Claude Code MCP insufficient_scope: re-authenticate to grant write

Sume's hosted MCP starts read-only. If Claude Code pins oauth.scopes, add mcp:write, run /mcp and re-authenticate, or the new token still lacks write.

4 min readSume
All posts

Add mcp:write to the server's oauth.scopes in your Claude Code config, run /mcp, and choose Re-authenticate on the Sume server. Then turn Write on at Sume's consent page. Skip either step and the new token is still read-only.

Why it happens

Sume's hosted MCP requires mcp:read and treats mcp:write as opt-in. A read-only session sees only read tools, and a call that changes data returns insufficient_scope. Claude Code's docs describe the matching client side: if a server returns a 403 insufficient_scope and the scope is not in your pinned oauth.scopes, you add it and authenticate again, because Claude Code requests the pinned scopes rather than the scope the server named.

Claude Code stores local-scope servers in its user configuration file by default, and project scope writes to a .mcp.json file that your team can commit. Pin scopes in the place that matches how widely you want the write grant shared.

Pin both scopes

Connect first with the command from the docs, then pin scopes in config if you want to control them:

A quick way to confirm the grant worked: after re-authenticating, ask the agent to list Sume's tools. A write session sees the tools that change data and the paid tools, while a read-only session sees only read tools. If the list did not grow, the token you hold is the old one, so check that the pinned scopes string includes both values separated by a space.

claude mcp add --transport http sume https://mcp.sume.com/mcp

{
  "mcpServers": {
    "sume": {
      "type": "http",
      "url": "https://mcp.sume.com/mcp",
      "oauth": { "scopes": "mcp:read mcp:write" }
    }
  }
}

Order of operations

Re-authentication steps for Claude Code and Sume (read 2026-10-06)
StepWhereWhat to check
1Configoauth.scopes lists mcp:write; oauth.scopes wins over scopes the server discovers
2/mcp in Claude CodePick Re-authenticate on the sume server
3Sume consent pageRead is locked on; flip the Write toggle, then continue
4First paid callInclude an idempotency_key; dry_run previews cost first

What re-authentication will not fix

Sume does not issue refresh tokens: access tokens last one hour and a refresh_token grant is ignored. Claude Code says it refreshes a token after a 401 and retries once, but with Sume that leads to another sign-in, not a silent refresh. For unattended work, give the agent an API key header instead of OAuth, and set max_spend_usd on each paid call so one runaway loop cannot drain the wallet. Sume's allow_write and allow_paid legacy flags cannot bypass a missing mcp:write scope, so do not bother adding them.

Sources

More in Developers

All Developers posts

Written by Sume