Gemini CLI authProviderType: connect Sume with dynamic_discovery
Gemini CLI defaults authProviderType to dynamic_discovery. For Sume that means OAuth discovery, not Google credentials. What each of the three values does.

For Sume, leave authProviderType at its default of dynamic_discovery, or omit it. Gemini CLI then discovers the OAuth endpoints from the server, registers, and signs you in. The other two values, google_credentials and service_account_impersonation, produce Google-issued tokens, which Sume's MCP host does not accept as a credential. Sume accepts its own OAuth access tokens or a Sume API key.
The three provider types
The page also describes an oauth object with enabled, clientId, authorizationUrl, tokenUrl, scopes, issuer and redirectUri, and says tokens are stored and refreshed. Sume advertises dynamic client registration at /oauth/register, so you normally do not need to set clientId yourself.
| Value | Gemini CLI page | Works with Sume |
|---|---|---|
| dynamic_discovery | Default; discovers OAuth from the server | Yes, uses Sume's OAuth metadata |
| google_credentials | Uses Google credentials | No, not a Sume credential |
| service_account_impersonation | Impersonates a Google service account | No, not a Sume credential |
What Sume's side looks like
Sume's authorization server supports the authorization_code grant with PKCE method S256, and public clients (token endpoint auth method none). Redirect URIs may be https anywhere, or http on localhost and 127.0.0.1, up to 10 per registration. Gemini CLI's local callback fits the localhost rule.
The access token lasts one hour and Sume does not implement refresh. Gemini CLI says it refreshes tokens, but with Sume the practical result is a new sign-in when the hour ends, so long unattended runs should use an API key instead.
Scopes you will see
Sume's OAuth requires mcp:read and is read-only by default. Write is an opt-in toggle on the consent page, listed as mcp:write. There is no paid scope; paid calls are gated by the write scope plus an idempotency_key. If you set oauth.scopes yourself, request mcp:read and add mcp:write only when you want the agent to be able to submit jobs.
- Use includeTools to expose only the read tools you want, since excludeTools takes precedence on conflicts.
- Set trust to false (its default) so Gemini CLI keeps asking before running a tool.
- For unattended jobs, switch to an API key in headers.
A settings.json sketch
A minimal entry uses the httpUrl key for streamable HTTP and relies on the default provider type. If you later move to an API key, drop the OAuth behaviour and send the key in headers instead.
{
"mcpServers": {
"sume": {
"httpUrl": "https://mcp.sume.com/mcp",
"authProviderType": "dynamic_discovery",
"includeTools": ["mcp_health", "jobs_wait", "jobs_result"]
}
}
}First sign-in and what to check
After the first connection, Gemini CLI opens the Sume consent page in your browser. Read the scopes it shows before you approve, then call mcp_health to confirm the session is read-only. Include only the tools you intend to use in includeTools, and review the list when Sume's tool surface changes.
If the browser step never opens, check that Gemini CLI can bind a localhost callback. If it opens but the token exchange fails, the authorization code may have expired: Sume codes last 10 minutes, and each can be used once. Start the sign-in again rather than reusing an old link.
Sources
Related posts
More in Integrations
- Does Copilot's MCP policy apply to Pro+ or Max? Sume hosted MCP
GitHub's MCP servers in Copilot policy covers Business and Enterprise, off by default. Free, Pro, Pro+ and Max users can add Sume's hosted MCP server directly.
- MCP spec: token in the header on every request, never the URL
The 2025-11-25 MCP spec forbids access tokens in the URL query string and wants a Bearer header on every request. Keep the Sume key in headers, not the URL.
- MCP spec: tool annotations are untrusted. What that means for Sume
The MCP spec says clients must treat tool annotations as untrusted unless they come from a trusted server. Treat Sume as trusted only for your own workspace.
- MCP tool error or JSON-RPC error: where Sume's failures land
Sume returns tool failures as results with isError true and keeps JSON-RPC errors for protocol faults, per the 2025-11-25 MCP spec. Here is the split.
Written by Sume