Claude Code 2.1.288 re-authenticate prompt: Sume's mcp:write
Claude Code 2.1.288 asks you to re-authenticate when an MCP server wants more OAuth scope mid-call. What that means for a read-only Sume grant.

If a Sume tool call in Claude Code stops on a missing permission, update to 2.1.288 or later and re-authenticate with Write turned on. That release added a re-authenticate prompt for the case where an MCP server asks for more OAuth scope during a tool call, and Sume's hosted MCP has exactly one scope step to ask for: mcp:write.
The release line comes from the Claude Code changelog, read 2026-10-03: version 2.1.288 (October 2, 2026) lists "Added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call". The changelog does not say which server response triggers it, so this post does not claim how Sume's replies map onto the prompt. It covers what Sume's docs say about scopes and what to do when the prompt, or a plain error, appears.
What did Claude Code 2.1.288 change for MCP sign-in?
Before this release, a server that wanted a wider grant mid-session left you to notice the failure and sign in again by hand. The changelog entry says Claude Code now shows a re-authenticate prompt at that moment. Nothing in the entry changes how the first sign-in works.
The same release also changed how URL prompts from servers are handled and fixed a double-run bug for very large MCP results. Those are separate questions, covered in the related posts below.
Which scope does a Sume tool call need?
Sume's OAuth and API keys page defines two scopes: mcp:read (required) and mcp:write (opt-in on the consent page). There is no mcp:paid scope. Granting write always includes read.
A session with only mcp:read sees read-only tools. A call to a mutating tool returns insufficient_scope. Paid generation tools such as generate_image or avatars_create are in that mutating group, so they need mcp:write too.
| Scope | Set at | Tools you can call |
|---|---|---|
| mcp:read | Consent page, always on | Read-only tools such as jobs_list, assets_get, catalog_list, crawl_scrape |
| mcp:write | Consent page, Write toggle (default off) | Also mutating and paid tools such as jobs_cancel, assets_create, generate_image |
| mcp:paid | Does not exist | Spend is wallet and admission, not a scope |
How do I re-authenticate with Write turned on?
Accept the re-authenticate prompt if Claude Code shows it. If it does not, sign in again yourself with the commands from the MCP quickstart, then flip Write on at the consent step. The consent page is on the MCP host, not on app.sume.com.
claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume
# On the consent page: leave Read on, switch Write on, continue.
# Then ask Claude Code to call mcp_health and check authenticated.auth_source.Should I turn Write on for every session?
Only if the session creates things. Read-only discovery, job status, and result reads work without it, and a read-only token cannot spend money by accident. When you do enable write, remember the gates that remain: paid and write calls need an idempotency_key, and dry_run=true or max_spend_usd are there when you want a preview or a cap.
API-key remote MCP is the other path. It sees the full tool set without a scope step, which is why the docs keep it for automation. For an interactive session, the re-authenticate flow is the safer default.
What Sume does not do here
Sume does not offer a way to widen scope without a new consent, and it does not mint an API key for an OAuth client as a workaround. Its docs say an OAuth token is not an API key and sume login does not broker hosted MCP tokens. If you rotate scopes, plan on one extra browser sign-in.
What should an agent do when a scope error appears?
Treat a scope error as a stop, not a retry. A retry with the same token fails the same way, and Sume's docs say legacy allow_write or allow_paid arguments cannot bypass a missing mcp:write scope. The useful reply from an agent is short: name the tool it wanted, say the session is read-only, and ask the person to re-authenticate with Write on.
It also helps to put that rule in the project instructions you give the client, so a subagent does not loop on a call that cannot succeed. A single line is enough: if a Sume tool returns insufficient_scope, stop and ask for Write access.
After you sign in again, confirm the new grant before spending anything. Call mcp_health and read the auth source, then tools_list: with Write on, mutating and paid tools such as generate_image appear in the list; with Read only, they stay hidden. Then use dry_run=true on the first paid call so the preview shows cost before a job exists.
Sources
Related posts
More in Integrations
- Claude Code URL prompts wait for "I'm done": does Sume send any?
Claude Code 2.1.288 now waits for I'm done, continue after an MCP URL prompt. Sume signs you in through OAuth, and its server has no elicitation code.
- claude mcp add-from-claude-desktop: will your Sume server import?
Claude Code can import Claude Desktop MCP servers on macOS and WSL, but only names with letters, digits, hyphens and underscores. Sume is named sume.
- Claude Code cloud sessions: where Sume hosted MCP comes from
In Claude Code cloud sessions the host passes in MCP servers from your claude.ai organization settings. Add Sume as a connector there, not in a local file.
- Claude Desktop Code tab subagents lose a "memory" MCP server
Claude Code 2.1.288 fixed subagents in the Claude Desktop Code tab getting no tools from a user MCP server named memory. Why Sume stays named sume.
Written by Sume