Devin Desktop MCP authorization opens the provider: Sume page
Devin Desktop 3.10.23 opens MCP authorization at the provider directly. For Sume that is mcp.sume.com/oauth/authorize, then a consent page on the MCP host.

The Devin Desktop changelog for v3.10.23 (September 10) says "MCP authorization opens the provider directly." The changelog line is one sentence and does not name Sume; reading it against Sume's docs, the provider is the MCP host: the client sends the user to https://mcp.sume.com/oauth/authorize, which redirects to a first-party consent page on the same host.
Vendor facts are from the changelog; Sume facts from MCP OAuth, read 2026-10-01.
What is the Sume authorization flow?
The docs list six steps for the hosted flow.
| Step | What happens |
|---|---|
| 1 | Client connects to https://mcp.sume.com/mcp |
| 2 | Sume returns an OAuth challenge and protected-resource metadata |
| 3 | Client sends the user to https://mcp.sume.com/oauth/authorize, which redirects to /oauth/consent on the MCP host |
| 4 | Consent shows Read locked on and Write default off |
| 5 | Client exchanges the code (PKCE) for an access token |
| 6 | Client calls /mcp with the bearer token |
Which origin is the authorization server?
The MCP origin. The docs say authorization_servers is the MCP origin, not www or app.sume.com, and tell clients not to send interactive users to app.sume.com for MCP OAuth. Metadata is public at https://mcp.sume.com/.well-known/oauth-authorization-server and https://mcp.sume.com/.well-known/oauth-protected-resource/mcp.
What if the browser shows a redirect error?
Sume's server rejects a redirect_uri that is not allowed with the message "OAuth redirect_uri is not allowed." Check that the client registered the callback it actually uses. Cursor has a page on the same class of problem.
How do I add Sume in Devin Desktop?
Add https://mcp.sume.com/mcp as a remote MCP server (the exact menu labels are in Devin Desktop's own docs), complete the browser sign-in, and leave Write off unless the agent needs it. The Windsurf page covers the older editor naming: Windsurf MCP server for Sume.
Sources
Related posts
More in Integrations
- Devin MCP write scopes by default: Sume keeps write opt-in
Devin now requests read/write scopes by default for Microsoft 365 MCP. Sume's hosted MCP asks for read only unless the user turns Write on at consent.
- fal MCP "why did my request fail": the Sume job equivalent
fal's Platform MCP lets an assistant debug a failed request. For a failed Sume media job, read jobs_events and the error, then retry by the error rules.
- Mastra idleTimeoutMs observer detach: the Sume job keeps running
Mastra idleTimeoutMs detaches the observer and keeps the run. A Sume job it started keeps running too: re-wait on its id, do not resubmit.
- Mastra respondToToolApproval needs toolCallId: Sume paid calls
Mastra now rejects approval responses without toolCallId. When you approve a Sume paid tool call, key it to that id and keep its idempotency_key stable.
Written by Sume