MCP 403 forbidden: Sume forbidden_origin vs insufficient_scope
Python SDK 2.2.0 hands back any 403 that is not insufficient_scope. Sume's forbidden_origin is an HTTP 403; insufficient_scope is a tool result.

Against Sume, an HTTP 403 and an insufficient_scope error are different things. A 403 with code forbidden_origin means the request's Origin is not allowed for remote MCP. A missing write scope comes back as a tool result with code insufficient_scope, not as an HTTP challenge. Check the body before changing scopes.
MCP Python SDK 2.2.0 (2026-09-07) says: "A 403 that isn't an insufficient_scope challenge is returned to the caller instead of retried." Sume facts are from MCP tools and gates and the MCP server code, read 2026-10-01.
What does Sume return for each case?
| Case | How it arrives | Code and detail |
|---|---|---|
| Origin not allowed | HTTP 403 with a public error body | forbidden_origin: "Origin is not allowed for remote MCP." |
| OAuth session without write scope calls a write or paid tool | MCP tool result (isError: true) | insufficient_scope, with required_scope mcp:write |
| Read-only OAuth session lists tools | Read-only tools only | mcp:read sessions see read-only tools |
Why does the SDK behavior matter here?
The 2.2.0 notes say an insufficient_scope challenge is the one 403 the client may act on, and any other 403 is handed back as is. Sume's scope error is not delivered as a 403 challenge, so a client sees it as an ordinary failed tool result. A genuine HTTP 403 from Sume is therefore the origin check, and retrying will not help.
How do I fix a forbidden_origin?
Call the endpoint from a server or CLI client that does not send a browser Origin, or from an Origin your deployment is allowed to use. Do not retry in a loop: the SDK will not, and Sume's answer will not change. If a browser app needs MCP, route the call through your backend.
How do I fix insufficient_scope?
Reconnect with consent that includes Write, which grants mcp:write (read is always included), or use an API key. The docs say there is no mcp:paid scope, and legacy allow_write or allow_paid cannot bypass a missing mcp:write. Paid submits still need idempotency_key. See standardized MCP error handling with Sume for the related shapes.
Sources
Related posts
More in Developers
- MCP Python SDK 2.2 protected resource metadata 5xx stops OAuth
Python SDK 2.2.0 stops the OAuth flow when protected resource metadata returns 5xx or 429. Curl Sume's two metadata URLs to confirm they return 200.
- MCP Python SDK redirect rule: which Sume URL avoids a redirect
MCP Python SDK 2.2.0 follows redirects only within the endpoint's origin. Sume answers POST on https://mcp.sume.com/mcp and on the host root directly.
- MCP validate_token_resource: the resource a Sume token is for
Python SDK 2.2.0 adds validate_token_resource for servers. A Sume OAuth token's resource audience is https://mcp.sume.com/mcp; confirm it in the metadata.
- MCP resource not found -32602: Sume is tools-only, so -32601
MCP 2026-07-28 moves resource-not-found from -32002 to -32602. Sume's hosted MCP advertises tools only, so resources/read gets method-not-found -32601.
Written by Sume