Kimi mcp test fails on Sume: URL, auth and scope checklist

If kimi mcp test fails or shows no Sume tools, check the endpoint URL, run kimi mcp auth, then separate a read-only grant from a broken connection.

4 min readSume
All posts

When kimi mcp test sume fails, check three things in order: the URL is exactly https://mcp.sume.com/mcp, the server was added with --transport http, and kimi mcp auth sume finished in the browser. A connected server that cannot call paid tools is a different problem: that is a read-only grant, not a fault.

Kimi's commands are from the Kimi Code CLI page; the Sume endpoint and scopes are from the Sume docs.

Is the entry right?

Run kimi mcp list and look at the sume entry, or open ~/.kimi/mcp.json. Common mistakes are a missing /mcp path, the development host instead of the production one (Sume docs say customer configs should use mcp.sume.com), or stdio transport. If in doubt, remove and re-add:

kimi mcp remove sume
kimi mcp add --transport http --auth oauth sume https://mcp.sume.com/mcp
kimi mcp auth sume
kimi mcp test sume

Did authorization finish?

kimi mcp auth sume opens a browser. Sume's sign-in runs through https://mcp.sume.com/oauth/authorize to a consent page on the MCP host, not on app.sume.com, per the OAuth page. If your browser landed somewhere else, you started from the wrong URL. A machine without a browser cannot complete the flow; use an API key header there instead.

Is it connected but read-only?

If kimi mcp test passes and read tools such as tools_list and jobs_list work but generate_image is missing or returns insufficient_scope, the connection is healthy. The default grant is mcp:read. Authorize again and turn Write on at consent. Do not confuse this with an outage.

Symptom to cause, read 2026-10-02
SymptomLikely causeFix
kimi mcp test fails to connectWrong URL or transportRe-add with --transport http and the production URL
Test fails with an auth errorOAuth not finishedRun kimi mcp auth sume
Read tools work, paid tools missingRead-only grantRe-authorize with Write on
Paid tool says insufficient_scopeSameSame, or use an API key header

What is the last check?

Ask Kimi to call mcp_health. It reports the endpoint, auth source and safety posture, so you can tell a bad credential from a bad scope. Keep in mind Kimi prompts before MCP calls unless you have enabled YOLO or AFK mode, so an unanswered prompt can look like a hang.

What should you not do while debugging?

Do not paste an API key into the chat to see if it helps, and do not mint a key just because OAuth is awkward on a headless machine without deciding that an unattended key is what you want. A key sees every tool, including paid ones.

Do not resubmit a paid job to test the connection. Use read tools: mcp_health, tools_list and jobs_list prove the connection and cost nothing.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume