Claude Code scope re-authenticate prompt vs unattended Sume runs
Claude Code 2.1.288 prompts to re-authenticate when a server asks for more OAuth scope. Unattended runs cannot answer it, so grant write up front.

Claude Code 2.1.288 added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call (Claude Code changelog, read 2026-10-04). That is helpful when you are at the keyboard. In an unattended run nobody can answer it, so decide the scope before the run starts: grant mcp:write at consent, or use an API key.
Whether that prompt appears for a Sume refusal is worth testing, because Sume reports a missing scope as a tool result carrying insufficient_scope and required_scope, not as an HTTP step-up challenge.
How Sume gates writes
The hosted endpoint offers two OAuth scopes, mcp:read and mcp:write. Read is required and read-only. Write is opt-in on the consent page, where the toggle defaults to off, and granting write always includes read. There is no mcp:paid scope: paid submits are governed by wallet and admission. API keys get the full tool set (MCP OAuth and API keys).
Why a mid-run upgrade is a poor fit for automation
A prompt needs a person. A scheduled or headless job has none, so the run would stall or fail at the first write. There is a second constraint: Sume's OAuth access token lasts 3600 seconds and the server issues no refresh token, so a long-lived job on OAuth would need a fresh sign-in anyway.
| Option | Works unattended | Notes |
|---|---|---|
| OAuth with mcp:read only | Reads only | A write returns insufficient_scope with required_scope |
| OAuth with Write granted at consent | For up to an hour | Access token lasts 3600 seconds; no refresh token is issued |
| API key | Yes | Full tool set; every write and paid call needs idempotency_key |
A practical split
Use OAuth, read-only, for people exploring a catalog and for checks. Use an API key for jobs that must generate, stored as a secret in the runner, with the paid gates in the prompt. Keep the interactive upgrade path for a person who decides, mid-session, that a task is worth the spend.
- Unattended writer: API key,
dry_runfirst,max_spend_usdon every call. - Interactive helper: OAuth read-only, reconnect with Write when needed.
- Never rely on a prompt that no one will see.
If a run already hit the wall
Read the tool result, find required_scope, and change the credential rather than retrying. Retrying the same call under the same token returns the same refusal, and nothing was submitted, so there is no job to clean up.
Sources
Related posts
More in Developers
- Claude Code 2.1.289 plugin loading fix: recheck Sume MCP after upgrade
Claude Code 2.1.289 fixed plugin loading after an upgrade. A four-call read-only check confirms the Sume MCP connection and scopes before you run a paid job.
- Claude Code's 60 s MCP timeout: Sume sync waits 30 s, video polls
Claude Code 2.1.287 caps MCP tool calls at 60 seconds per server. Sume's 30 s sync wait and 55 s jobs_wait fit under it; a video render needs repeated waits.
- Claude Code MCP startup wait: Sume tools missing on the first -p turn
Headless Claude Code bounds how long turn one waits for MCP servers with CLAUDE_CODE_MCP_STARTUP_WAIT_MS. Name Sume tools and check mcp_health first.
- Claude Files API is GA: review Sume outputs by job id and media URL
The Claude Files API left beta on Aug 19. When Claude reviews generated media, store the Sume job id and media.sume.com URL, not raw provider links.
Written by Sume