claude -p says Sume needs authentication after one refused write call
Claude Code 2.1.286 stopped headless runs flagging a server as unauthenticated after one refused call. Sume's scope refusal is a tool result, not a 401.

If a headless Claude Code run reported that your Sume server needs authentication right after a write call was refused, that was a client-side status bug, and the 2.1.286 changelog lists a fix: headless sessions no longer report an MCP server as needing authentication after one refused call, even though later calls succeed (Claude Code changelog, read 2026-10-04).
A refused write on Sume is not an authentication failure. When a read-only OAuth session calls a mutating tool, Sume answers with insufficient_scope as a tool result, and the rest of the session keeps working.
Why a refused write looks like an auth problem
From a client's point of view, a refused call and a failed sign-in can look alike: a call came back without the data you wanted, with the word scope or auth in it. Before the fix, the headless session could treat one such refusal as proof that the server needed sign-in, and print a reminder to authenticate.
The fix matters for scripts, because a single status line can fail a pipeline that checks for "needs authentication".
What Sume actually returns
Under OAuth, mcp:read sessions see read-only tools. A mutating call without mcp:write returns insufficient_scope (MCP OAuth and API keys). It is returned as a tool error carrying the required_scope, not as an HTTP 401 or 403 that restarts the sign-in flow.
| Symptom | What it means | What to check |
|---|---|---|
| Tool result with insufficient_scope and required_scope | Token is valid but lacks mcp:write | Reconnect with Write on, or use an API key |
| Every call fails, including reads | Missing, expired or invalid credential | Run mcp_health; sign in again |
| A write tool is not in tools_list | Session is read-only | Expected under mcp:read |
A short diagnostic for a pipeline
Do not branch on the phrase "needs authentication" alone. Check with a read call first, so a refused write is not mistaken for a dead session.
- Call
mcp_healthand read the auth source. A valid token showsmcp_oauth, an API key shows its own source. - Call
tools_list. If write tools are missing, the session is read-only by design. - If reads work and a write returns
insufficient_scope, change the grant, not the sign-in. - Use an API key for unattended automation that must write, since a headless run cannot answer a consent page.
Keep the paid call safe once write is on
When write is granted, every paid or write call needs an idempotency_key. Add dry_run before an expensive call and max_spend_usd when you want a ceiling, because the server enforces that cap only when you send it.
Sources
Related posts
More in Developers
- claude -p killed by timeout or systemd: the Sume job keeps running
A supervisor that kills claude -p does not cancel the Sume job it started. List jobs, then wait or cancel before retrying, or you pay twice.
- claude plugin validate: a clean .mcp.json entry for Sume
Claude Code v2.1.281 makes claude plugin validate check .mcp.json entries. A Sume entry needs only the URL https://mcp.sume.com/mcp and no secret.
- Cloudflare AI Search bills from Nov 1: split retrieval from renders
Cloudflare's October 1 changelog makes AI Search GA with usage billing from November 1, 2026. How to keep retrieval costs separate from Sume render costs.
- Cloudflare Sandbox SDK 1.0: run the Sume SDK inside one
The @sume-com/sdk has no runtime dependencies and needs only fetch and WebCrypto, so it can run in a sandbox. Pass the key as an env var, server-side only.
Written by Sume