2 2026-07-28
tasks-required-task-error FAIL 1/2 2026-07-28
tasks-status-notifications FAIL 0/0 2026-07-28
tasks-wire-fields FAIL 1/4 2026-07-28
tools-call-audio PASS 4/4 2025-11-25, 2026-07-28
tools-call-elicitation PASS 2/2 2025-11-25
tools-call-embedded-resource PASS 4/4 2025-11-25, 2026-07-28
tools-call-error PASS 4/4 2025-11-25, 2026-07-28
tools-call-image PASS 4/4 2025-11-25, 2026-07-28
tools-call-mixed-content PASS 4/4 2025-11-25, 2026-07-28
tools-call-sampling PASS 2/2 2025-11-25
tools-call-simple-text PASS 4/4 2025-11-25, 2026-07-28
tools-call-with-logging PASS 2/2 2025-11-25
tools-call-with-progress PASS 4/4 2025-11-25, 2026-07-28
tools-list PASS 6/6 2025-11-25, 2026-07-28
All 42 scored client scenarios
Scenario Status Checks Scored at
auth/authorization-server-migration PASS 27/27 2026-07-28
auth/basic-cimd PASS 25/25 2025-11-25, 2026-07-28
auth/client-credentials-basic PASS 15/15 2025-11-25, 2026-07-28
auth/client-credentials-jwt PASS 15/15 2025-11-25, 2026-07-28
auth/dpop FAIL 19/25 2025-11-25, 2026-07-28
auth/dpop-nonce FAIL 19/29 2025-11-25, 2026-07-28
auth/enterprise-managed-authorization PASS 17/17 2025-11-25, 2026-07-28
auth/iss-normalized PASS 8/8 2026-07-28
auth/iss-not-advertised PASS 14/14 2026-07-28
auth/iss-supported PASS 14/14 2026-07-28
auth/iss-supported-missing PASS 8/8 2026-07-28
auth/iss-unexpected PASS 8/8 2026-07-28
auth/iss-wrong-issuer PASS 8/8 2026-07-28
auth/metadata-default PASS 26/26 2025-11-25, 2026-07-28
auth/metadata-issuer-mismatch PASS 3/3 2026-07-28
auth/metadata-var1 PASS 26/26 2025-11-25, 2026-07-28
auth/metadata-var2 PASS 26/26 2025-11-25, 2026-07-28
auth/metadata-var3 PASS 26/26 2025-11-25, 2026-07-28
auth/offline-access-not-supported PASS 14/14 2026-07-28
auth/offline-access-scope PASS 12/12 2026-07-28
auth/pre-registration PASS 25/25 2025-11-25, 2026-07-28
auth/resource-mismatch PASS 2/2 2026-07-28
auth/scope-from-scopes-supported PASS 28/28 2025-11-25, 2026-07-28
auth/scope-from-www-authenticate PASS 28/28 2025-11-25, 2026-07-28
auth/scope-omitted-when-undefined PASS 28/28 2025-11-25, 2026-07-28
auth/scope-retry-limit PASS 21/21 2025-11-25, 2026-07-28
auth/scope-step-up PASS 43/43 2025-11-25, 2026-07-28
auth/token-endpoint-auth-basic PASS 36/36 2025-11-25, 2026-07-28
auth/token-endpoint-auth-none PASS 36/36 2025-11-25, 2026-07-28
auth/token-endpoint-auth-post PASS 36/36 2025-11-25, 2026-07-28
auth/wif-jwt-bearer FAIL 16/18 2025-11-25, 2026-07-28
elicitation-sep1034-client-defaults PASS 5/5 2025-11-25
http-custom-headers PASS 18/18 2026-07-28
http-invalid-tool-headers PASS 11/11 2026-07-28
http-standard-headers PASS 3/3 2026-07-28
initialize PASS 1/1 2025-11-25
json-schema-2020-12-preservation PASS 18/18 2025-11-25, 2026-07-28
json-schema-ref-no-deref PASS 1/1 2026-07-28
request-metadata PASS 8/8 2026-07-28
sep-2322-client-request-state PASS 5/5 2026-07-28
sse-retry PASS 3/3 2025-11-25
tools_call PASS 4/4 2025-11-25, 2026-07-28

3. Issue Triage — ✅ 99.5%

196 of 197 open issues carry a label (tier-check method); the one exception, #3309, was opened Fri 2026-08-14 21:34Z and was inside two business days at assessment time. All 12 taxonomy labels exist (labels); the triage commitment is published in CONTRIBUTING.md § Issue Triage.

