codex mcp add --oauth-client-secret: do you need it for Sume?

Codex CLI 0.158.0 added --oauth-client-secret for MCP servers that require a pre-registered client secret. Sume's OAuth uses public clients, so you can skip it.

4 min readSume
All posts

You do not need codex mcp add --oauth-client-secret for Sume. Codex CLI 0.158.0, released September 28, 2026, added support for MCP servers that require a pre-registered OAuth client secret, including through that flag. Sume's hosted MCP is not that kind of server: its authorization server metadata lists token_endpoint_auth_methods_supported as none and offers a registration endpoint at /oauth/register, so Codex can register itself as a public client and use PKCE, with no secret to store.

The Codex facts are from the ChatGPT and Codex changelog, read 2026-10-01. The Sume facts are from the repository's OAuth metadata and OAuth and API keys.

When does a client secret apply?

A pre-registered client is for servers that hand you a client id and secret in a developer console and refuse dynamic registration, which is how many SaaS MCP servers with fixed app registrations work. The new flag lets Codex hold that secret. Sume does not issue one: there is no console step where you create an OAuth app for Codex, and a secret you invent would not be checked.

Codex 0.158.0 entry and Sume OAuth metadata, read 2026-10-01.
Server typeWhat you give CodexExample fit
Dynamic registration, public clientNothing but the URLSume hosted MCP
Pre-registered client with secretClient id and --oauth-client-secretServers that issue an app secret
Static key in a headerAn environment variable name for the bearer tokenSume with an API key

What should I run instead?

Add the server by URL and log in for the server name you chose, as in Sume's quickstart: Codex discovers the protected-resource metadata, then sends you to https://mcp.sume.com/oauth/authorize, which continues to the consent page on the MCP host. Leave Write off for exploration and on when Codex should create media.

If you run Codex unattended, skip OAuth. Sume's access tokens last one hour and no refresh token is issued, so an API key in a bearer header is the stable choice. Paid calls still need an idempotency_key.

Limits

I only read the changelog line for 0.158.0, not the full flag reference, so check codex mcp add --help for exact syntax on your build. If a future Sume release adds confidential clients, this answer changes; the metadata above is what the repository serves today.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume