Contain before retrying.Cancel the turn, stop follow-ups, invalidate the exact MCP owner, and prove a new initialize plus tools/list generation.

Two outages need different triggers.

Transport close

rc.8 enters bounded reconnect backoff and rediscovers tools.

Application expiry

The server rejects a call while the SDK transport remains nominally live.

Ordinary tool error

The executor throws the result back to the model; no generation change follows.

Amplifier

The same visible schema invites another model replan and provider request.

Repair generation ownership first.

Invalidateone owner

Stop admission and collapse concurrent expiry signals into one transition.

Recoverinitialize + tools/list

Replace registrations only after the new generation is coherent.

Retrysafe and finite

Replay at most once for read-only or proven-idempotent work.

A model change is not MCP recovery.

Reasoning aggregation can reduce event volume, but neither action renews the server-side session or closes the stale circuit.

Primary evidence.

Break the stale generation, not just the loop.

The complete runbook includes live containment, evidence fields, stdio/HTTP/shared-service recovery, replay safety, a runtime repair contract, circuit-breaker identity, and fifteen acceptance gates.

Read the complete runbook