MCP Enterprise-Managed Authorization is stable: Sume uses OAuth or key
The MCP roadmap calls Enterprise-Managed Authorization stable. Sume's hosted MCP documents two sign-in modes: OAuth with scopes, or an API key.

Sume's hosted MCP server documents two ways to sign in: OAuth with mcp:read required and mcp:write opt-in, or an API key sent as a bearer or x-api-key header. The MCP project's August 22, 2026 roadmap lists Enterprise-Managed Authorization as stable, but Sume's docs do not describe an enterprise-managed flow, so plan on those two.
The roadmap facts are from the MCP blog, read 2026-10-01. The Sume facts are from its MCP docs.
What does the MCP roadmap say about authorization?
Among its priority areas the roadmap includes DPoP and Workload Identity Federation, and it marks Enterprise-Managed Authorization as stable. It is a statement about the protocol, not about any one server.
Which sign-in modes does Sume document?
The OAuth and API keys page lists them. Nothing else is documented, so a client that wants an enterprise-managed grant has no Sume-specific path to it today.
| Mode | Tools visible | Use for |
|---|---|---|
OAuth, mcp:read | Read tools | Browsing models, jobs and results |
OAuth, plus mcp:write | Write and paid tools | A person approving generation |
| API key | Full tool set | Servers and CI |
What should an enterprise team do today?
Pick by who is at the keyboard. For people, OAuth: the consent page shows the scopes, and Write stays off unless chosen. For unattended runs, an API key held in your secret manager, with paid calls bounded by max_spend_usd. The docs say a key that leaks into logs or chat history should be rotated.
Is there a mcp:paid scope?
No. Paid access comes through mcp:write or an API key, and every paid call needs an idempotency_key. If a policy needs a separate paid grant, enforce it in the client's tool approval rather than expecting a scope.
Sources
Related posts
More in Integrations
- n8n MCP Client node ends sessions: what that means for Sume
n8n 2.42.0 terminates the MCP session before closing the client. Sume's endpoint is POST-only and issues no session id, so pair it with idempotency keys.
- Notion 600 requests/min per connection: write back 100 Sume results
Notion allows 600 requests per minute per connection on Business and Enterprise, 180 elsewhere. Here is how to write 100 finished Sume results back within that.
- OpenAI Agents Python conditional approval and Sume dry_run
Openai-agents-python v0.22.3 aligns conditional approvals with validated tool arguments. For Sume tools, base the check on tools_schema and dry_run.
- Always-on agents making video: a Sume callback_url, not polling
An always-on agent that waits on video should not poll in a loop. On Sume, pass an HTTPS callback_url and receive a signed webhook when the job finishes.
Written by Sume