4. P0 Resolution — ✅ 0 open

No open P0s. P0 history: #1442, closed in 3 days (all P0 issues).

5–6. Stable Release and Spec Tracking — ✅ 2.0.0

2.0.0 (PyPI) implements the 2026-07-28 revision and negotiates every earlier one; it was published 2026-07-28T13:41Z, the same day as the spec release (16:47Z). tier-check reports a 0-day gap on conformance main (which includes conformance#458, counting a release in the 24h before the spec tag); under the published 0.2.0-alpha.11 rule the same facts read as "20 days since spec, no release after it" and pass until day 30. The v1.x maintenance line released 1.29.0 the same day.

7. Documentation — ✅ 48/48

Documentation site: https://py.sdk.modelcontextprotocol.io/ (sources: docs/, runnable examples in docs_src/ included into the pages, plus examples/). All 48 non-experimental features from the audit's feature list have prose and an example; the five experimental Tasks features are not implemented (SEP-2663) and not required.

Per-feature evidence (48/48)
# Feature Docs Example
1 Tools - listing docs/servers/tools.md:19-35 docs_src/tools/tutorial001.py PASS
2 Tools - calling docs/client/index.md:80-133 docs_src/client/tutorial003.py:24-33 PASS
3 Tools - text results docs/servers/tools.md:43-52 docs_src/tools/tutorial001.py PASS
4 Tools - image results docs/servers/media.md:7-45 docs_src/media/tutorial001.py PASS
5 Tools - audio results docs/servers/media.md:46-61 docs_src/media/tutorial002.py:18-21 PASS
6 Tools - embedded resources docs/servers/media.md:84-100 docs_src/media/tutorial005.py:13-18 PASS
7 Tools - error handling docs/servers/handling-errors.md:1-80 docs_src/handling_errors/tutorial001.py PASS
8 Tools - change notifications docs/handlers/subscriptions.md:7-20 docs_src/subscriptions/tutorial001.py:29-33 PASS
9 Resources - listing docs/servers/resources.md:9-43 docs_src/resources/tutorial001.py PASS
10 Resources - reading text docs/servers/resources.md:34-38,99-121 docs_src/resources/tutorial001.py PASS
11 Resources - reading binary docs/servers/resources.md:117-121 docs_src/resources/tutorial003.py:20-23 PASS
12 Resources - templates docs/servers/resources.md:55-97 docs_src/resources/tutorial002.py:12-15 PASS
13 Resources - template reading docs/servers/resources.md:76-82 docs_src/client/tutorial004.py:28 PASS
14 Resources - subscribing docs/handlers/subscriptions.md:1-45 docs_src/subscriptions/tutorial001.py:17-21 PASS
15 Resources - unsubscribing docs/client/subscriptions.md:60,84 docs_src/subscriptions/tutorial004_anyio.py:14,18-23 PASS
16 Resources - change notifications docs/handlers/subscriptions.md:15-18 examples/stories/stickynotes/server.py:64,74,92 PASS
17 Prompts - listing docs/servers/prompts.md:15-33 docs_src/prompts/tutorial001.py PASS
18 Prompts - getting simple docs/servers/prompts.md:35-76 docs_src/prompts/tutorial001.py PASS
19 Prompts - getting with arguments docs/servers/prompts.md:110-134 docs_src/prompts/tutorial003.py PASS
20 Prompts - embedded resources docs/servers/prompts.md:141-159 docs_src/prompts/tutorial004.py:18-25 PASS
21 Prompts - image content docs/servers/prompts.md:161-172 docs_src/prompts/tutorial005.py:11-17 PASS
22 Prompts - change notifications docs/servers/prompts.md:174-184 docs_src/prompts/tutorial006.py:16-28 PASS
23 Sampling - creating messages docs/handlers/sampling-and-roots.md:10-21,36-38 docs_src/sampling_and_roots/tutorial001.py PASS
24 Elicitation - form mode docs/handlers/elicitation.md:7-111 docs_src/elicitation/tutorial001.py PASS
25 Elicitation - URL mode docs/handlers/elicitation.md:10,113-125 docs_src/elicitation/tutorial002.py:7-17 PASS
26 Elicitation - schema validation docs/handlers/elicitation.md:57-111 docs_src/elicitation/tutorial001.py:9-11,20-24 PASS
27 Elicitation - default values docs/handlers/elicitation.md:59-82 docs_src/elicitation/tutorial001.py:11 PASS
28 Elicitation - enum values docs/handlers/elicitation.md:84-86 examples/stories/legacy_elicitation/server_lowlevel.py:10-17 PASS
29 Elicitation - complete notification docs/handlers/elicitation.md:125 docs_src/elicitation/tutorial002.py:20-24 PASS
30 Roots - listing docs/handlers/sampling-and-roots.md:23-38 docs_src/sampling_and_roots/tutorial002.py PASS
31 Roots - change notifications docs/deprecated.md:77-100 docs/deprecated.md:81-86 PASS
32 Logging - sending log messages docs/handlers/logging.md:5 examples/snippets/servers/notifications.py:9-13 PASS
33 Logging - setting level docs/client/callbacks.md:136 docs/migration.md:2857-2860 PASS
34 Completions - resource argument docs/servers/completions.md:88-114 docs_src/completions/tutorial003.py:34-38 PASS
35 Completions - prompt argument docs/servers/completions.md:20-86 docs_src/completions/tutorial002.py:21-29 PASS
36 Ping docs/deprecated.md:14,21,53-75 docs/deprecated.md:57-61 PASS
37 Streamable HTTP transport (client) docs/client/transports.md:24-79 docs_src/client_transports/tutorial002.py PASS
38 Streamable HTTP transport (server) docs/run/index.md:54-84 docs_src/run/tutorial002.py PASS
39 SSE transport - legacy (client) docs/client/transports.md:103-105 examples/clients/simple-auth-client/mcp_simple_auth_client/main.py:226-233 PASS
40 SSE transport - legacy (server) docs/run/index.md:9-18 docs/migration.md:786-789 PASS
41 stdio transport (client) docs/client/transports.md:81-101 docs_src/client_transports/tutorial004.py PASS
42 stdio transport (server) docs/run/index.md:20-52 docs_src/run/tutorial001.py:12-13 PASS
43 Progress notifications docs/handlers/progress.md:1-115 docs_src/progress/tutorial001.py PASS
44 Cancellation docs/migration.md:1616-1622 examples/stories/streaming/client.py:36-52 PASS
45 Pagination docs/advanced/pagination.md:1-80 docs_src/pagination/tutorial001.py:15-19 PASS
46 Capability negotiation docs/client/callbacks.md:68-112 docs_src/client_callbacks/tutorial003.py:23-31 PASS
47 Protocol version negotiation docs/protocol-versions.md:1-125 docs_src/protocol_versions/tutorial001.py-tutorial004.py PASS
48 JSON Schema 2020-12 support docs/advanced/low-level-server.md:114-123 docs_src/lowlevel/tutorial007.py:4-17 PASS

