MCP URL mode elicitation in Claude Code vs OAuth consent
Claude Code 2.1.281 added MCP URL-mode elicitation, a browser flow a server can request. Sume's browser step is OAuth consent, a different mechanism.

URL-mode elicitation lets an MCP server ask Claude Code to open a browser-based flow in the middle of a session. Sume's hosted server does not use it for sign-in: its browser step is the OAuth authorize and consent pages, which the client opens itself when you log in. The two look alike on screen but are triggered differently.
What did Claude Code add?
Claude Code 2.1.281 added MCP URL-mode elicitation on 2026-07-28 protocol connections, so servers can ask Claude Code to open a browser-based flow. The changelog adds that no waiting dialog is left on screen when the server has no way to confirm completion. The condition matters: it applies to connections speaking the 2026-07-28 protocol.
What is Sume's browser step, then?
Sume documents an OAuth flow. The client connects to https://mcp.sume.com/mcp, receives an OAuth challenge, and sends you to https://mcp.sume.com/oauth/authorize, which redirects to the consent page on the MCP host. That consent shows Permissions with Read locked on and a Write toggle that defaults to off. The client then exchanges the code with PKCE and calls the endpoint with the bearer token.
| URL-mode elicitation | Sume OAuth consent | |
|---|---|---|
| Who starts it | The server asks the client mid-session | The client, after the OAuth challenge |
| Protocol condition | 2026-07-28 protocol connections | Documented for the hosted endpoint |
| Result | Whatever the server's flow does | An access token with mcp:read, plus mcp:write if Write is on |
Will my Sume connection change with this release?
Nothing in the Sume docs describes elicitation, and the MCP 2026-07-28 spec post covers which protocol versions the hosted server negotiates. Keep using claude mcp login sume as the quickstart shows.
Where do I turn Write on?
On the consent page, not in an elicitation. The default grant is read-only, and Write is opt-in; there is no mcp:paid scope, so paid submits go through wallet and admission. Details in OAuth and API keys.
How can I tell which flow I am in?
Look at what started the browser tab. If you ran the login yourself, or the client answered an OAuth challenge from the endpoint, you are in the OAuth flow, and the tab is Sume's consent page on the MCP host with the Permissions block. If a tool call mid-session asked Claude Code to open a page, that is an elicitation, and it is the server's own flow rather than Sume's documented sign-in.
The practical difference is what you end with. The OAuth flow ends with a token that the client stores and sends as a bearer on later calls. The changelog describes elicitation only as a browser-based flow a server can ask for, so do not expect it to grant scopes on Sume.
Sources
Related posts
More in Developers
- Claude skill allowed-tools: pre-approve Sume MCP tools
A skill's allowed-tools field pre-approves tools for one turn and does not restrict the rest. How to list Sume's job tools and leave paid ones prompting.
- Add a video tool to Claude Sonnet 5.5 in the Messages API
Define a generate_video tool with input_schema, run it against Sume's /v1/videos when Claude Sonnet 5.5 returns tool_use, and return the job id as tool_result.
- Claude tool_result is_error: return Sume API errors
When a Sume REST call fails inside your Claude tool loop, send the error back as a tool_result with is_error true and say what to try next. Code and table.
- C# HttpClient default timeout: 100 seconds, and how to set it
HttpClient.Timeout defaults to 100 seconds per request and throws TaskCanceledException. How to set it, and why slow API jobs need polling instead.
Written by Sume