MCP x-mcp-header and Mcp-Param headers vs Sume idempotency_key

The MCP 2026-07-28 spec can mirror tool parameters into Mcp-Param headers via x-mcp-header. Sume takes idempotency_key as a tool argument in the JSON body.

4 min readSume
All posts

An x-mcp-header property on a tool parameter tells a client to copy that parameter's value into an Mcp-Param-{Name} request header, so a gateway can read it without parsing the body. Sume's idempotency_key is an ordinary tool argument in the JSON body, and the docs do not describe a header form of it.

Spec facts are from the 2026-07-28 Streamable HTTP page; Sume facts from MCP tools and gates and MCP quickstart, read 2026-10-01.

What do the new MCP headers carry?

The page lists Mcp-Method (the request method, on all requests) and Mcp-Name (params.name or params.uri, on tools/call, resources/read and prompts/get). Parameters marked with x-mcp-header in a tool's schema are mirrored into Mcp-Param-{Name}. Values that are not plain ASCII use a Base64 sentinel form, and a header that disagrees with the body is a mismatch error.

Where does Sume keep idempotency_key?

In the tool arguments. The gate table lists idempotency_key as required on write and paid tools, as a stable key for transport and dedup rather than human approval. Do not assume anything beyond that; the live contract for any tool comes from tools_schema with a name.

Header names read 2026-10-01: spec page above; Sume CORS allow-list from packages/mcp-server/src/mcp.ts
HeaderWhere it appears
Mcp-Method, Mcp-NameSpec: standard request headers
Mcp-Param-{Name}Spec: from parameters marked x-mcp-header
mcp-protocol-versionIn Sume's preflight allow-list
x-api-keyIn Sume's preflight allow-list
idempotency_keySume tool argument in the JSON body

What should a gateway in front of Sume do?

Route on the headers the spec defines, and keep reading the body if you need the key. A gateway that wants per-key dedup should parse the tools/call body. For the method and name headers, see Mcp-Method routing at the Sume endpoint.

How do I confirm the contract for a tool?

Call tools_schema with the tool name and read the input schema it returns. Whether a given parameter carries a header annotation is a property of that schema, not something to infer from the spec.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume