Claude Code tells Claude when an MCP server fails: Sume down vs auth

With tool search on, Claude Code reports failed MCP servers to the model. How to read that when Sume's server will not connect, 401 or 403.

6 min readSume
All posts

With tool search on, which is the default in Claude Code v2.1.232 and later, Claude Code tells the model which MCP servers failed to connect and includes that in its ToolSearch results. If Sume's server is among them, the agent can say so, instead of acting as if the tools never existed. Without tool search, Claude Code's docs say no failed connections are reported to Claude. That difference decides whether your agent can explain a missing Sume tool.

When tool search is off

The Claude Code MCP page lists the cases without tool search: a custom ANTHROPIC_BASE_URL, ENABLE_TOOL_SEARCH=false, and models earlier than the Claude 4.5 generation on Google Cloud's Agent Platform. In those cases the model sees only the tools that loaded, so a failed Sume server looks like a Sume server with no tools.

Failure reporting in Claude Code, Claude Code docs, read 2026-10-08
ConditionFailed servers reported to ClaudeWhere to look
Tool search on (default, v2.1.232+)Yes, in ToolSearch resultsAsk the agent; check /mcp
ENABLE_TOOL_SEARCH=falseNo/mcp in the terminal
Custom ANTHROPIC_BASE_URLNo/mcp in the terminal
Server still connectingClaude waits for it, within limitsRetry after connect

Telling the Sume causes apart

Three causes dominate. A connection failure at startup is a URL or network problem; Claude Code retries a first failure up to 3 times for transient errors, and a mid-session drop reconnects with backoff for up to 5 attempts. A 401 means the credential is missing or expired. Claude Code refreshes a stored OAuth token on 401, retries once, and only then marks the server as needing auth. A 403 with insufficient_scope means the session lacks a Sume scope: the call fails and names the scope it needs.

On Sume's side, mcp:read is required for OAuth and mcp:write is opt-in, and an API key gets the full tool set. A write or paid call under a read-only session returns insufficient_scope, which is a scope problem rather than an outage.

What to put in the agent's instructions

The startup-wait setting is in MCP connect timeout and startup wait.

  • If Sume tools are missing, call mcp_health once; it reports the credential block, whether OAuth token or API key.
  • Do not resubmit a paid create after a reconnect; find the job by id and use jobs_wait.
  • Stop and ask for a reconnect through /mcp on an auth failure instead of retrying in a loop.

A quick triage order

Start with the cheapest check. Run /mcp and read the server state. If it shows needs authentication, reconnect through the OAuth flow. If it shows failed, test the URL from the same machine, then check whether a proxy blocks mcp.sume.com.

Only then look at scopes. A server that connects but whose write tools are missing is almost always a read-only session: Sume lists only read tools when write is off, and the fix is to re-authorize with mcp:write or use an API key.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume