Codex 0.161.0 /mcp login: sign in to Sume without leaving the session
Codex 0.161.0 added /mcp login <name> to sign in to an MCP server from a live terminal session. Sign in to Sume with read access first, then add write.

In Codex 0.161.0 you sign in to Sume's hosted MCP server from a running terminal session with /mcp login <name>, where <name> is the name you gave the server. The Codex changelog entry for October 7, 2026 says users can sign in to MCP servers from an active terminal session this way. Add Sume with the URL https://mcp.sume.com/mcp, then log in and approve the consent page.
What the changelog says
The Codex facts come from the Codex changelog (read 2026-10-07). The Sume facts come from the OAuth page.
Pick the grant
Sume's consent page asks for mcp:read, which is required and read-only, and shows a Write toggle for mcp:write. There is no mcp:paid scope. The table shows what each grant lets the session do.
| Grant | Tools visible | Paid or write call |
|---|---|---|
mcp:read only | Read-only tools | Returns insufficient_scope |
mcp:read and mcp:write | Read, write and paid tools | Allowed; needs an idempotency_key; spend follows the wallet and admission |
| API key in a header | Full hosted tool set | Allowed; needs an idempotency_key |
Start read-only
Start with read access. Log in, ask the agent to call mcp_health and tools_list, and confirm that the catalog and job reads work. Log in again with Write on only when you want the agent to start renders. Sume's docs say a missing write scope cannot be bypassed by dry_run or max_spend_usd, so a read-only session is a hard stop for spend.
Tokens stay in their lane
A token from /mcp login is an MCP OAuth token. It is not a Sume API key, and you should not paste it into prompts or use it in the REST API. For scripts and CI, use an API key in a single header instead.
Sources
Related posts
More in Integrations
- Copilot 'MCP servers in Copilot' policy: admin checklist for Sume
For Copilot Business and Enterprise, an MCP servers in Copilot policy controls remote servers. What an admin checks before allowing Sume's hosted endpoint.
- Deno.cron weekly Sume video run with a per-day idempotency key
A Deno.cron job that starts one Sume Format run each Monday, keyed by UTC date so a double fire replays, skips overlap, and hands the result to a webhook.
- fastmcp-remote: connect a stdio-only MCP host to Sume's hosted MCP
FastMCP 3.4.0 added fastmcp-remote, a bridge from stdio-only hosts to HTTP servers with OAuth for HTTPS. Point it at mcp.sume.com/mcp, verify with mcp_health.
- Forward a finished Sume run to team chat with a signed webhook
A standard-library Python receiver that verifies the sume-v1 signature, rejects an empty secret, and forwards primary_output_url when a Format run ends.
Written by Sume