LiteLLM /mcp-rest/tools/call: test Sume tools without an LLM

LiteLLM exposes REST routes to list and call MCP tools with no model in the loop. Use them to smoke-test Sume's read tools and gates before an agent sees them.

5 min readSume
All posts

When an agent misuses a tool, it is hard to tell whether the model, the proxy or the server is at fault. LiteLLM's MCP gateway has a way to take the model out of the question. The LiteLLM MCP page documents /mcp-rest/tools/list and /mcp-rest/tools/call, usable without an LLM, read 2026-10-03. Pointed at a Sume entry, they give you a deterministic smoke test.

What to call, in order

Start with the listing, then call only read tools. Sume's tools and gates page names mcp_health, tools_list, tools_schema, catalog_list, balance_get and usage_get among the tools. The LiteLLM page lists an x-mcp-servers header to select which servers a request targets, so send it to keep the test on the Sume entry.

A no-LLM smoke test through LiteLLM, read 2026-10-03.
StepRouteWhat you learn
1/mcp-rest/tools/listThe proxy reaches Sume and your credential works
2/mcp-rest/tools/call with mcp_healthThe server answers a tool call
3/mcp-rest/tools/call with balance_getA read tool returns your own account data
4A write tool under a read-only credentialThe expected insufficient_scope error

Test the gates on purpose

The gates are the part worth testing deliberately. Paid and write tools require an idempotency_key; calling one without it should be refused. Previews such as dry_run and generation_admission_preview show cost without spending. max_spend_usd is enforced only when you provide it, so a test that omits it proves nothing about caps.

With an OAuth credential limited to mcp:read, a write or paid tool returns insufficient_scope, per the Sume OAuth page. Seeing that error through the proxy confirms the proxy did not widen the credential.

Keep the test cheap and repeatable

Do not run a paid create in a smoke test unless you intend to pay for it. If you do, send a fixed idempotency_key so a rerun does not create a second job. Record the job id, then use jobs_wait or jobs_result to read it back; jobs_wait holds 50 seconds by default and 55 at most, and wait_slice_expired means ask again with the same ids.

LiteLLM's page mentions MCP cost tracking and guardrails but gives no detail, so this post does not describe them. Confirm any spend limit on the Sume side.

  • Use the x-mcp-servers header so the test stays on Sume.
  • Call read tools first.
  • Expect insufficient_scope for writes on a read-only credential.
  • Reuse one idempotency key per test case.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume