MCP 403 forbidden_origin: why a browser client is refused
Sume remote MCP answers a disallowed Origin header with 403 forbidden_origin. A request with no Origin, like curl or a server SDK, is not checked this way.

A browser-hosted MCP client gets 403 with code forbidden_origin and the message "Origin is not allowed for remote MCP." from Sume when its Origin header is not on the allowed list. The MCP 2026-07-28 transport page requires servers to answer an invalid Origin with 403. Requests that send no Origin header, such as curl or server-side SDKs, pass this check.
Spec text is from the MCP Streamable HTTP page, read 2026-10-01. Behavior is from the Sume's MCP server source; the endpoint is in the hosted MCP docs.
What does the spec require?
If the Origin header is present and invalid, servers must respond with HTTP 403 Forbidden. The spec text allows a response body, and does not make the check apply when the header is absent.
How does Sume decide?
| Request | Result |
|---|---|
No Origin header | Allowed |
Origin in the configured allowed set or equal to the public base URL | Allowed |
Any other Origin | 403, code forbidden_origin |
Why does curl work but my web app fail?
Browsers attach Origin to cross-site requests; curl does not. A web page on an origin Sume does not list is therefore refused even with a valid key. Sume's docs do not offer a way to register your own origin for the endpoint, so I would not assume one exists.
What should I do instead?
Call the endpoint from your server and have the browser talk to your backend. Keep the key there; see API key vs OAuth for MCP. Desktop and CLI clients that send no Origin are unaffected.
Sources
Related posts
More in Developers
- MCP ping method removed in 2026-07-28: Sume still replies {}
The MCP 2026-07-28 revision removes ping. Sume's hosted server still answers a ping request with an empty result on the versions it speaks.
- MCP progressive discovery: Sume tools_list, then tools_schema
For a large MCP tool set, list first and fetch one contract second. Sume has tools_list for visible tools and tools_schema for a single tool by name.
- MCP 403 forbidden: Sume forbidden_origin vs insufficient_scope
Python SDK 2.2.0 hands back any 403 that is not insufficient_scope. Sume's forbidden_origin is an HTTP 403; insufficient_scope is a tool result.
- MCP Python SDK 2.2 protected resource metadata 5xx stops OAuth
Python SDK 2.2.0 stops the OAuth flow when protected resource metadata returns 5xx or 429. Curl Sume's two metadata URLs to confirm they return 200.
Written by Sume