Replicate MCP discovery via server.json vs Sume's MCP URL
Replicate publishes /.well-known/mcp/server.json for the official MCP Registry. Sume documents one hosted MCP URL and OAuth metadata. How each client connects.

Replicate made its MCP server discoverable through the official MCP Registry on February 10, 2026, by publishing metadata at /.well-known/mcp/server.json. Sume's docs take a different route: you add one hosted URL, https://mcp.sume.com/mcp, and sign in with OAuth or an API key, and Sume documents OAuth metadata endpoints under mcp.sume.com/.well-known, not a registry listing.
Replicate's side is from its changelog, read on 2026-10-03. Sume's side is from MCP OAuth and API keys, the MCP quickstart, and MCP tools and gates.
What did Replicate ship?
The changelog entry says Replicate published metadata at /.well-known/mcp/server.json, following the MCP server.json specification, so clients that read the official MCP Registry can install the server without hosting code, only metadata about where to find it. It names VS Code as the best integration (enable chat.mcp.gallery.enabled, then search @mcp in Extensions) and Claude Desktop through its curated directory under Settings, Extensions, Browse extensions. ChatGPT, Cursor, and LM Studio need the server URL or a config file edit.
It also says the metadata exposes a --tools choice between all and code mode at install time.
How do you connect to Sume's MCP?
Sume's quickstart gives one production URL and three client paths. For Claude Code the commands are two lines. The docs advise OAuth for interactive clients and say not to paste API keys into chat.
claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sumeWhat metadata does Sume publish?
The OAuth page lists two public metadata endpoints, https://mcp.sume.com/.well-known/oauth-protected-resource/mcp and https://mcp.sume.com/.well-known/oauth-authorization-server, and an OAuth resource audience of https://mcp.sume.com/mcp. Those let a client discover how to sign in. They are authorization metadata, which is a different thing from a registry listing that tells a client where a server exists.
The pages we read do not mention a server.json or a registry entry for Sume. If you want a one-click install in a registry-aware client, check the client's own listing rather than assuming Sume appears in it.
| Item | Replicate | Sume |
|---|---|---|
| Discovery file | /.well-known/mcp/server.json | OAuth metadata under mcp.sume.com/.well-known |
| Install path | Registry-aware clients, or URL and config | Add https://mcp.sume.com/mcp, then OAuth |
| Tool selection | --tools all or code at install | Scopes: mcp:read, optional mcp:write |
| Paid actions | Not covered on the page we fetched | Idempotency key required; dry_run and max_spend_usd optional |
What does the scope model change for an agent?
Sume's hosted MCP defaults to read-only visibility under mcp:read. Mutating and paid tools stay hidden until the session has mcp:write or an API key, and there is no mcp:paid scope: spend is governed by the wallet and admission. A read-only connection is a safe first step while you test.
Every write or paid tool requires an idempotency_key, and dry_run=true previews cost without submitting.
Which should you pick?
If your team lives in VS Code and wants a gallery install for Replicate, use the registry. For Sume, plan on a manual add with the URL, since the docs describe that path. Either way, test with a read-only call first: ask the agent for mcp_health or tools_list on Sume, and confirm the tools you expect appear before you grant write.
What does a first connection check look like?
After you add either server, do the same three checks. First, confirm the client shows the server as connected. Second, call a read-only tool. On Sume that is mcp_health or tools_list; the docs say mcp_health reports endpoint readiness, auth source, and safety posture, and you want the auth source to read mcp_oauth if you signed in with OAuth. Third, confirm the tool list matches your scope: a read-only session should show no mutating or paid tools.
If the list is empty or missing tools you expect, it is usually the scope. Reconnect and turn Write on at the consent screen, which defaults to off.
What does not change between the two?
Neither registry listing nor OAuth metadata decides what an agent may spend. On Sume, spend is governed by the wallet and admission, with dry_run and max_spend_usd as optional guards. Whatever route you used to install the server, give the agent a budget in its instructions and keep Write off until a task needs it.
Sources
Related posts
More in Comparisons
- Replicate allow_fallback_model: Nano Banana Pro vs Sume
Replicate can fall back from Nano Banana Pro to Seedream 5.0 lite and bills the fallback. Sume's allow_fallbacks is accepted but has no effect. What to do.
- Replicate predictions source=web filter vs Sume jobs list
Replicate lets you list only web-created predictions, limited to 14 days. Sume's GET /v1/jobs lists only jobs your key's member created. How to scope a list.
- Runway Model Router credit ceiling vs Sume max_spend_usd
Runway's per-modality credit ceiling removes costly models before ranking and errors if none fit. Sume's max_spend_usd caps one call. How the two caps differ.
- Runway Model Router dryRun: preview the pick, and what Sume Auto shows
Runway's Model Router has a dryRun preview, per-modality credit ceilings and cost, latency or quality goals. Sume's sume/auto never says which family ran.
Written by Sume