Kimi mcp test fails on Sume: URL, auth and scope checklist
If kimi mcp test fails or shows no Sume tools, check the endpoint URL, run kimi mcp auth, then separate a read-only grant from a broken connection.

When kimi mcp test sume fails, check three things in order: the URL is exactly https://mcp.sume.com/mcp, the server was added with --transport http, and kimi mcp auth sume finished in the browser. A connected server that cannot call paid tools is a different problem: that is a read-only grant, not a fault.
Kimi's commands are from the Kimi Code CLI page; the Sume endpoint and scopes are from the Sume docs.
Is the entry right?
Run kimi mcp list and look at the sume entry, or open ~/.kimi/mcp.json. Common mistakes are a missing /mcp path, the development host instead of the production one (Sume docs say customer configs should use mcp.sume.com), or stdio transport. If in doubt, remove and re-add:
kimi mcp remove sume
kimi mcp add --transport http --auth oauth sume https://mcp.sume.com/mcp
kimi mcp auth sume
kimi mcp test sumeDid authorization finish?
kimi mcp auth sume opens a browser. Sume's sign-in runs through https://mcp.sume.com/oauth/authorize to a consent page on the MCP host, not on app.sume.com, per the OAuth page. If your browser landed somewhere else, you started from the wrong URL. A machine without a browser cannot complete the flow; use an API key header there instead.
Is it connected but read-only?
If kimi mcp test passes and read tools such as tools_list and jobs_list work but generate_image is missing or returns insufficient_scope, the connection is healthy. The default grant is mcp:read. Authorize again and turn Write on at consent. Do not confuse this with an outage.
| Symptom | Likely cause | Fix |
|---|---|---|
kimi mcp test fails to connect | Wrong URL or transport | Re-add with --transport http and the production URL |
| Test fails with an auth error | OAuth not finished | Run kimi mcp auth sume |
| Read tools work, paid tools missing | Read-only grant | Re-authorize with Write on |
Paid tool says insufficient_scope | Same | Same, or use an API key header |
What is the last check?
Ask Kimi to call mcp_health. It reports the endpoint, auth source and safety posture, so you can tell a bad credential from a bad scope. Keep in mind Kimi prompts before MCP calls unless you have enabled YOLO or AFK mode, so an unanswered prompt can look like a hang.
What should you not do while debugging?
Do not paste an API key into the chat to see if it helps, and do not mint a key just because OAuth is awkward on a headless machine without deciding that an unattended key is what you want. A key sees every tool, including paid ones.
Do not resubmit a paid job to test the connection. Use read tools: mcp_health, tools_list and jobs_list prove the connection and cost nothing.
Sources
Related posts
More in Developers
- Kling motion control with avatar_id instead of image_url
Sume's Kling 3.0 Motion Control takes image_url or avatar_id/avatar_handle, never both. A ready avatar resolves server-side to its identity still.
- Kling motion control sync mode: a 30-second wait, then poll
Sume's sync and subscribe modes on Kling 3.0 Motion Control wait at most 30 seconds. A clip usually outlasts that, so poll status_url; do not resubmit.
- LangGraph 1.2 node timeout: the Sume video job keeps billing
LangGraph 1.2 adds run_timeout and idle_timeout per node. A timeout stops your node, not the Sume job it started: store the job id and re-poll.
- LangGraph DeltaChannel: keep Sume artifact URLs in state, not video
LangGraph 1.2 DeltaChannel stores only the per-step delta. Even so, keep Sume media out of state: store the artifact URL and job id and fetch bytes when needed.
Written by Sume