MCP 403 forbidden: Sume forbidden_origin vs insufficient_scope

Python SDK 2.2.0 hands back any 403 that is not insufficient_scope. Sume's forbidden_origin is an HTTP 403; insufficient_scope is a tool result.

4 min readSume
All posts

Against Sume, an HTTP 403 and an insufficient_scope error are different things. A 403 with code forbidden_origin means the request's Origin is not allowed for remote MCP. A missing write scope comes back as a tool result with code insufficient_scope, not as an HTTP challenge. Check the body before changing scopes.

MCP Python SDK 2.2.0 (2026-09-07) says: "A 403 that isn't an insufficient_scope challenge is returned to the caller instead of retried." Sume facts are from MCP tools and gates and the MCP server code, read 2026-10-01.

What does Sume return for each case?

403-related Sume responses from the MCP server code and docs, read 2026-10-01
CaseHow it arrivesCode and detail
Origin not allowedHTTP 403 with a public error bodyforbidden_origin: "Origin is not allowed for remote MCP."
OAuth session without write scope calls a write or paid toolMCP tool result (isError: true)insufficient_scope, with required_scope mcp:write
Read-only OAuth session lists toolsRead-only tools onlymcp:read sessions see read-only tools

Why does the SDK behavior matter here?

The 2.2.0 notes say an insufficient_scope challenge is the one 403 the client may act on, and any other 403 is handed back as is. Sume's scope error is not delivered as a 403 challenge, so a client sees it as an ordinary failed tool result. A genuine HTTP 403 from Sume is therefore the origin check, and retrying will not help.

How do I fix a forbidden_origin?

Call the endpoint from a server or CLI client that does not send a browser Origin, or from an Origin your deployment is allowed to use. Do not retry in a loop: the SDK will not, and Sume's answer will not change. If a browser app needs MCP, route the call through your backend.

How do I fix insufficient_scope?

Reconnect with consent that includes Write, which grants mcp:write (read is always included), or use an API key. The docs say there is no mcp:paid scope, and legacy allow_write or allow_paid cannot bypass a missing mcp:write. Paid submits still need idempotency_key. See standardized MCP error handling with Sume for the related shapes.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume