AI & Analytics Legends The knowledge platform for SAP Analytics
Concept card

MCP Streaming HTTP Transport — For Production Multi-Tenant Deployments

MCP Streaming HTTP Transport — For Production Multi-Tenant Deployments — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-10-06

What is MCP Streaming HTTP Transport?

MCP's Streamable HTTP transport treats every request as independent by default, replacing the SSE-only design that broke session continuity behind a load balancer — the only transport that scales horizontally on stateless containers.

MCP's Streamable HTTP transport, introduced in the Model Context Protocol specification revision of March 2025 and superseding the original SSE-only transport, is the production wire format for serving MCP tools to remote agent clients over a network. A single HTTPS endpoint accepts JSON-RPC 2.0 requests by POST; the server replies with a plain JSON response for a one-shot tool call, or upgrades the same connection to a chunked event stream when a tool needs to push partial results, progress updates, or a long-lived subscription. The transport is stateless by default, every request carries its full JSON-RPC payload and can, in principle, land on any backend instance, but it supports stateful sessions through a session-id header negotiated during the initial handshake, for the cases where continuity across requests is actually needed.

Why It Exists

The original MCP transport was SSE-only: a persistent server-to-client event stream carried all server-originated messages, with client requests routed back over a separate HTTP POST channel. That asymmetric design worked well for simple local tooling, but it imposed a standing connection requirement that made horizontal scaling behind a load balancer unreliable; successive requests in the same logical session could land on different backend instances, silently breaking continuity. Streamable HTTP resolves this by treating every request as independent unless a session is explicitly negotiated, a design that maps directly onto stateless container runtimes and lets a load balancer route each request without needing sticky sessions as the default assumption.

Why it matters

  • The old SSE-only transport required a persistent connection, so different request cycles could land on different backend instances and break sessions — a real horizontal-scaling blocker.
  • Streamable HTTP lets the same MCP server autoscale on BTP Cloud Foundry or Kyma, terminate TLS at the edge, and authenticate with OAuth 2.1 bearer tokens.
  • Per-tenant audit logs from every tool call can flow into SAP AI Agent Hub, satisfying EU AI Act Art. 9 record-keeping at the transport layer.

Key points

  • Streamable HTTP transport — MCP spec revision 2025-03, replaces the original SSE-only transport; one POST /mcp endpoint, optional upgrade to chunked SSE for streaming responses.
  • Stateless by default — horizontal scaling on BTP Cloud Foundry / Kyma; optional Mcp-Session-Id header for stateful sessions when needed.
  • OAuth 2.1 mandated when authorization is supported — MCP spec 2026-07-28 requires it conditionally for HTTP transports (authorization itself is protocol-optional; see C226); most production deployments still need it.
  • Multi-tenant ready — per-tenant audit logs flow into SAP AI Agent Hub (C211); EU AI Act Art. 9-49 record-keeping discharged at the transport layer.
  • Anti-pattern — shipping a stdio-only server then rewriting for production; build HTTP from day one when more than one operator will use it.
  • Tasks extension (spec 2026-07-28) — for long-running tool calls, a server can return a durable taskId instead of holding the HTTP connection open; the client polls tasks/get or subscribes to notifications, surviving disconnects and load-balancer timeouts that a held-open stream cannot.
  • Tasks vs raw streaming — a chunked SSE response is still the right choice for a call that finishes in seconds with incremental output; Tasks is the right choice when the call can take minutes-to-hours or the client may disconnect mid-call.

Terms used on this page

Streamable HTTP
MCP transport introduced 2025-03 — single HTTPS POST endpoint, optional upgrade to chunked text/event-stream for partial results; production wire format.
Mcp-Session-Id
Optional HTTP header negotiated at initialize for stateful sessions across multiple requests; not required for stateless tool calls.
OAuth 2.1
Auth profile MCP requires when a server chooses to support authorization for HTTP transports (spec 2026-07-28); consolidates OAuth 2.0 best practices, drops the implicit + ROPC flows. Authorization itself is protocol-optional — see C226.
Per-tenant scope
OAuth claim narrowing a token's access to one customer tenant's MCP tools and data scopes; foundation of multi-tenant isolation.
MCP Tasks extension
An optional extension (spec 2026-07-28, ext-tasks repository) letting a server return a durable task handle instead of blocking the HTTP connection for a long-running call; the client polls tasks/get or subscribes to notifications/tasks until the task reaches a terminal state.
CreateTaskResult / taskId
The response a Tasks-capable server returns in place of a synchronous result: a taskId, initial status, time-to-live (ttlMs), and a suggested pollIntervalMs. The task must be durably created before the response is sent, so the taskId survives a client disconnect.
input_required (task status)
A Tasks-extension lifecycle state indicating the server needs client input — often an elicitation — before continuing; the client reads the inputRequests map from tasks/get and responds via tasks/update, with no second connection needed.

Sources

  1. Model Context Protocol specification — Streamable HTTP transport (2025-03 revision)
  2. Model Context Protocol specification — Authorization (2025-06 revision, OAuth 2.1)
  3. Anthropic — Model Context Protocol SDK (TypeScript) HTTP transport reference
  4. SAP BTP — Cloud Foundry deployment of HTTPS endpoints
  5. Model Context Protocol — Tasks extension overview (spec 2026-07-28)
  6. Model Context Protocol — ext-tasks specification repository
  7. Model Context Protocol — Streamable HTTP transport (spec 2026-07-28)
  8. Model Context Protocol — stdio transport (spec 2026-07-28)
  9. Model Context Protocol — Extensions overview and client-matrix
  10. Model Context Protocol — Transports Working Group
  11. Model Context Protocol — Authorization specification (spec 2026-07-28)
  12. modelcontextprotocol/typescript-sdk — v2.3.0 release notes, 2 October 2026 (one server per request, same-origin redirects, expectedResource, Tasks on 2026-07-28)
  13. modelcontextprotocol/typescript-sdk — v2.3.1 release notes, 5 October 2026 (expectedResource in server-legacy)
  14. modelcontextprotocol/python-sdk — v2.3.0 release notes, 2 October 2026 (max_sse_event_size on the Streamable HTTP client)
  15. Model Context Protocol — Key changes, specification 2026-07-28 (sessions and SSE resumability removed from Streamable HTTP)

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →