IT admin checklist: approving the Sume MCP connector
The MCP 2026-07-28 post proposes mandatory OAuth and OIDC discovery support. This checklist covers Sume's hosted MCP OAuth, scopes and keys.

The AAIF post on the MCP 2026-07-28 release says support for both OAuth 2.0 and OIDC discovery is proposed as mandatory, and describes Enterprise-Managed Authorization as an extension that would let IT administrators centrally provision MCP server access through an identity provider. Sume's hosted MCP docs describe an OAuth flow with protected-resource metadata and PKCE at https://mcp.sume.com/mcp. They do not describe Enterprise-Managed Authorization, so this checklist covers only what is documented.
What to verify
Confirm each item with your own test before you approve the connector for a team.
| Item | What the docs say |
|---|---|
| Endpoint | https://mcp.sume.com/mcp |
| Discovery | Protected-resource metadata; authorization server is the MCP origin |
| Code exchange | Authorization code with PKCE |
| Audience | https://mcp.sume.com/mcp |
| Scopes | mcp:read required, mcp:write opt-in, no mcp:paid |
| Consent | First-party page on the MCP host; Write toggle default off |
Scopes and spend
mcp:read sessions see only read-only tools. A mutating call without write returns insufficient_scope. A user who toggles Write on consent exposes mutating and paid tools, so decide whether your policy allows that toggle. Paid submits still need an idempotency_key and are gated by workspace balance and admission.
The docs list two metadata URLs you can fetch to confirm the setup before rollout:
https://mcp.sume.com/.well-known/oauth-protected-resource/mcphttps://mcp.sume.com/.well-known/oauth-authorization-server
Credential rules
An OAuth token is not a Sume API key, and the docs advise against storing OAuth tokens in CLI config, pasting them into prompts or forwarding them to other providers. API keys are a separate path for automation. Keys sent over MCP see the full tool set, so treat them as high-privilege and rotate any key that appears in logs or chat history.
curl -s https://mcp.sume.com/.well-known/oauth-protected-resource/mcpSources
Related posts
More in Developers
- Expired MCP session after 30 idle minutes: resume by job id
MCP Python SDK v2.2.0 closes idle Streamable HTTP sessions after 30 minutes by default. Keep the Sume job_id and resume the render with jobs_wait.
- Explicit key vs saved login: auth order in the Sume CLI
The Sume docs state no precedence between a saved login and an env key. Here is what they do say about saved login, env keys, auth mode and the two-header 401.
- FCC caption display settings, August 2026: burned-in captions
The FCC's caption display settings rule had an August 17, 2026 compliance date. Burned-in captions are pixels in the video; how to add them with Sume's API.
- Fit narration to a fixed slot: measure first, then set TTS speed
A 45-second cap or a 30-second slot decides your script. Render once with word timings, compute the speed ratio, and rewrite only if outside 0.6 to 1.5.
Written by Sume