Gemini CLI authProviderType: connect Sume with dynamic_discovery

Gemini CLI defaults authProviderType to dynamic_discovery. For Sume that means OAuth discovery, not Google credentials. What each of the three values does.

5 min readSume
All posts

For Sume, leave authProviderType at its default of dynamic_discovery, or omit it. Gemini CLI then discovers the OAuth endpoints from the server, registers, and signs you in. The other two values, google_credentials and service_account_impersonation, produce Google-issued tokens, which Sume's MCP host does not accept as a credential. Sume accepts its own OAuth access tokens or a Sume API key.

The three provider types

The page also describes an oauth object with enabled, clientId, authorizationUrl, tokenUrl, scopes, issuer and redirectUri, and says tokens are stored and refreshed. Sume advertises dynamic client registration at /oauth/register, so you normally do not need to set clientId yourself.

Gemini CLI authProviderType values (read 2026-10-09) and fit with Sume (as of 2026-10-09)
ValueGemini CLI pageWorks with Sume
dynamic_discoveryDefault; discovers OAuth from the serverYes, uses Sume's OAuth metadata
google_credentialsUses Google credentialsNo, not a Sume credential
service_account_impersonationImpersonates a Google service accountNo, not a Sume credential

What Sume's side looks like

Sume's authorization server supports the authorization_code grant with PKCE method S256, and public clients (token endpoint auth method none). Redirect URIs may be https anywhere, or http on localhost and 127.0.0.1, up to 10 per registration. Gemini CLI's local callback fits the localhost rule.

The access token lasts one hour and Sume does not implement refresh. Gemini CLI says it refreshes tokens, but with Sume the practical result is a new sign-in when the hour ends, so long unattended runs should use an API key instead.

Scopes you will see

Sume's OAuth requires mcp:read and is read-only by default. Write is an opt-in toggle on the consent page, listed as mcp:write. There is no paid scope; paid calls are gated by the write scope plus an idempotency_key. If you set oauth.scopes yourself, request mcp:read and add mcp:write only when you want the agent to be able to submit jobs.

  • Use includeTools to expose only the read tools you want, since excludeTools takes precedence on conflicts.
  • Set trust to false (its default) so Gemini CLI keeps asking before running a tool.
  • For unattended jobs, switch to an API key in headers.

A settings.json sketch

A minimal entry uses the httpUrl key for streamable HTTP and relies on the default provider type. If you later move to an API key, drop the OAuth behaviour and send the key in headers instead.

{
  "mcpServers": {
    "sume": {
      "httpUrl": "https://mcp.sume.com/mcp",
      "authProviderType": "dynamic_discovery",
      "includeTools": ["mcp_health", "jobs_wait", "jobs_result"]
    }
  }
}

First sign-in and what to check

After the first connection, Gemini CLI opens the Sume consent page in your browser. Read the scopes it shows before you approve, then call mcp_health to confirm the session is read-only. Include only the tools you intend to use in includeTools, and review the list when Sume's tool surface changes.

If the browser step never opens, check that Gemini CLI can bind a localhost callback. If it opens but the token exchange fails, the authorization code may have expired: Sume codes last 10 minutes, and each can be used once. Start the sign-in again rather than reusing an old link.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume