Codex mcp_oauth_callback_port and the Sume OAuth login
Pin the Codex OAuth callback port for a remote Sume MCP login, and how the login flows from Codex to the Sume consent page on mcp.sume.com.

Codex's MCP page names mcp_oauth_callback_port as the fixed listener port for OAuth callbacks, and a per-server callback_port under [mcp_servers.<name>.oauth]. Set one, then run codex mcp login sume. The Sume side is unchanged: Codex is sent to https://mcp.sume.com/oauth/authorize, which continues to the consent page on the MCP host.
Codex keys come from its MCP page; the Sume flow comes from OAuth and API keys and the quickstart, read 2026-09-30.
What can Codex configure for the callback?
| Setting | What the Codex page says |
|---|---|
mcp_oauth_callback_url | Custom callback path or remote ingress URL |
mcp_oauth_callback_port | Fixed listener port for OAuth callbacks |
[mcp_servers.<name>.oauth] | Per-server callback_url and callback_port overrides |
| Default | Loopback callback at http://127.0.0.1/callback |
What happens on the Sume side during login?
The docs describe six steps: the client connects to https://mcp.sume.com/mcp, receives an OAuth challenge and protected-resource metadata, and sends you to https://mcp.sume.com/oauth/authorize. That redirects to GET /oauth/consent on the MCP host, where Read is locked on and the Write toggle defaults off. The client then exchanges the authorization code with PKCE and calls the endpoint with the bearer token.
How do I pin the port and log in?
Pick a free port, put it in the server's oauth table, and log in by server name. The Sume docs do not list allowed redirect URIs, so confirm by finishing one login rather than assuming.
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
[mcp_servers.sume.oauth]
callback_port = 8765
# then, in a shell:
# codex mcp login sumeWhat should I check after the login?
Ask Codex to call mcp_health and confirm authenticated.auth_source is mcp_oauth, then tools_list. With Write off you see read-only tools only. An OAuth token is not a Sume API key, and the docs say sume login does not broker hosted MCP tokens.
What if the login runs on a remote machine?
Codex's page names mcp_oauth_callback_url for a custom callback path or remote ingress URL, which the page describes that way. Sume's own docs say to complete the sign-in on the MCP host at https://mcp.sume.com/oauth/consent, not on app.sume.com, and that www.sume.com is a secondary and deprecated authorization surface that protected-resource metadata no longer advertises. The public metadata endpoints are https://mcp.sume.com/.well-known/oauth-protected-resource/mcp and https://mcp.sume.com/.well-known/oauth-authorization-server.
Sources
Related posts
More in Developers
- Content Credentials after download: check the file you deliver
C2PA 2.2 defines Content Credentials and a separate Soft Binding API. Sume's docs do not say a downloaded output keeps one, so check the delivered file.
- Can I continue a Sume Agent Completion with thread_id?
Not yet. Every Agent Completion runs in a fresh thread, so a follow-up call cannot reuse thread_id. Pass earlier results back in the next request instead.
- Get the rendered MP4 back from a video editing API job
Descript's API lists no rendered file download without publishing. In Sume, a finished timeline_render job result carries video_url; here is the poll flow.
- 429 enforced_spend_limit_reached: why retrying never works
A 429 with no retry-after can be a monthly spend cap, not a rate limit. What Anthropic's page says, and how Sume separates 402, 429 rate_limited and queue_full.
Written by Sume