What a media MCP server should declare at server/discover

MCP 2026-07-28 adds a required server/discover call. A media server has more to say than versions: async jobs, wait limits, scopes. Where Sume documents each.

5 min readSume
All posts

server/discover is a new required RPC in MCP 2026-07-28. It advertises the versions the server supports, its capabilities and its identity, and it doubles as a backward-compatibility probe on STDIO, per the changelog read on 2026-10-03. A media server should also make its async behavior, wait limits and scope rules findable somewhere; Sume documents those in its MCP pages and exposes them through discovery tools.

What the protocol covers and what it leaves out

The changelog lists three things discover advertises. It does not define fields for generation-specific facts such as job lifetimes or spend gates, so those need a home of your own.

The practical split is below. The right column shows where the Sume docs put each item.

Discovery content for a media server (spec read 2026-10-03)
Fact a client needsCovered by server/discover?Where Sume states it
Supported protocol versionsYesNot stated in the Sume docs; test the connection
Capabilities and identityYesMCP overview page
Tool list and per-tool contractThrough list callstools_list and tools_schema
Endpoint health and auth sourceNomcp_health
Jobs are asynchronousNoJobs and results; tools and gates
Scope needed for paid toolsNoOAuth page: mcp:read, mcp:write

What Sume tells a client today

The Sume docs point clients at three read-only tools for discovery. mcp_health confirms the endpoint, the auth source and the safety posture. tools_list lists every tool visible to the session, with safety metadata. tools_schema returns one tool contract by name. The docs say to discover the live contract with those tools and not to assume parity with the HTTP API.

Visibility depends on the session. Under OAuth with only mcp:read, the list shows read-only tools; mutating and paid tools appear with mcp:write or an API key. A cached list from one session should not be reused for another.

What to publish if you run your own server

Keep the protocol-level answer small and accurate, then document the media-specific rules where a human and an agent can both read them. These items belong in your docs, and ideally in each tool description:

  • Which tools are paid and which are free to read.
  • That submits return a job id and results arrive later.
  • The longest a single wait call will hold, and what to do when it expires.
  • Which scope unlocks mutating tools, and whether a spend scope exists at all.
  • Where large outputs go: asset URLs, never inline bytes.

Verify, do not assume

The Sume quickstart suggests a first prompt to the agent: call tools_list and summarize the tools. Add mcp_health to confirm the auth source. If your client speaks the newer protocol, the discovery step happens on connect; if it does not, these tools still work as the explicit check.

claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume
# then ask the agent:
# Call mcp_health, then tools_list, and tell me which tools are paid.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume