MCP GET stream endpoint removed: Sume GET /mcp returns 405
MCP 2026-07-28 removes the GET stream endpoint. Sume's remote MCP already answers GET /mcp with 405 and Allow: POST, so send every message as an HTTP POST.

If a client opens a GET stream to Sume's remote MCP endpoint, it gets HTTP 405 with an Allow: POST header and the body Remote MCP uses POST JSON-RPC requests. That is the expected shape, not a fault: the MCP 2026-07-28 transport notes list removal of the GET stream endpoint, and POST is Sume's only working route for JSON-RPC.
Spec facts are from the MCP changelog page, read 2026-10-01. Endpoint facts are from Sume's hosted MCP docs and the MCP server source.
What did the spec change?
The 2026-07-28 revision's notes list two relevant removals: the GET stream endpoint and protocol-level sessions. Messages go as HTTP POST requests instead. For background on the older transports see MCP SSE vs streamable HTTP.
What does Sume return for each method?
| Request | Response |
|---|---|
GET /mcp | 405, header allow: POST, error text "Remote MCP uses POST JSON-RPC requests." |
POST /mcp | Handled as JSON-RPC |
Which clients need to change?
The docs point Cursor, Claude Code, Codex and other remote MCP clients at the same URL. A client that treats a failed GET as fatal during connect is the only one that needs attention: make it treat 405 on GET as "no stream here" and continue with POST. Check your client's own release notes for how it handles that.
How do I get job progress without a stream?
Poll with jobs_status or use jobs_wait; see MCP jobs_wait for long video jobs and the note that Sume does not push list changes.
Sources
Related posts
More in Developers
- MCP human-presence attestation: Sume consent vs API key
Human-presence attestation is only a roadmap topic. Sume separates people from automation by credential: OAuth consent in a browser, or an API key.
- MCP JSON-RPC batch 400: one message per request, Sume max 4
MCP 2026-07-28 requires one JSON-RPC message per POST. Sume still takes legacy batches of 1 to 4 on the 2025-03-26 shape and returns 400 -32600 otherwise.
- MCP OAuth .localhost redirect URI: Sume allows localhost and 127.0.0.1
MCP TypeScript SDK 2.2.0 treats .localhost hosts as loopback for token endpoints. Sume's redirect check allows http only on localhost and 127.0.0.1.
- MCP 403 forbidden_origin: why a browser client is refused
Sume remote MCP answers a disallowed Origin header with 403 forbidden_origin. A request with no Origin, like curl or a server SDK, is not checked this way.
Written by Sume