Co-authors:
Stenal Jolly, Strategic Cloud Engineer, Google
Anubhav Dhawan, Software Engineer, Google
Following the landmark announcement of MCP Toolbox v1.0, we’re thrilled to announce that the MCP Toolbox Java SDK has officially reached version 1.0.
This release brings first-class, type-safe agent orchestration to one of the world’s most widely adopted enterprise ecosystems. Java’s mature architecture is purpose-built for rigorous demands, providing the high concurrency, strict transactional integrity, and robust state management required to safely scale mission-critical AI agents in production.
In this post, we’ll tell you about what’s new in Java SDK v1.0, show you a real-world example, and help you get started with your own implementation.
MCP: The universal interface
Today, developers face a compounding integration bottleneck: if you have N different AI models and M enterprise data sources, you must build, secure, and maintain N × M bespoke, custom connections. This lack of a unified integration layer forces engineering teams to rely on a fragmented web of ad-hoc pipelines. As a result, scaling an agentic architecture quickly becomes unsustainable, exposing sensitive enterprise databases to severe security vulnerabilities, fragmented access controls, and massive maintenance overhead.
Eliminating the fragmented web of custom integrations is the core problem solved by the Model Context Protocol (MCP). Acting as a universal interface—the “USB Type-C” for AI orchestration—MCP decouples models from data sources. Instead of writing custom or managed API integration code for every new model or database, developers write to a single, standardized protocol. This approach allows any MCP-compliant agent to securely and immediately interact with any MCP-enabled system. The MCP connection lets developers connect agents to real-world systems without building bespoke integrations for every new model.
What’s new in Java SDK v1.0: Built for production workloads
When we announced the public Beta for the MCP Toolbox Java SDK, our goal was to bring first-class, type-safe agent orchestration to enterprise Java environments. Since then, we’ve collaborated with developers and open-source contributors to harden our APIs.
The v1.0 release marks a stable, backwards-compatible foundation suitable for enterprise workloads. Here’s what’s new and hardened since our v0.2 release:
-
Transport layer abstraction & HttpMcpTransport: We introduced a clean transport layer abstraction alongside HttpMcpTransport. This feature decouples the core protocol logic from underlying HTTP clients, making it easy to swap network implementations or customize connection pooling.
-
Decoupled client authentication: To simplify enterprise security compliance, client authentication is now decoupled using CredentialsProvider and AuthMethods classes. Credentials are resolved asynchronously on every request, so teams can refresh tokens dynamically or plug in their own token source (Google OIDC via ADC ships in the box, anything else is a one-method interface).
-
Default parameter support: Native support for default values in tool parameters, reducing prompt payload sizes and enhancing agent reliability.
-
Pruning bound parameters: Sensitive parameters that are bound server-side (like tenant_id) are now automatically stripped from exposed tool definitions so the LLM can’t manipulate them.
-
Version selection & session tracking: Standardized MCP version selection and robust session tracking ensure consistent protocol negotiation and conversation-state lifecycles.
-
HTTP credential exposure warnings: Added built-in detection that warns you at runtime when credentials are about to travel over a plaintext HTTP connection.
-
Generic client headers map: Easily attach custom corporate proxy headers, transaction tracing IDs, or correlation metadata to all outgoing requests.
Get started with the Java SDK v1.0
We designed the MCP Toolbox Java SDK to be frictionless for enterprise teams. Just add the following dependency to your pom.xml:





