Claude Code MCP OAuth token lost, keychain locked: Sume tokens
Claude Code 2.1.281 stops a locked macOS keychain from dropping stored MCP OAuth tokens. A Sume token lasts one hour with no refresh grant.

Claude Code 2.1.281 fixed macOS credential writes that dropped stored MCP OAuth tokens when the login keychain was locked. For Sume, a stored token still lives only one hour: the server issues no refresh grant, so after that you sign in again with claude mcp login sume, or use an API key for unattended work.
Vendor fact from the Claude Code changelog; Sume facts from the code and MCP OAuth docs, read 2026-10-01.
What did the keychain fix change?
The 2.1.281 entry (September 23, 2026) says credential writes could drop stored MCP OAuth tokens, or delete the keychain entry, when the login keychain was locked, for instance right after wake. That was a client-side storage bug, fixed in Claude Code.
How long does a Sume token last?
The Sume OAuth package sets the access token lifetime to 60 * 60 seconds. Its client registration code notes that clients such as Cursor often advertise refresh_token, but it is ignored because refresh is not implemented yet and only authorization_code is stored. Registered clients are public clients: the metadata lists none as the token endpoint auth method.
| Property | Value |
|---|---|
| Access token lifetime | 3600 seconds |
| Refresh grant | Not implemented; refresh_token is ignored |
| Client authentication | none (public clients) |
| Scopes | mcp:read required, mcp:write opt-in |
What should I do when the token expires?
Run the login again: claude mcp login sume. A locked or unlocked keychain does not extend the hour, so an expiry after sixty minutes is expected behavior, not the bug the changelog describes. Background on the same limit is in Sume MCP access tokens last one hour.
Is there a path without interactive sign-in?
Yes. The docs say API-key remote MCP remains the other path for automation that does not speak OAuth. Keep the key in an environment variable, never in chat. See API key or OAuth for MCP.
Sources
Related posts
More in Developers
- CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTH and Sume server instructions
Claude Code 2.1.280 lets CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTH change the 2,048-character cap. Sume's instructions are long; use tools_schema.
- claude mcp add refused: managed settings, plugins only, Sume
Claude Code 2.1.284 refuses claude mcp add when managed settings limit MCP servers to plugins. What the Sume remote URL needs from your admin.
- Claude Code MCP connector lists no tools: Sume handshake versions
Claude Code 2.1.286 fixed connectors showing no tools after a server dropped an older handshake. Sume answers 2025-03-26, 2025-06-18 and 2025-11-25.
- Claude Code MCP images saved to file: Sume returns a media URL
Claude Code 2.1.283 saves images from MCP tools to a file. Sume tool results are text with a media.sume.com URL, so keep the URL as the durable reference.
Written by Sume