Gemini CLI keeps the OAuth refresh token: what Sume's MCP does

Gemini CLI 0.62 retains the OAuth refresh token on refresh. Sume's MCP token endpoint accepts only authorization_code, so expect a fresh sign-in, not a refresh.

4 min readSume
All posts

The Gemini CLI fix keeps a refresh token it already has; it does not make a server issue one. Sume's hosted MCP token endpoint accepts only the authorization_code grant and rejects any other grant_type, so against Sume the stored credential expires and the CLI has to run the sign-in again, or you use an API key.

The CLI fact is from the Gemini CLI release notes; the Sume facts are from the MCP OAuth package source and MCP OAuth and API keys, read 2026-09-30.

What changed in Gemini CLI 0.62?

The v0.62.0 release notes (dated 2026-09-29) list one entry: "fix(core): retain oauth refresh token on refresh and make credential deletion idempotent" (pull request 29339). The notes say nothing more about how it behaves per server, so this post does not either.

What does Sume's token endpoint accept?

Sume's MCP OAuth server behavior from package source, read 2026-09-30
ItemValue in source
grant_types_supported["authorization_code"]
Other grant_type valuesError: "OAuth grant_type must be authorization_code."
token_endpoint_auth_methods_supported["none"] (public clients)
Scopesmcp:read (required), mcp:write (opt-in)

So is there a refresh token to retain?

A code comment in the package says clients often advertise refresh_token, that Sume ignores it, and that refresh is not implemented yet. Treat that as today's behavior, not a promise. The longer explanation is in Sume's one-hour token with no refresh.

What should I do for a long Gemini CLI session?

Two options from the docs. Re-authorize when the token lapses: the consent screen shows Read locked on and a Write toggle that defaults to off, and a read-only (mcp:read) session sees only read tools. Or send an API key, which gets the full hosted tool set, with idempotency_key required on write and paid calls. Pick one per job; a read-only session that hits a write tool gets insufficient_scope, not a prompt to refresh.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume