Codex mcp_oauth_callback_port and the Sume OAuth login

Pin the Codex OAuth callback port for a remote Sume MCP login, and how the login flows from Codex to the Sume consent page on mcp.sume.com.

4 min readSume
All posts

Codex's MCP page names mcp_oauth_callback_port as the fixed listener port for OAuth callbacks, and a per-server callback_port under [mcp_servers.<name>.oauth]. Set one, then run codex mcp login sume. The Sume side is unchanged: Codex is sent to https://mcp.sume.com/oauth/authorize, which continues to the consent page on the MCP host.

Codex keys come from its MCP page; the Sume flow comes from OAuth and API keys and the quickstart, read 2026-09-30.

What can Codex configure for the callback?

Codex OAuth callback settings named on the Codex MCP page, read 2026-09-30; Sume login docs: https://docs.sume.com/mcp/oauth
SettingWhat the Codex page says
mcp_oauth_callback_urlCustom callback path or remote ingress URL
mcp_oauth_callback_portFixed listener port for OAuth callbacks
[mcp_servers.<name>.oauth]Per-server callback_url and callback_port overrides
DefaultLoopback callback at http://127.0.0.1/callback

What happens on the Sume side during login?

The docs describe six steps: the client connects to https://mcp.sume.com/mcp, receives an OAuth challenge and protected-resource metadata, and sends you to https://mcp.sume.com/oauth/authorize. That redirects to GET /oauth/consent on the MCP host, where Read is locked on and the Write toggle defaults off. The client then exchanges the authorization code with PKCE and calls the endpoint with the bearer token.

How do I pin the port and log in?

Pick a free port, put it in the server's oauth table, and log in by server name. The Sume docs do not list allowed redirect URIs, so confirm by finishing one login rather than assuming.

[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"

[mcp_servers.sume.oauth]
callback_port = 8765

# then, in a shell:
# codex mcp login sume

What should I check after the login?

Ask Codex to call mcp_health and confirm authenticated.auth_source is mcp_oauth, then tools_list. With Write off you see read-only tools only. An OAuth token is not a Sume API key, and the docs say sume login does not broker hosted MCP tokens.

What if the login runs on a remote machine?

Codex's page names mcp_oauth_callback_url for a custom callback path or remote ingress URL, which the page describes that way. Sume's own docs say to complete the sign-in on the MCP host at https://mcp.sume.com/oauth/consent, not on app.sume.com, and that www.sume.com is a secondary and deprecated authorization surface that protected-resource metadata no longer advertises. The public metadata endpoints are https://mcp.sume.com/.well-known/oauth-protected-resource/mcp and https://mcp.sume.com/.well-known/oauth-authorization-server.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume