claude mcp login over SSH: sign in to Sume with no browser

On a machine with no browser, claude mcp login prints the sign-in URL. Open it on your laptop, then paste the redirect URL back. Sume's MCP works this way.

5 min readSume
All posts

Yes, you can sign in to a remote MCP server from an SSH session. Run claude mcp login sume (add --no-browser to force it). Claude Code prints the authorization URL instead of opening a browser, you open it on your own computer, and you paste the full address you land on back into the terminal prompt.

Claude Code's behavior comes from its MCP documentation, read 2026-09-29. The Sume steps come from MCP OAuth and API keys and the MCP quickstart.

How do I run the login step by step?

The docs' quickstart shows the same two commands for the first connection, claude mcp add then claude mcp login. Only the browser step changes on a server with no display.

  • Add the server once: claude mcp add --transport http sume https://mcp.sume.com/mcp.
  • Connect with ssh -t, because the command needs an interactive terminal for the paste step.
  • Run claude mcp login sume --no-browser. Claude Code prints the authorization URL.
  • Open that URL on your laptop. It goes to https://mcp.sume.com/oauth/authorize, then to Sume's consent page on the MCP host.
  • Sign in. The consent page shows Permissions: Read is locked on, and the Write toggle is off by default. Continue.
  • After you continue, the browser is redirected back to a local address. If that shows a connection error, that is expected on this setup: copy the full URL from the address bar and paste it into the prompt in the SSH session.

Why do I have to paste a URL?

OAuth ends with a redirect back to the client, and on a remote box your laptop's browser is not the machine Claude Code runs on. Claude Code's docs cover this: if the browser redirect fails with a connection error after authenticating, paste the full callback URL from the address bar into the URL prompt.

In current code, Sume accepts http redirects to localhost or 127.0.0.1, so the local address Claude Code registers is allowed.

From the Claude Code MCP page, read 2026-09-29.
Command or flagWhat it does
claude mcp login <name>Runs the server's OAuth flow from your shell
--no-browserForces the URL prompt even when a local browser is detected
claude mcp logout <name>Clears the stored credentials for that server
ssh -tGives the session an interactive terminal for the paste step

What does the consent screen grant?

Read-only by default. OAuth requires mcp:read, and turning Write on at consent also grants mcp:write. With read only, tools that mutate or spend return insufficient_scope. If you need paid tools on a headless box, grant Write at consent or use an API key instead.

Do I have to repeat this every hour?

In current code, a Sume MCP access token lasts one hour and the server issues no refresh token, so a remote box that stays up for days will need a fresh paste-back sign-in each time the hour runs out. For unattended or scheduled runs, Sume's docs point to the API-key path instead: send Authorization: Bearer $SUME_API_KEY or x-api-key on the connection, and keep the key server-side as authentication describes.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume