MCP tool inputSchema and JSON Schema 2020-12: Sume's tool schemas
MCP 2026-07-28 lets inputSchema use any JSON Schema 2020-12 keyword. Sume builds tool inputs as closed objects; fetch one with tools_schema.

The MCP 2026-07-28 changelog loosens inputSchema and outputSchema to allow any JSON Schema 2020-12 keywords, and adds $ref resolution requirements. For a Sume client that changes little: Sume's tool inputs come from one objectSchema helper that emits type: "object", properties, required and additionalProperties: false.
Spec text is from the MCP changelog; Sume details are from the MCP server source and the tools and gates docs, read 2026-10-01.
What did the spec loosen?
Per the changelog: inputSchema and outputSchema may use any JSON Schema 2020-12 keywords, structuredContent may be any JSON value, and $ref resolution requirements and resource bounds for composition keywords were added. A client should therefore be ready to see keywords beyond plain type and properties from servers that use them.
What shape do Sume's tool schemas have?
| Piece | What the source does |
|---|---|
objectSchema(properties, required) | Returns type: "object" with the given properties and required |
| Unknown keys | Rejected: additionalProperties: false |
| No-argument tool | emptyInputSchema, an empty object schema |
$ref | Not used in the MCP input-schema files I checked |
| Composition | anyOf appears in at least one property (a filter that takes a string or an array) |
How do I read one tool's contract?
Call tools_schema with the tool name. The docs describe it as fetching one tool contract by name, and say to always discover the live contract with tools_list and tools_schema instead of assuming parity with the HTTP API. For big tool sets see progressive discovery.
What should my client do?
Validate with a full 2020-12 validator rather than a hand-rolled type and properties reader, so a keyword like anyOf is handled the same on every server. Do not hard-code a schema copy: it can change, and additionalProperties: false means a stale extra key is rejected rather than ignored. Paid and write tools also need idempotency_key, which is part of the contract you fetch.
Sources
Related posts
More in Developers
- MCP tools/list order and prompt caching: keying a Sume cache
Sume's tools/list returns one array in registry order with no cursor. Key your tool-list cache on credential and scope, and refetch when either changes.
- MCP tools/list different per user: what Sume's list varies by
MCP 2026-07-28 says list endpoints no longer vary per connection. Sume's tools/list still varies by credential: OAuth read, OAuth write or an API key.
- MCP workload identity federation: Sume takes code grant only
MCP's roadmap names Workload Identity Federation. Sume's hosted MCP advertises only the authorization_code grant, so headless workloads use an API key.
- MCP x-mcp-header and Mcp-Param headers vs Sume idempotency_key
The MCP 2026-07-28 spec can mirror tool parameters into Mcp-Param headers via x-mcp-header. Sume takes idempotency_key as a tool argument in the JSON body.
Written by Sume