How to test an MCP server: Inspector, Postman, or curl

Test an MCP server with the MCP Inspector: connect, sign in or add an auth header, list tools, and call a read-only one. Postman and curl work too.

6 min readSume
All posts

To test an MCP server, connect to it with the MCP Inspector, the protocol's reference tool for testing and debugging servers: run npx @modelcontextprotocol/inspector, point it at the server (its launch command for a local server, or its URL with the http transport for a remote one), sign in or add an auth header, list the tools, and call one that only reads. If the tool list comes back and the read-only call succeeds, the transport, the sign-in, and the server all work.

The Inspector steps come from its docs (overview, CLI, configuration, protocol eras, authorization), Postman's from its MCP request guide, and the wire format from the MCP specification, all read on 2026-09-28. The worked example is Sume's hosted MCP server, from its MCP quickstart, MCP tools and gates, and current server code.

How do I test a server with the MCP Inspector?

The Inspector needs Node 22.19.0 or newer and runs through npx with no installation. One package gives you three clients: a web UI (the default, which prints a URL to open in your browser), a scriptable CLI, and a terminal UI.

  • Local server: pass its launch command, as in npx @modelcontextprotocol/inspector node path/to/server/index.js.
  • Remote server: pass --server-url with the endpoint and --transport http; the other transport choices are stdio and sse.
  • Auth: add --header "Name: Value" (repeatable), or let the Inspector run OAuth. When the server answers 401, it reads the protected-resource metadata, opens the sign-in page in your browser, exchanges the code for tokens, and retries.
  • Call: select a tool, fill in the form built from its input schema, and read the result. The Protocol tab shows the raw JSON-RPC requests and responses.

Can I test an MCP server from the command line?

Yes. Each run of the Inspector's CLI connects, invokes the one method you name with --method, prints the result, and exits, which suits CI; --format json prints a single JSON object. A non-zero exit tells you what failed: 3 means the server requires authentication, 4 that it is unreachable, and 5 that the tool call returned an error or the tool wasn't found. Against Sume's server with an API key:

npx @modelcontextprotocol/inspector --cli https://mcp.sume.com/mcp \
  --transport http \
  --header "Authorization: Bearer $SUME_API_KEY" \
  --method tools/list --format json

npx @modelcontextprotocol/inspector --cli https://mcp.sume.com/mcp \
  --transport http \
  --header "Authorization: Bearer $SUME_API_KEY" \
  --method tools/call --tool-name mcp_health --tool-args-json '{}'

Which protocol era should I pick?

The 2026-07-28 revision of MCP removed the initialize handshake, so the Inspector makes the era a per-server setting. legacy, the default, sends a plain initialize; auto probes the newer server/discover first and falls back to initialize; modern pins 2026-07-28 with no fallback, so an older server fails loudly. Test on the era your real clients use.

Sume's server, in current code, negotiates only the handshake revisions 2025-03-26, 2025-06-18, and 2025-11-25, and answers any other MCP-Protocol-Version header with 400, so keep it on legacy.

How do I test an MCP server in Postman?

Create an MCP request, choose HTTP for a streamable HTTP server, and enter its URL; for a local server, choose STDIO and enter its command. If the server needs auth, open the Authorization tab, select an Auth Type, and add your details. Click Load Capabilities, open the Tools tab, choose a tool and define its arguments, then click Run. The reply appears in the Response tab.

Can I test an MCP server with curl?

Yes, by writing the protocol messages yourself. Under Streamable HTTP every message is a POST whose Accept header lists both application/json and text/event-stream, and in the 2025-11-25 revision the first message must be initialize. The response shows the protocol version and the capabilities the server declares; Sume's currently lists only tools.

curl -sS https://mcp.sume.com/mcp \
  -H "Authorization: Bearer $SUME_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"curl-check","version":"1.0.0"}}}'

What should I check on Sume's MCP server?

Start with the read-only calls from Sume's quickstart: mcp_health confirms the endpoint, auth source, and safety posture; tools_list lists every tool visible to the session; tools_schema returns one tool's contract by name; account_me confirms the workspace. Under OAuth, authenticated.auth_source should be mcp_oauth. Test a paid tool only with dry_run=true, which previews admission and cost without submitting the job, and don't paste API keys into chat.

If write and paid tools are missing from tools_list, the session is OAuth without Write, per MCP tools and gates; Fix MCP insufficient_scope on Sume covers that fix, and Sume's MCP OAuth flow the sign-in. Sume's basics page says hosted MCP still works but is not part of the primary path today. Other responses you may see while testing:

From MCP OAuth and API keys, read 2026-09-28, plus current server code where marked.
What you seeWhat it means on Sume
401 in a browser or on a request with no keyNo credential; the reply carries an OAuth challenge. With a valid credential, a GET gets 405, because the endpoint takes JSON-RPC over POST (current code)
401 with "Send only one MCP credential."Both Authorization: Bearer and x-api-key were sent; send one (current code)
403 with forbidden_originThe request carried an Origin header that isn't on Sume's allowlist; a request with no Origin header passes this check (current code)
400 with "Unsupported MCP protocol version."The client sent a protocol version Sume doesn't negotiate, such as the modern era's (current code)

Sources

Related posts

More in Developers

All Developers posts

Written by Sume