MCP JSON-RPC batch 400: one message per request, Sume max 4
MCP 2026-07-28 requires one JSON-RPC message per POST. Sume still takes legacy batches of 1 to 4 on the 2025-03-26 shape and returns 400 -32600 otherwise.

Send one JSON-RPC message per POST. The MCP 2026-07-28 transport page says the body must be a single request or notification, not a batch array. Sume's remote MCP still accepts a legacy array of 1 to 4 messages, and answers an empty array, an array of more than 4, or an array sent under a later supported protocol version header (2025-06-18 or 2025-11-25) with HTTP 400 and JSON-RPC code -32600.
Spec text read 2026-10-01. Limits are from the Sume's MCP server source; endpoint in the hosted MCP docs.
What is the exact error?
The message is "Legacy MCP batches allow 1–4 messages; current revisions require one message per request." The server's endpoint information also advertises legacy_batch_max_messages with the ceiling.
When does a batch still work?
| Request | Result |
|---|---|
| Single object body | Normal handling |
Array of 1 to 4, no version header or 2025-03-26 | Legacy batch accepted |
| Array of 0 or more than 4 | 400, -32600 |
Array with mcp-protocol-version 2025-06-18 or 2025-11-25 | 400, -32600, same message |
| Any version value Sume does not list (for example 2026-07-28) | 400, -32600, "Unsupported MCP protocol version." |
What do I change in a client that sends arrays?
Stop batching: send each message as its own POST and run them concurrently if you want parallelism. A different 400 covers arrays that mix kinds of tool calls: mixed work classes. Which protocol versions the server negotiates is covered in which version Sume speaks.
Does batching save budget?
Do not assume so. See how the endpoint counts toward the read budget before restructuring calls.
Sources
Related posts
More in Developers
- MCP OAuth .localhost redirect URI: Sume allows localhost and 127.0.0.1
MCP TypeScript SDK 2.2.0 treats .localhost hosts as loopback for token endpoints. Sume's redirect check allows http only on localhost and 127.0.0.1.
- MCP 403 forbidden_origin: why a browser client is refused
Sume remote MCP answers a disallowed Origin header with 403 forbidden_origin. A request with no Origin, like curl or a server SDK, is not checked this way.
- MCP ping method removed in 2026-07-28: Sume still replies {}
The MCP 2026-07-28 revision removes ping. Sume's hosted server still answers a ping request with an empty result on the versions it speaks.
- MCP progressive discovery: Sume tools_list, then tools_schema
For a large MCP tool set, list first and fetch one contract second. Sume has tools_list for visible tools and tools_schema for a single tool by name.
Written by Sume