MCP deprecations, removal from July 2027: audit Sume client
An MCP 2026-07-28 release candidate deprecates Roots, Sampling, Logging, Dynamic Client Registration and HTTP+SSE, removal no earlier than July 28, 2027.

An AAIF post on the MCP 2026-07-28 release candidate lists Roots, Sampling, Logging, Dynamic Client Registration and the HTTP+SSE transport as deprecated, with the earliest removal on July 28, 2027. For Sume, connect with a Streamable HTTP client at https://mcp.sume.com/mcp. Then check your own client for the other deprecated features.
What is deprecated
The list below is from the AAIF migration post, read on 2026-10-03. Deprecated does not mean gone; removal is no earlier than the date shown.
| Feature | Status | Earliest removal |
|---|---|---|
| Roots | Deprecated | July 28, 2027 |
| Sampling | Deprecated | July 28, 2027 |
| Logging | Deprecated | July 28, 2027 |
| Dynamic Client Registration | Deprecated | July 28, 2027 |
| HTTP+SSE transport | Deprecated | July 28, 2027 |
How Sume connects
Sume documents one hosted endpoint, https://mcp.sume.com/mcp, and tells clients to point a streamable HTTP MCP server at it. Claude Code connects with --transport http, and Cursor takes a remote server entry with a url. Neither path in the Sume docs uses the SSE transport.
claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sumeAuthentication is OAuth with protected-resource metadata and PKCE, or an API key sent as a bearer token or x-api-key. OAuth sessions default to mcp:read; Write is an opt-in at consent. Sume's docs do not describe the registration method your client uses to obtain a client id, so that detail is worth confirming for your specific client.
A short audit for your own client
Most of the work sits in the client you run, not in the server you connect to. Go through this list once for each MCP client in your stack.
- Transport: is the configured Sume server a Streamable HTTP entry rather than an SSE one?
- Roots, Sampling and Logging: does your client or agent framework depend on any of these?
- Registration: how does your client register with an OAuth server, and does it rely on Dynamic Client Registration?
- Upgrades: which client versions follow the AAIF migration guidance?
Verify after any client upgrade
After you change a client, call mcp_health to confirm the endpoint, auth source and safety posture, then tools_list to confirm the tools you expect are visible. Paid tools stay hidden under a read-only OAuth session, so check that the scope matches what you intended before you conclude a tool is missing.
Sources
Related posts
More in Developers
- MCP OAuth without DCR: client ID metadata documents and issuer checks
MCP 2026-07-28 deprecates dynamic client registration for Client ID Metadata Documents and requires clients to validate iss. What it means for Sume.
- Python MCP SDK 2.3 subscriptions=False: a Sume wrapper that pulls
MCPServer(subscriptions=False) turns off push subscriptions in the Python SDK. A wrapper over Sume jobs can do without them by waiting in bounded slices.
- Python MCP SDK v1 now gets security fixes only: use v2 for new clients
The Python MCP SDK v1.x line gets security fixes only; v2 added MRTR and the 2026-07-28 spec. What that means when you connect a client to Sume's hosted MCP.
- MCP tasks/cancel vs Sume jobs_cancel: cancel works only before start
TypeScript SDK 2.3.0 adds tasks/get and tasks/cancel. Sume's jobs_cancel is narrower: it succeeds only before generation starts, then returns 409.
Written by Sume