Copilot CLI 1.0.92: MCP tools after OAuth re-auth, with Sume

Copilot CLI 1.0.92-0 keeps MCP tools working after OAuth re-auth when definitions are unchanged. Sume tokens last one hour with no refresh, so you will hit it.

4 min readSume
All posts

GitHub Copilot CLI v1.0.92-0, a pre-release published October 1, 2026, lists one fix: MCP tools continue working after OAuth reauthentication when the tool definitions are unchanged. For Sume's hosted MCP that is the exact situation you land in every hour, because Sume's OAuth access tokens expire after 3,600 seconds and the server issues no refresh token. The release note does not say what the bug looked like, so treat the fix as relevant to that re-login case, not as a verified cure.

The release facts are from the Copilot CLI releases page, read 2026-10-01. Sume's token behavior is from the repository and from OAuth and API keys.

Why does a Sume session need re-auth at all?

Sume's authorization server metadata advertises only the authorization_code grant with PKCE S256 and public clients (token_endpoint_auth_methods_supported is none). The access token lifetime is one hour. With no refresh grant, a client cannot renew silently: it has to send you through the browser again, and the consent page shows Read locked on and the Write toggle off by default.

If you tick Write on the first consent and forget on the second, the session comes back with only read-only tools. Same server, same name, different tool list. That is why a fix keyed on 'definitions are unchanged' is narrower than it sounds: it helps when you re-consent with the same scope, and it does nothing about a scope downgrade.

Release facts from the Copilot CLI releases page and Sume facts from the repository and docs, read 2026-10-01.
QuestionAnswerSource
What is in v1.0.92-0?MCP tools continue working after OAuth reauthentication when tool definitions are unchangedCopilot CLI releases
Is it a stable release?Listed as a pre-release on 2026-10-01; v1.0.91 is marked latestCopilot CLI releases
How long does a Sume OAuth token last?One hour (3,600 seconds)Sume code and OAuth docs
Does Sume issue a refresh token?No; only authorization_code is advertisedSume OAuth metadata
What does API-key auth change?No expiry from the OAuth clock; full tool set; idempotency_key required on writesSume OAuth docs

What should I do today?

For short interactive work, stay on OAuth and re-consent with the same Write choice. For anything that outlasts an hour, such as a ten-minute render plus edits, use an API key in a header, as covered in Copilot CLI MCP server: add Sume with copilot mcp add. Keys come from the dashboard and should be rotated if they appear in logs or chat.

After any re-auth, ask the agent to call tools_list and check that generate_image or generate_video is still present before it plans a paid step. If it is missing, you consented read-only. Jobs already submitted keep running and keep billing across a re-login, so recover them with jobs_list or jobs_status instead of submitting again.

Limits

The release note is one line. It does not say how Copilot CLI behaves when definitions change, and I have not tested the pre-release against Sume. Treat it as a reason to retest your own flow, not as proof that hourly expiry no longer interrupts a session.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume