IT admin checklist: approving the Sume MCP connector

The MCP 2026-07-28 post proposes mandatory OAuth and OIDC discovery support. This checklist covers Sume's hosted MCP OAuth, scopes and keys.

4 min readSume
All posts

The AAIF post on the MCP 2026-07-28 release says support for both OAuth 2.0 and OIDC discovery is proposed as mandatory, and describes Enterprise-Managed Authorization as an extension that would let IT administrators centrally provision MCP server access through an identity provider. Sume's hosted MCP docs describe an OAuth flow with protected-resource metadata and PKCE at https://mcp.sume.com/mcp. They do not describe Enterprise-Managed Authorization, so this checklist covers only what is documented.

What to verify

Confirm each item with your own test before you approve the connector for a team.

Sume hosted MCP facts for an approval review (read 2026-10-03)
ItemWhat the docs say
Endpointhttps://mcp.sume.com/mcp
DiscoveryProtected-resource metadata; authorization server is the MCP origin
Code exchangeAuthorization code with PKCE
Audiencehttps://mcp.sume.com/mcp
Scopesmcp:read required, mcp:write opt-in, no mcp:paid
ConsentFirst-party page on the MCP host; Write toggle default off

Scopes and spend

mcp:read sessions see only read-only tools. A mutating call without write returns insufficient_scope. A user who toggles Write on consent exposes mutating and paid tools, so decide whether your policy allows that toggle. Paid submits still need an idempotency_key and are gated by workspace balance and admission.

The docs list two metadata URLs you can fetch to confirm the setup before rollout:

  • https://mcp.sume.com/.well-known/oauth-protected-resource/mcp
  • https://mcp.sume.com/.well-known/oauth-authorization-server

Credential rules

An OAuth token is not a Sume API key, and the docs advise against storing OAuth tokens in CLI config, pasting them into prompts or forwarding them to other providers. API keys are a separate path for automation. Keys sent over MCP see the full tool set, so treat them as high-privilege and rotate any key that appears in logs or chat history.

curl -s https://mcp.sume.com/.well-known/oauth-protected-resource/mcp

Sources

Related posts

More in Developers

All Developers posts

Written by Sume