Codex 0.161.0 /mcp login: sign in to Sume without leaving the session

Codex 0.161.0 added /mcp login <name> to sign in to an MCP server from a live terminal session. Sign in to Sume with read access first, then add write.

4 min readSume
All posts

In Codex 0.161.0 you sign in to Sume's hosted MCP server from a running terminal session with /mcp login <name>, where <name> is the name you gave the server. The Codex changelog entry for October 7, 2026 says users can sign in to MCP servers from an active terminal session this way. Add Sume with the URL https://mcp.sume.com/mcp, then log in and approve the consent page.

What the changelog says

The Codex facts come from the Codex changelog (read 2026-10-07). The Sume facts come from the OAuth page.

Pick the grant

Sume's consent page asks for mcp:read, which is required and read-only, and shows a Write toggle for mcp:write. There is no mcp:paid scope. The table shows what each grant lets the session do.

What each Sume grant allows (read 2026-10-07)
GrantTools visiblePaid or write call
mcp:read onlyRead-only toolsReturns insufficient_scope
mcp:read and mcp:writeRead, write and paid toolsAllowed; needs an idempotency_key; spend follows the wallet and admission
API key in a headerFull hosted tool setAllowed; needs an idempotency_key

Start read-only

Start with read access. Log in, ask the agent to call mcp_health and tools_list, and confirm that the catalog and job reads work. Log in again with Write on only when you want the agent to start renders. Sume's docs say a missing write scope cannot be bypassed by dry_run or max_spend_usd, so a read-only session is a hard stop for spend.

Tokens stay in their lane

A token from /mcp login is an MCP OAuth token. It is not a Sume API key, and you should not paste it into prompts or use it in the REST API. For scripts and CI, use an API key in a single header instead.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume