MCP C# SDK 2.0 for a .NET client: check the protocol header with Sume
The C# MCP SDK 2.0 targets the 2026-07-28 spec and keeps 1.x APIs compiling. What to test before pointing a .NET client at Sume, which lists 2025 versions.

Before you move a .NET MCP client to the C# SDK 2.0, test one call against Sume and read the status code. The Microsoft .NET blog says the SDK implements the 2026-07-28 revision, which drops the initialize / initialized handshake and sends the protocol version and capabilities with each request. Sume's hosted server lists three protocol versions, 2025-03-26, 2025-06-18 and 2025-11-25, and answers 400 with Unsupported MCP protocol version. when a request's Mcp-Protocol-Version header is outside that list.
So the question is not whether your code compiles. The blog promises that stable, non-deprecated 1.x APIs continue to compile and run in 2.0. The question is which protocol version the client sends on the wire.
What each side says
Sume's side comes from the server source and its health response; the SDK side from the announcement.
| Item | SDK 2.0 announcement | Sume hosted MCP |
|---|---|---|
| Spec revision | 2026-07-28 | Lists 2025-03-26, 2025-06-18, 2025-11-25 |
| Handshake | initialize / initialized removed | Still answers initialize and reports tools capability |
| Version header | Version travels with each request | Header outside the list gets HTTP 400, JSON-RPC -32600 |
| Client creation | McpClient.CreateAsync with a transport and options | Remote Streamable HTTP at https://mcp.sume.com/mcp |
| Auth | SDK says auth and authorization are its next focus | OAuth mcp:read / mcp:write, or API key as Bearer or x-api-key |
Steps to test
Create the client with McpClient.CreateAsync and an HTTP client transport pointed at https://mcp.sume.com/mcp, with an Authorization header carrying your Sume key. Call tools_list first; it is a read call and costs nothing. If you get a 400 with Unsupported MCP protocol version, pin the client to a 2025 version if the SDK lets you, or stay on the 1.x line until Sume lists the newer revision.
- Log the status code and the response body on the first call, not only the exception message.
- Use an API key for server-side .NET code; OAuth is for interactive clients.
- Send an
idempotency_keyon every write or paid tool, and start withdry_run=true.
Why the status code is the signal
A 400 is a clean failure: the body is a JSON-RPC error with code -32600 and the text Unsupported MCP protocol version. That is easy to tell apart from a 401, which means the credential is wrong, and from a 403 forbidden_origin, which Sume returns when the request's Origin is not allowed. If you only log the exception message from the SDK, those three can look alike, and you may spend an hour rotating a key that was fine.
Write the check as a small console program that makes one call and prints the status. Keep it in your repository so the next SDK bump re-runs it.
What Sume does not do
Sume does not claim support for the 2026-07-28 revision today, and this post cannot say how SDK 2.0 behaves when a server lists only older versions, because the announcement does not cover it. Test it. Sume also does not offer a stateful session you can resume; the endpoint takes POST only, and GET on /mcp returns 405.
Sources
Related posts
More in Developers
- Four Tier-1 MCP SDKs ship 2026-07-28 betas: which to use for Sume
Google says the TypeScript, Python, Go and C# MCP SDKs have betas for the new spec. Run Sume from a stable release, and test the beta separately.
- MiniMax H3 duration errors: at most 15 s, at least 5 s, Recast 30 s
Video Router refuses a MiniMax H3 job over 15 s or under 5 s with a named message, and Recast has its own 5-30 s rule. Messages, limits and a pre-check.
- Modal 1.6.1 endpoint logs and stats: debug a Sume webhook receiver
Modal 1.6.1 adds modal endpoint info, stats and logs. Use them to see why a Sume job webhook got a 401 or a timeout, and check the 150 s web timeout first.
- model sume/auto on /v1/videos: defaults, limits, replay-stable price
sume/auto lets Sume pick the video family. Defaults are 720p and 8 s, clips run 3 to 10 s at 16:9 or 9:16, and a replay gets the same route and price.
Written by Sume