8–10. Policies — ✅

  • Dependency policy: DEPENDENCY_POLICY.md (floors-only requirements, when a floor moves, automated updates) + .github/dependabot.yml (monthly grouped uv and Actions updates).
  • Roadmap: ROADMAP.md — organized by spec revision; links the 2026-07-28 project boards and the open items (capabilities API #2896, Tasks extension #2806, DPoP, jwt-bearer).
  • Versioning policy: VERSIONING.md — SemVer in PEP 440 syntax, the public-API boundary, what is and is not a breaking change, the two deprecation channels, supported release lines; breaking changes between majors are recorded in the Migration Guide.
  • Also: SECURITY.md (supported versions, reporting), CONTRIBUTING.md.

Reproduce This Assessment

git clone https://github.com/modelcontextprotocol/conformance.git && cd conformance
git checkout 74edef3 && npm install && npm run build      # 0.2.0-alpha.11 + #458
export GITHUB_TOKEN=$(gh auth token)

# Known-SDK mode: clones python-sdk main, starts the everything-server and
# drives .github/actions/conformance/client.py for each revision
node dist/index.js tier-check --sdk-path /path/to/python-sdk \
  --requirements 2025-11-25,2026-07-28 --output markdown

# or URL mode from a python-sdk checkout:
#   uv sync --frozen && uv run --frozen mcp-everything-server --port 3001 &
#   node dist/index.js tier-check --repo modelcontextprotocol/python-sdk --branch main \
#     --conformance-server-url http://localhost:3001/mcp \
#     --client-cmd 'uv run --frozen python .github/actions/conformance/client.py' \
#     --requirements 2025-11-25,2026-07-28 --timeout 60000 --output markdown

gh release view v2.0.0 --repo modelcontextprotocol/python-sdk

AI Disclaimer

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions