MCP expectedIssuer with client credentials: Sume uses an API key

MCP TypeScript SDK 2.2.0 adds expectedIssuer to machine-to-machine providers. Sume's OAuth is authorization_code only; headless agents use an API key.

4 min readSume
All posts

Setting expectedIssuer on ClientCredentialsProvider does not make Sume work with it, because Sume's OAuth server does not support the client credentials grant. Its metadata lists only authorization_code, and the token endpoint rejects any other grant_type. For a headless agent, send a Sume API key as a bearer token instead.

SDK facts are from the TypeScript SDK release notes; Sume facts from the MCP OAuth and API keys page and the OAuth package source, read 2026-09-30.

What changed in the SDK?

The v2.2.0 notes say to pass expectedIssuer to the machine-to-machine providers (ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider, CrossAppAccessProvider); constructing them without it is deprecated and logs a warning. fetchToken() also throws AuthorizationServerMismatchError before sending anything when the client information is bound to a different authorization server.

What does Sume's authorization server advertise?

Sume OAuth metadata and docs, read 2026-09-30
FieldValue
issuerThe MCP origin
grant_types_supported["authorization_code"]
token_endpoint_auth_methods_supported["none"]
Other grant_typeError: "OAuth grant_type must be authorization_code."

So what do I use for an unattended agent?

The OAuth docs list the API key mode as full hosted tool set, sent as Authorization: Bearer <SUME_API_KEY> or x-api-key. Spend goes through wallet admission, and idempotency_key is required on writes and paid calls. The same page calls API-key remote MCP the path for automation that does not speak OAuth. See API key vs OAuth for MCP.

Does expectedIssuer matter for Sume at all?

Only for an interactive OAuth client. There the issuer Sume returns is the MCP origin, which is what a client would compare against; the full flow is in the MCP OAuth flow. Read-only mcp:read is required and mcp:write is opt-in on consent.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume