MCP Python SDK redirect rule: which Sume URL avoids a redirect
MCP Python SDK 2.2.0 follows redirects only within the endpoint's origin. Sume answers POST on https://mcp.sume.com/mcp and on the host root directly.

Pass https://mcp.sume.com/mcp to the MCP Python client. Sume's server handles POST on that path directly, so there is no redirect for the 2.2.0 same-origin rule to block. A POST to the host root also works, as a compatibility route.
SDK behavior is from the v2.2.0 release notes; Sume's routes are from the MCP server source and OAuth docs, read 2026-10-01.
Which redirects does 2.2.0 still follow?
Per the release notes, only those that keep the scheme, host and port the same, or upgrade http to https on the same host. Anything else fails with MCPError and leaves the session usable.
| Redirect target | Followed? |
|---|---|
| Same scheme, host and port | Yes |
| http to https on the same host | Yes |
| A different host or port | No: MCPError |
Which Sume URLs answer a POST without redirecting?
The server registers POST /mcp and POST /. Its routing code names the host origin as the compatibility endpoint and the resource URL as the canonical one, and the OAuth docs tell the client to connect to https://mcp.sume.com/mcp. Both live on mcp.sume.com, so a client that falls back to the root stays in the same origin.
What if my config points at another host?
Then 2.2.0 will not follow a redirect there; the notes say to use the other URL as the endpoint if that is the server you meant. For Sume that means the MCP host, not the API host. Use the canonical path exactly as documented.
Do I still need follow_redirects?
No. The notes say the setting on a passed-in httpx2.AsyncClient is no longer used for MCP requests. With a direct URL nothing needs following in the first place. Session handling is a separate topic: see the idle-session post.
Sources
Related posts
More in Developers
- MCP validate_token_resource: the resource a Sume token is for
Python SDK 2.2.0 adds validate_token_resource for servers. A Sume OAuth token's resource audience is https://mcp.sume.com/mcp; confirm it in the metadata.
- MCP resource not found -32602: Sume is tools-only, so -32601
MCP 2026-07-28 moves resource-not-found from -32002 to -32602. Sume's hosted MCP advertises tools only, so resources/read gets method-not-found -32601.
- What are MCP extensions? Sume's capabilities list tools only
MCP 2026-07-28 adds an optional extensions field to client and server capabilities. Sume's initialize reply advertises only tools, with listChanged false.
- MCP standardized error handling: Sume's named outcomes
MCP has no single error standard across surfaces yet. Here is how Sume's named outcomes map to retry, re-auth, or stop in a hosted MCP client.
Written by Sume