Devin Desktop "Needs auth" and the Authenticate button for Sume
Devin Desktop shows an Authenticate button on MCP servers marked Needs auth, and it clears stored OAuth credentials. What to expect when you do it for Sume.

If Devin Desktop shows Sume as "Needs auth", click Authenticate: it clears the stored OAuth credentials for that server and starts a fresh sign-in. For Sume that means one trip through the consent page on mcp.sume.com, where you choose again whether Write is on.
What does the Authenticate button do?
The Devin Desktop changelog (read 2026-10-03) lists under v3.6.21, dated July 29, 2026: "MCP servers reporting 'Needs auth' now show an **Authenticate** button...which clears the stored OAuth credentials". Two later entries touch the same flow. Version 3.10.23 (September 10, 2026) reads "MCP authorization opens the provider directly", and version 3.10.48 (September 29, 2026) says servers passed by an ACP client in session/new or session/load are now usable by the agent.
Why would Sume show Needs auth?
Two causes are plausible. The client may hold no valid credential, or the grant may be missing the scope a tool needs. Sume's own docs state that hosted OAuth scopes are mcp:read and mcp:write, and that a missing scope on a tool call returns insufficient_scope. A server marked Needs auth is a client-side state, so the button is the right first move for either cause.
The related post on token lifetime covers the first cause; a re-sign-in is ordinary maintenance.
| What you see | Meaning | Move |
|---|---|---|
| Needs auth on the server row | Client holds no valid credential | Click Authenticate, finish consent |
| Tools listed, paid call refused | Grant is read-only | Authenticate again with Write on |
| No tools listed after sign-in | Wrong or missing URL | Check the entry is https://mcp.sume.com/mcp |
What happens on the Sume consent page?
The OAuth and API keys page lays out the steps. The client sends you to https://mcp.sume.com/oauth/authorize, which redirects to the first-party consent page on the MCP host. After you sign in, Permissions shows Read locked on and a Write toggle that defaults to off. Continuing posts your decision and the client exchanges the code, with PKCE, for a token.
Because the button clears the old credentials first, the next token starts from your new choice on the Write toggle. Turn Write on again if you still need paid tools.
How do I confirm it worked?
Ask the agent to call mcp_health and read the auth source, which should show mcp_oauth, then tools_list. With Write on you will see paid tools such as generate_image; without it you will see only read tools. That check costs nothing, since both calls are read-only.
Call mcp_health and report authenticated.auth_source.
Then call tools_list and tell me whether generate_image is listed.What if the button does not help?
Check the entry URL first, then whether an admin allowlist blocks the server; the related Devin post on allowlists covers that case. Sume cannot see your client's stored credentials, so a clean sign-in from the client is the only reset available.
Does Authenticate affect my Sume account or jobs?
No. Clearing the stored OAuth credentials removes the client's token, not anything in your Sume workspace. Jobs you already created keep running and keep their ids, and jobs_list shows them again after you sign back in. Credits, assets and history are tied to your account, not to the token.
If you are partway through a paid task when the prompt appears, finish by re-authenticating, then read jobs_status for the ids you already have before creating anything new. A new create with a new idempotency_key is a new job, so check first.
Sources
Related posts
More in Integrations
- Google lifestyle_image_link vs additional_image_link
Put the AI scene in lifestyle_image_link, angles in additional_image_link, and host stable URLs. Limits, a Sume request and a feed snippet.
- Mercado Libre photo size: 1200x1200 and the pictures API
Mercado Libre wants 1200 x 1200 JPG or PNG up to 10 MB and shows a zoom widget past 800 px. Generate that size with Sume, upload it, link it to the item.
- Mercado Libre poor_quality_thumbnail: fix the cover photo
A poor_quality_thumbnail tag means Mercado Libre flagged the cover photo. Read the reason with the moderations API, then regenerate a clean cover with Sume.
- Meta Ads MCP server: seven tool categories and where Sume fits
Meta's hosted ads MCP server groups its tools into seven categories. None is a video maker, so an agent needs another MCP server such as Sume for the creative.
Written by Sume