MCP deprecations, removal from July 2027: audit Sume client

An MCP 2026-07-28 release candidate deprecates Roots, Sampling, Logging, Dynamic Client Registration and HTTP+SSE, removal no earlier than July 28, 2027.

4 min readSume
All posts

An AAIF post on the MCP 2026-07-28 release candidate lists Roots, Sampling, Logging, Dynamic Client Registration and the HTTP+SSE transport as deprecated, with the earliest removal on July 28, 2027. For Sume, connect with a Streamable HTTP client at https://mcp.sume.com/mcp. Then check your own client for the other deprecated features.

What is deprecated

The list below is from the AAIF migration post, read on 2026-10-03. Deprecated does not mean gone; removal is no earlier than the date shown.

MCP deprecations (read 2026-10-03)
FeatureStatusEarliest removal
RootsDeprecatedJuly 28, 2027
SamplingDeprecatedJuly 28, 2027
LoggingDeprecatedJuly 28, 2027
Dynamic Client RegistrationDeprecatedJuly 28, 2027
HTTP+SSE transportDeprecatedJuly 28, 2027

How Sume connects

Sume documents one hosted endpoint, https://mcp.sume.com/mcp, and tells clients to point a streamable HTTP MCP server at it. Claude Code connects with --transport http, and Cursor takes a remote server entry with a url. Neither path in the Sume docs uses the SSE transport.

claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume

Authentication is OAuth with protected-resource metadata and PKCE, or an API key sent as a bearer token or x-api-key. OAuth sessions default to mcp:read; Write is an opt-in at consent. Sume's docs do not describe the registration method your client uses to obtain a client id, so that detail is worth confirming for your specific client.

A short audit for your own client

Most of the work sits in the client you run, not in the server you connect to. Go through this list once for each MCP client in your stack.

  • Transport: is the configured Sume server a Streamable HTTP entry rather than an SSE one?
  • Roots, Sampling and Logging: does your client or agent framework depend on any of these?
  • Registration: how does your client register with an OAuth server, and does it rely on Dynamic Client Registration?
  • Upgrades: which client versions follow the AAIF migration guidance?

Verify after any client upgrade

After you change a client, call mcp_health to confirm the endpoint, auth source and safety posture, then tools_list to confirm the tools you expect are visible. Paid tools stay hidden under a read-only OAuth session, so check that the scope matches what you intended before you conclude a tool is missing.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume