Codex account-scoped MCP grant cleanup and Sume's 1-hour token

Codex 0.161.0 adds account-scoped grant cleanup for enterprise MCP authentication. How that sits with Sume's one-hour OAuth token and its revoke endpoint.

3 min readSume
All posts

Account-scoped grant cleanup in Codex cleans up on the client's side; Sume's access tokens end on their own after one hour. The Codex changelog entry for 0.161.0 on October 7, 2026 says enterprise MCP authentication now supports account-scoped grant cleanup. It does not say what is sent to a server. Sume's hosted MCP issues an OAuth access token valid for 3600 seconds and no refresh token.

So an enterprise that cleans up a user's grant in Codex has removed the client's copy. The token on Sume's side stops working at its expiry, and Sume's OAuth metadata also lists a revocation endpoint.

Who holds what

The first two rows come from the Codex changelog; the rest from Sume's OAuth documentation and the server's metadata.

Grant and token lifetime, Codex and Sume (read 2026-10-08)
ItemHeld byLifetime or action
Account-scoped grant (enterprise MCP auth)CodexCleanup added in 0.161.0; details of what it calls are not in the changelog
Sume access tokenCodex's store, issued by Sume3600 seconds, no refresh token
mcp:read scopeSume consentRead-only tools
mcp:write scopeSume consent, opt-inWrite and paid tools appear
Revocation endpointSume OAuth metadata/oauth/revoke, no client authentication

Steps for an admin

Decide what a departure should do. If an employee leaves, the grant cleanup removes their Codex access to MCP servers in the account. If you also want Sume to stop honoring a token that was already issued, that token will end within an hour on its own. For anything faster, use the revocation endpoint with the token, or remove the API key if the person used one.

API keys are different: they are not OAuth tokens, so a client-side grant cleanup does not touch them. Keep a list of which keys exist and who holds them.

  • Prefer OAuth for people and API keys only for unattended jobs.
  • Keep Write off at consent unless the person needs paid tools.
  • Rotate any API key a departing teammate could have copied.

Why the hour matters

An hour is short enough that a forgotten session cannot stay valid for long, and long enough that a render started in that window completes on Sume's side. A job you submitted before the token ended keeps running after the token ends; the token gates new calls, not jobs already accepted. That is useful when someone leaves mid-render: the work finishes and sits in the account, and you can read it with a new credential. Plan who owns a finished job after a person's access goes away.

What Sume does not do

Sume does not learn about Codex's cleanup and cannot see an enterprise directory. The changelog does not tell us whether Codex calls the revoke endpoint during cleanup, so test it on a throwaway account before you rely on it.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume