claude -p says Sume needs authentication after one refused write call

Claude Code 2.1.286 stopped headless runs flagging a server as unauthenticated after one refused call. Sume's scope refusal is a tool result, not a 401.

5 min readSume
All posts

If a headless Claude Code run reported that your Sume server needs authentication right after a write call was refused, that was a client-side status bug, and the 2.1.286 changelog lists a fix: headless sessions no longer report an MCP server as needing authentication after one refused call, even though later calls succeed (Claude Code changelog, read 2026-10-04).

A refused write on Sume is not an authentication failure. When a read-only OAuth session calls a mutating tool, Sume answers with insufficient_scope as a tool result, and the rest of the session keeps working.

Why a refused write looks like an auth problem

From a client's point of view, a refused call and a failed sign-in can look alike: a call came back without the data you wanted, with the word scope or auth in it. Before the fix, the headless session could treat one such refusal as proof that the server needed sign-in, and print a reminder to authenticate.

The fix matters for scripts, because a single status line can fail a pipeline that checks for "needs authentication".

What Sume actually returns

Under OAuth, mcp:read sessions see read-only tools. A mutating call without mcp:write returns insufficient_scope (MCP OAuth and API keys). It is returned as a tool error carrying the required_scope, not as an HTTP 401 or 403 that restarts the sign-in flow.

Telling a scope refusal from a real auth failure on Sume's hosted MCP. Sources: Claude Code changelog and Sume docs, read 2026-10-04.
SymptomWhat it meansWhat to check
Tool result with insufficient_scope and required_scopeToken is valid but lacks mcp:writeReconnect with Write on, or use an API key
Every call fails, including readsMissing, expired or invalid credentialRun mcp_health; sign in again
A write tool is not in tools_listSession is read-onlyExpected under mcp:read

A short diagnostic for a pipeline

Do not branch on the phrase "needs authentication" alone. Check with a read call first, so a refused write is not mistaken for a dead session.

  • Call mcp_health and read the auth source. A valid token shows mcp_oauth, an API key shows its own source.
  • Call tools_list. If write tools are missing, the session is read-only by design.
  • If reads work and a write returns insufficient_scope, change the grant, not the sign-in.
  • Use an API key for unattended automation that must write, since a headless run cannot answer a consent page.

Keep the paid call safe once write is on

When write is granted, every paid or write call needs an idempotency_key. Add dry_run before an expensive call and max_spend_usd when you want a ceiling, because the server enforces that cap only when you send it.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume