claude mcp logout: how to sign out of a remote MCP server

Run claude mcp logout <name> or pick Clear authentication in /mcp to remove stored credentials. What that does for Sume's hosted MCP, and the hourly token.

5 min readSume
All posts

Run claude mcp logout sume to clear the stored credentials for a remote MCP server, or open /mcp in a session and choose Clear authentication from that server's menu. Then claude mcp login sume signs in again, and it is the way to switch accounts or grant a different scope.

Claude Code's commands come from its MCP documentation, read 2026-09-29. The Sume side comes from MCP OAuth and API keys and, where marked, current code.

Which sign-out options does Claude Code have?

The page's tips list Clear authentication as the way to revoke access. It does not say the command calls the server's revocation endpoint, so treat it as removing what Claude Code holds locally.

From the Claude Code MCP page, read 2026-09-29.
ActionEffect
claude mcp logout <name>Clears stored credentials for that server
Clear authentication in /mcpClears them from a session; also discards that server's cached tool list
claude mcp remove <name>Deletes the server entry, including the OAuth tokens and client registration stored for it
claude mcp login <name>Runs the OAuth flow again from your shell

What happens to the token on Sume's side?

In current code, a Sume MCP access token lasts one hour and no refresh token is issued, and the authorization server has a /oauth/revoke endpoint. Once Claude Code no longer holds the token, it stops being sent. A token that was copied elsewhere would otherwise lapse on its own within the hour.

An API key is a separate credential from the OAuth token. See Sume API keys, scopes and hosts for what a key can reach, and rotate it if it leaked.

How do I sign back in with different scopes?

Log out, then log in and use the consent page. OAuth requires mcp:read; the Write toggle is off by default and grants mcp:write when turned on, per MCP OAuth and API keys. With read only, tools that mutate or spend return insufficient_scope. Signing in again is how you move between the two.

claude mcp logout sume
claude mcp login sume

Should I use logout or remove?

Use logout when you want to keep the server entry and sign in again, for example to change the consent scopes or account. Use remove when the server should be gone from your config. Per Claude Code's page, removing a remote server also deletes the OAuth tokens and client registration it stored, so the next add starts a fresh registration.

Clear authentication in /mcp is the in-session equivalent of logout, and it also discards that server's cached tool list, so the next connection fetches the tools again.

Why does the server show needs authentication after an hour?

Most likely that is the one-hour token lapsing, since no refresh token is issued, rather than a logout you did. The fix is the same two commands, or the API-key path for unattended runs. See MCP server needs authentication in Claude Code for the status and how it clears.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume