claude mcp logout: how to sign out of a remote MCP server
Run claude mcp logout <name> or pick Clear authentication in /mcp to remove stored credentials. What that does for Sume's hosted MCP, and the hourly token.

Run claude mcp logout sume to clear the stored credentials for a remote MCP server, or open /mcp in a session and choose Clear authentication from that server's menu. Then claude mcp login sume signs in again, and it is the way to switch accounts or grant a different scope.
Claude Code's commands come from its MCP documentation, read 2026-09-29. The Sume side comes from MCP OAuth and API keys and, where marked, current code.
Which sign-out options does Claude Code have?
The page's tips list Clear authentication as the way to revoke access. It does not say the command calls the server's revocation endpoint, so treat it as removing what Claude Code holds locally.
| Action | Effect |
|---|---|
claude mcp logout <name> | Clears stored credentials for that server |
Clear authentication in /mcp | Clears them from a session; also discards that server's cached tool list |
claude mcp remove <name> | Deletes the server entry, including the OAuth tokens and client registration stored for it |
claude mcp login <name> | Runs the OAuth flow again from your shell |
What happens to the token on Sume's side?
In current code, a Sume MCP access token lasts one hour and no refresh token is issued, and the authorization server has a /oauth/revoke endpoint. Once Claude Code no longer holds the token, it stops being sent. A token that was copied elsewhere would otherwise lapse on its own within the hour.
An API key is a separate credential from the OAuth token. See Sume API keys, scopes and hosts for what a key can reach, and rotate it if it leaked.
How do I sign back in with different scopes?
Log out, then log in and use the consent page. OAuth requires mcp:read; the Write toggle is off by default and grants mcp:write when turned on, per MCP OAuth and API keys. With read only, tools that mutate or spend return insufficient_scope. Signing in again is how you move between the two.
claude mcp logout sume
claude mcp login sumeShould I use logout or remove?
Use logout when you want to keep the server entry and sign in again, for example to change the consent scopes or account. Use remove when the server should be gone from your config. Per Claude Code's page, removing a remote server also deletes the OAuth tokens and client registration it stored, so the next add starts a fresh registration.
Clear authentication in /mcp is the in-session equivalent of logout, and it also discards that server's cached tool list, so the next connection fetches the tools again.
Why does the server show needs authentication after an hour?
Most likely that is the one-hour token lapsing, since no refresh token is issued, rather than a logout you did. The fix is the same two commands, or the API-key path for unattended runs. See MCP server needs authentication in Claude Code for the status and how it clears.
Sources
Related posts
More in Integrations
- Claude Sonnet 5.5 MCP tools in Claude Code: add Sume video/image tools
Claude Code v2.1.284 made Sonnet 5.5 the default Sonnet. Add Sume's hosted MCP server in two commands and give that model video and image generation tools.
- Codex bearer_token_env_var: connect Sume MCP with an API key, no OAuth
Set url and bearer_token_env_var in Codex's config.toml so a Sume API key from the environment authenticates hosted MCP, with enabled_tools to shorten the list.
- Codex MCP OAuth client registration: CIMD or DCR for Sume
Codex registers with Sume's hosted MCP server by Dynamic Client Registration, because Sume's metadata advertises no Client ID Metadata Document support.
- Codex mcp-server command removed: does Sume still work?
Codex removed `codex mcp-server` on 2026-09-05. Connecting Codex to Sume's hosted MCP server uses `codex mcp`, which the changelog says continues.
Written by Sume