MCP 403 forbidden_origin: why a browser client is refused
Sume remote MCP answers a disallowed Origin header with 403 forbidden_origin. A request with no Origin, like curl or a server SDK, is not checked this way.

A browser-hosted MCP client gets 403 with code forbidden_origin and the message "Origin is not allowed for remote MCP." from Sume when its Origin header is not on the allowed list. The MCP 2026-07-28 transport page requires servers to answer an invalid Origin with 403. Requests that send no Origin header, such as curl or server-side SDKs, pass this check.
Spec text is from the MCP Streamable HTTP page, read 2026-10-01. Behavior is from the Sume's MCP server source; the endpoint is in the hosted MCP docs.
What does the spec require?
If the Origin header is present and invalid, servers must respond with HTTP 403 Forbidden. The spec text allows a response body, and does not make the check apply when the header is absent.
How does Sume decide?
| Request | Result |
|---|---|
No Origin header | Allowed |
Origin in the configured allowed set or equal to the public base URL | Allowed |
Any other Origin | 403, code forbidden_origin |
Why does curl work but my web app fail?
Browsers attach Origin to cross-site requests; curl does not. A web page on an origin Sume does not list is therefore refused even with a valid key. Sume's docs do not offer a way to register your own origin for the endpoint, so I would not assume one exists.
What should I do instead?
Call the endpoint from your server and have the browser talk to your backend. Keep the key there; see API key vs OAuth for MCP. Desktop and CLI clients that send no Origin are unaffected.
Sources
Related posts
More in Developers
- MCP progressive discovery: Sume tools_list, then tools_schema
For a large MCP tool set, list first and fetch one contract second. Sume has tools_list for visible tools and tools_schema for a single tool by name.
- MCP resource not found -32602: Sume is tools-only, so -32601
MCP 2026-07-28 moves resource-not-found from -32002 to -32602. Sume's hosted MCP advertises tools only, so resources/read gets method-not-found -32601.
- MCP standardized error handling: Sume's named outcomes
MCP has no single error standard across surfaces yet. Here is how Sume's named outcomes map to retry, re-auth, or stop in a hosted MCP client.
- MCP sub-agent with narrower authority: a read-only Sume token
Give a sub-agent a Sume token granted only mcp:read and it sees read-only tools, so it can inspect jobs and assets but never submit a paid generation.
Written by Sume