MCP Inspector 405 Method Not Allowed on a POST-only server
Inspector 2.8.0 can suppress the standalone GET notification stream. Sume's MCP endpoint answers GET /mcp with 405 and Allow: POST, so turn it off.

A 405 in Inspector's log against Sume is expected: the MCP endpoint serves POST JSON-RPC only, and a GET to /mcp returns 405 with allow: POST and the text "Remote MCP uses POST JSON-RPC requests." Inspector 2.8.0 added a per-server setting to suppress the standalone GET notification stream, which is the setting to use with a POST-only server like Sume.
Inspector's change is from its GitHub releases page; Sume's responses are from the MCP server source and docs, read 2026-10-01. I did not find the setting's exact label in the release notes, so look for it in the server's connection settings.
What does the Inspector release say?
The 2.8.0 notes (2026-09-23) list "per-server setting to suppress the standalone GET notification stream". The standalone GET stream is how a client can receive server-pushed notifications on some servers; a server that does not offer one has nothing to send there.
What does Sume answer?
| Item | Value |
|---|---|
GET /mcp | 405, allow: POST |
Endpoint info methods | ["POST"] |
capabilities.tools.listChanged | false |
Does the 405 mean my connection is broken?
No. A client that tolerates a 405 on the optional GET carries on with POST. If tools list and calls succeed, the connection is fine and the 405 is noise; suppressing the stream removes it. If POST fails too, the cause is elsewhere, such as the credential: see one Sume key in Inspector's headers.
How do I follow a long job without a stream?
Poll. The docs say each jobs_wait call holds at most 55 seconds (default 50); on wait_slice_expired, call it again with the same ids and never resubmit the paid create. Background on why there is no push is in no push, listChanged false.
Sources
Related posts
More in Developers
- MCP JSON-RPC batch 400: one message per request, Sume max 4
MCP 2026-07-28 requires one JSON-RPC message per POST. Sume still takes legacy batches of 1 to 4 on the 2025-03-26 shape and returns 400 -32600 otherwise.
- MCP OAuth .localhost redirect URI: Sume allows localhost and 127.0.0.1
MCP TypeScript SDK 2.2.0 treats .localhost hosts as loopback for token endpoints. Sume's redirect check allows http only on localhost and 127.0.0.1.
- MCP 403 forbidden_origin: why a browser client is refused
Sume remote MCP answers a disallowed Origin header with 403 forbidden_origin. A request with no Origin, like curl or a server SDK, is not checked this way.
- MCP ping method removed in 2026-07-28: Sume still replies {}
The MCP 2026-07-28 revision removes ping. Sume's hosted server still answers a ping request with an empty result on the versions it speaks.
Written by Sume