Mastra MCPClient and JSON Schema 2019-09: Sume tool schemas
Mastra MCP 2.1.1 accepts tool inputs in JSON Schema 2019-09. Sume builds its tool inputs as plain object schemas, and tools_schema returns each contract.

The Mastra fix is unlikely to matter for Sume. @mastra/mcp 2.1.1 lets MCPClient accept tools from MCP servers whose inputs use JSON Schema draft 2019-09, and Sume's schema builder emits a simple object schema with properties, required and additionalProperties: false. If a call still fails validation, fetch that tool's contract with tools_schema and compare.
Vendor text is from the @mastra/core 1.72.0 release (2026-09-30), which lists the @mastra/mcp 2.1.1 patch. Sume facts are from the repository and MCP tools and gates, read 2026-10-01.
What did the Mastra release change?
The patch note says two things: tool calls no longer fail with a schema validation error when tools are defined with zod v3 schemas, and MCPClient now accepts tools from other MCP servers that describe their inputs with JSON Schema draft 2019-09. It names no Sume behavior.
What do Sume's tool schemas look like?
The shared builder in the MCP server source returns type: "object", the property map, the required list, and additionalProperties: false. I did not audit every tool; a few may add their own nested keywords. That is why the check below reads the live contract, not a summary.
| Tool | What it gives your client |
|---|---|
tools_list | Every tool visible in the session, with safety metadata |
tools_schema | One tool contract, fetched by name |
mcp_health | Endpoint readiness, auth source, safety posture |
How do I point a Mastra MCPClient at Sume?
Use the hosted URL https://mcp.sume.com/mcp as the server entry, with an OAuth session or an API key as described in OAuth and API keys. Mastra's own config shape is covered in Mastra MCPClient with Sume.
What do I do when a tool input is rejected?
Call tools_schema with the tool name, read the required fields, and resend. Paid and write tools also require an idempotency_key. Under OAuth mcp:read only, those tools are hidden entirely, so a missing tool is a scope question, not a schema question.
Sources
Related posts
More in Developers
- MCP batch mixed tools error: split status reads, waits, tools
Sume's legacy MCP batch must hold one class of work: jobs_status reads, jobs_wait waits, or other tools. A mixed array gets 400 -32600. Here is how to split it.
- MCP CORS preflight: headers Sume allows for a browser client
Sume answers an MCP OPTIONS preflight with 204 and lists authorization, content-type, idempotency-key, mcp-session-id and x-api-key for listed origins.
- MCP DPoP sender-constrained tokens: Sume is bearer-only today
The MCP roadmap lists DPoP finalization, but Sume's hosted MCP issues mcp_at_ bearer tokens sent in the Authorization header, valid for one hour.
- MCP DCR application_type: what Sume's register endpoint reads
The 2026-07-28 MCP spec asks clients to send application_type in dynamic registration. Sume's /oauth/register reads redirect_uris and other named fields.
Written by Sume