MCP error codes: what -32601, -32602, and -32001 mean
MCP error codes are JSON-RPC codes. What -32700 to -32603 mean, why -32001 is a client-side timeout, and how a failed tool call differs from both.

MCP error codes are JSON-RPC 2.0 error codes. The standard ones are -32700 (parse error), -32600 (invalid request), -32601 (method not found), -32602 (invalid params), and -32603 (internal error). In the MCP TypeScript SDK, -32000 and -32001, as in MCP error -32001: Request timed out, are client-side codes: the connection closed, or no answer arrived within the request timeout, 60 seconds by default. A tool that runs and fails is different: it returns a normal result with isError: true.
The codes come from the JSON-RPC 2.0 specification, the MCP 2025-11-25 tools page, the 2026-07-28 changelog, and the TypeScript SDK's v1.x types and protocol source, all read on 2026-09-28. The Sume examples describe the current code of Sume's hosted MCP server, which the basics page says still works but is not part of the primary path today.
What does each MCP error code mean?
JSON-RPC reserves -32768 to -32000 for predefined errors and sets aside -32000 to -32099 for implementation-defined server errors. That is why a number in that last range can mean one thing in an SDK and another on a server.
| Code | Name | Raised by | Meaning |
|---|---|---|---|
-32700 | Parse error | Server | Invalid JSON was received by the server |
-32600 | Invalid Request | Server | The JSON sent is not a valid Request object |
-32601 | Method not found | Server | The method does not exist or is not available |
-32602 | Invalid params | Server | Invalid method parameters; the MCP spec's example uses it for an unknown tool |
-32603 | Internal error | Server | Internal JSON-RPC error |
-32000 | ConnectionClosed | TypeScript SDK, client side | The connection closed while the request was still waiting |
-32001 | RequestTimeout | TypeScript SDK, client side | No response arrived within the request timeout, 60,000 ms by default |
Why do I get MCP error -32001: Request timed out?
Because the client stopped waiting, not because the server sent an error. In the TypeScript SDK, every request starts a timer. If no response arrives within timeout milliseconds, the request fails with RequestTimeout and the message Request timed out, and the SDK's error class prints that as MCP error -32001: Request timed out. The default, DEFAULT_REQUEST_TIMEOUT_MSEC, is 60,000 ms.
- Raise the request
timeoutif your client lets you. In the SDK,resetTimeoutOnProgress(defaultfalse) lets progress notifications restart the timer, andmaxTotalTimeoutcaps the total wait. - The 60-second default belongs to the TypeScript SDK. A client built another way can use another value, so check its own docs.
- Make long work return early and wait in slices. On Sume's server, generation tools answer with a job id in current code, and one
jobs_waitcall holds at most 55 seconds. MCP tool call timeouts on long-running video jobs covers that loop. - Its neighbor, -32000
Connection closed, means the transport closed while requests were waiting: the SDK fails each of them with that code.
Is a failed tool call an MCP error code?
No. The MCP spec uses two mechanisms. Protocol errors are standard JSON-RPC errors, for unknown tools, malformed requests, and server errors. Tool execution errors, such as API failures, input validation errors, and business logic errors, come back as a normal result with isError: true. Clients SHOULD provide tool execution errors to the model so it can self-correct; protocol errors are less likely to lead to recovery. The spec's two examples:
// Protocol error: a JSON-RPC error object
{ "jsonrpc": "2.0", "id": 3,
"error": { "code": -32602, "message": "Unknown tool: invalid_tool_name" } }
// Tool execution error: a normal result with isError
{ "jsonrpc": "2.0", "id": 4,
"result": {
"content": [{ "type": "text",
"text": "Invalid departure date: must be in the future. Current date is 08/08/2025." }],
"isError": true } }What do the codes mean on Sume's MCP server?
At https://mcp.sume.com/mcp, the server's current code answers like this:
-32600for a message withoutjsonrpc: "2.0"or a stringmethod. With HTTP400andUnsupported MCP protocol version., it also answers anMCP-Protocol-Versionheader other than 2025-03-26, 2025-06-18, or 2025-11-25.-32601,MCP method is not supported: …, for a request whose method isn'tinitialize,ping,tools/list, ortools/call. The server declares only thetoolscapability, soresources/listlands here.-32602for other request failures, such as atools/callwith no tool name.-32000,MCP work budget is full; retry shortly., with HTTP429, when the caller's MCP work budget is full and the message is not a tool call.- Tool failures are
isError: trueresults whose text is JSON with acodeand amessage. An OAuth session withoutmcp:writegetsinsufficient_scopeon a write tool (how to fix it). An unknown tool name getstool_not_foundas a tool result, where the spec's own example uses -32602.
Did the 2026-07-28 revision change the codes?
It set a policy for the server-error range: -32000 to -32019 stays implementation-defined, with existing SDK usage grandfathered, and -32020 to -32099 is reserved for the MCP specification. It moved three codes introduced in that draft to -32020 (HeaderMismatch), -32021 (MissingRequiredClientCapability), and -32022 (UnsupportedProtocolVersion), and changed resource not found from -32002 to -32602. Sume's error.code tokens outside MCP are a different system, indexed in Sume API error codes by surface.
Sources
- JSON-RPC 2.0 Specification (read 2026-09-28)
- MCP specification 2025-11-25: Tools (read 2026-09-28)
- MCP specification 2026-07-28: Key changes (read 2026-09-28)
- MCP TypeScript SDK v1.x: types.ts (read 2026-09-28)
- MCP TypeScript SDK v1.x: protocol.ts (read 2026-09-28)
- MCP overview
- MCP OAuth and API keys
- Jobs and results
- Sume basics
Related posts
More in Developers
- MCP JSON config: what's in mcp.json and why clients differ
An MCP JSON config lists servers by name: a command for local ones, a URL and headers for remote ones. Why the key names differ between clients.
- MCP server API key vs OAuth: which one to use
Use OAuth when a person signs in from Claude, Cursor, or another client; use an API key header for scripts, CI, and headless runs with no browser.
- MCP server file upload: how a local file reaches a tool
A remote MCP server can't read your disk. A tool gets only the arguments your client sends, so the file must sit at a URL the tool accepts.
- MCP SSE vs Streamable HTTP: which transport to use
SSE is MCP's older, deprecated HTTP transport; Streamable HTTP replaced it with one endpoint that takes every message as a POST. Which to choose.
Written by Sume