Hermes daily MCP re-auth nudge vs Sume's one-hour access token

Hermes Agent Desktop added a daily MCP re-auth nudge. Sume access tokens last 3600 seconds with no refresh token, so use an API key for scheduled work.

5 min readSume
All posts

Hermes Agent's September 14, 2026 release added a daily MCP re-auth nudge in Desktop, and its September 11 release fixed an MCP OAuth refresh that erased the refresh token (v2026.9.14 and v2026.9.11, read 2026-10-04). Sume's hosted endpoint issues access tokens that last 3600 seconds and issues no refresh token, so a daily nudge is slower than the token lifetime. For scheduled Hermes jobs that call Sume, use an API key.

What Sume's tokens look like

The authorization code is valid for 600 seconds and the access token for 3600 seconds. The server supports the authorization-code grant with PKCE and does not issue a refresh token, so when the hour ends the client has to send you through consent again (MCP OAuth and API keys).

A client that has a refresh-token bug fixed, such as the Hermes one, has nothing to refresh with against this server. The fix is real for servers that issue refresh tokens, and not a reason to expect longer sessions here.

Token lifetime vs reminder cadence. Sources: Hermes release notes and Sume docs, read 2026-10-04.
ItemValueSource
Hermes MCP re-auth nudgeDaily, in DesktopHermes v2026.9.14 release notes
Sume authorization code lifetime600 secondsSume code and OAuth docs
Sume access token lifetime3600 secondsSume code and OAuth docs
Sume refresh tokenNot issuedSume OAuth docs

Why this matters for scheduled work

A scheduled Hermes job that calls Sume on OAuth will start failing about an hour after you last signed in, long before a daily nudge fires. Hermes release notes also mention cron fixes, which suggests scheduled jobs are a use case there, but a job on a schedule has nobody to click through consent.

What to use instead

For unattended jobs, send an API key as Authorization: Bearer <key> or x-api-key to the hosted endpoint. The key gets the full tool set and does not expire hourly, so apply the paid gates in the job: idempotency_key on every write, dry_run for previews, and max_spend_usd for a ceiling. Keep OAuth for the interactive sessions where a person is at the keyboard and the one-hour boundary is harmless.

  • Interactive: OAuth, read-only by default, re-consent when it lapses.
  • Scheduled: API key held in the runner's secret store.
  • Either way, call mcp_health first to confirm which credential the session is using.

A quick test

Sign in with OAuth, run a read tool, wait past the hour and run it again. If the second call fails with an auth error, you have confirmed the token lifetime in your own setup, and you know to switch the scheduled job to a key.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume