MCP DPoP sender-constrained tokens: Sume is bearer-only today
The MCP roadmap lists DPoP finalization, but Sume's hosted MCP issues mcp_at_ bearer tokens sent in the Authorization header, valid for one hour.

Sume's hosted MCP does not advertise sender-constrained tokens today. Its OAuth access tokens are plain bearer tokens, accepted from the Authorization header only, with the mcp_at_ prefix and a one-hour lifetime. DPoP is a roadmap item on the MCP side, not a Sume feature.
Roadmap wording is from the MCP roadmap (last updated 2026-08-22), read 2026-10-01. Sume details are from the mcp-oauth package and MCP OAuth and API keys.
What does the MCP roadmap say about DPoP?
Under Agent Identity and Enterprise-Ready Security, the roadmap says the Agent Identity working group, which is forming during the roadmap period, should finalize the specification for Demonstrating Proof of Possession (DPoP) and focus on getting widespread adoption. It is a plan, not a shipped protocol feature.
What does Sume's authorization server publish today?
| Field | Value |
|---|---|
bearer_methods_supported | ["header"] |
token_endpoint_auth_methods_supported | ["none"] |
| Access token prefix | mcp_at_ |
| Access token lifetime | One hour (60 * 60 seconds) |
What does bearer-only mean for my client?
Whoever holds the token can use it until it expires, so treat it like a password: do not paste it into prompts, store it in CLI config or forward it to third parties. The docs also say an MCP OAuth token is not a Sume API key. Send it as Authorization: Bearer <token>; the metadata lists header as the only bearer method.
How do I limit the damage of a leaked token?
Keep the grant narrow. Consent leaves Write off by default, so an mcp:read token only sees read-only tools. The short lifetime bounds the rest; see the one-hour token post. I found no DPoP or proof-of-possession field in the Sume metadata, so do not build a client that expects one.
Sources
Related posts
More in Developers
- MCP ETag on tool results: Sume idempotency_key and job reads
ETag-versioned MCP tool results are a roadmap idea. In Sume, idempotency_key is write dedup, not a cache validator; job reads are separate read tools.
- MCP human-presence attestation: Sume consent vs API key
Human-presence attestation is only a roadmap topic. Sume separates people from automation by credential: OAuth consent in a browser, or an API key.
- MCP OAuth .localhost redirect URI: Sume allows localhost and 127.0.0.1
MCP TypeScript SDK 2.2.0 treats .localhost hosts as loopback for token endpoints. Sume's redirect check allows http only on localhost and 127.0.0.1.
- MCP progressive discovery: Sume tools_list, then tools_schema
For a large MCP tool set, list first and fetch one contract second. Sume has tools_list for visible tools and tools_schema for a single tool by name.
Written by Sume