Claude Code MCP OAuth token lost, keychain locked: Sume tokens

Claude Code 2.1.281 stops a locked macOS keychain from dropping stored MCP OAuth tokens. A Sume token lasts one hour with no refresh grant.

4 min readSume
All posts

Claude Code 2.1.281 fixed macOS credential writes that dropped stored MCP OAuth tokens when the login keychain was locked. For Sume, a stored token still lives only one hour: the server issues no refresh grant, so after that you sign in again with claude mcp login sume, or use an API key for unattended work.

Vendor fact from the Claude Code changelog; Sume facts from the code and MCP OAuth docs, read 2026-10-01.

What did the keychain fix change?

The 2.1.281 entry (September 23, 2026) says credential writes could drop stored MCP OAuth tokens, or delete the keychain entry, when the login keychain was locked, for instance right after wake. That was a client-side storage bug, fixed in Claude Code.

How long does a Sume token last?

The Sume OAuth package sets the access token lifetime to 60 * 60 seconds. Its client registration code notes that clients such as Cursor often advertise refresh_token, but it is ignored because refresh is not implemented yet and only authorization_code is stored. Registered clients are public clients: the metadata lists none as the token endpoint auth method.

Sume MCP OAuth token facts from code, read 2026-10-01
PropertyValue
Access token lifetime3600 seconds
Refresh grantNot implemented; refresh_token is ignored
Client authenticationnone (public clients)
Scopesmcp:read required, mcp:write opt-in

What should I do when the token expires?

Run the login again: claude mcp login sume. A locked or unlocked keychain does not extend the hour, so an expiry after sixty minutes is expected behavior, not the bug the changelog describes. Background on the same limit is in Sume MCP access tokens last one hour.

Is there a path without interactive sign-in?

Yes. The docs say API-key remote MCP remains the other path for automation that does not speak OAuth. Keep the key in an environment variable, never in chat. See API key or OAuth for MCP.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume