MCP expectedIssuer with client credentials: Sume uses an API key
MCP TypeScript SDK 2.2.0 adds expectedIssuer to machine-to-machine providers. Sume's OAuth is authorization_code only; headless agents use an API key.

Setting expectedIssuer on ClientCredentialsProvider does not make Sume work with it, because Sume's OAuth server does not support the client credentials grant. Its metadata lists only authorization_code, and the token endpoint rejects any other grant_type. For a headless agent, send a Sume API key as a bearer token instead.
SDK facts are from the TypeScript SDK release notes; Sume facts from the MCP OAuth and API keys page and the OAuth package source, read 2026-09-30.
What changed in the SDK?
The v2.2.0 notes say to pass expectedIssuer to the machine-to-machine providers (ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider, CrossAppAccessProvider); constructing them without it is deprecated and logs a warning. fetchToken() also throws AuthorizationServerMismatchError before sending anything when the client information is bound to a different authorization server.
What does Sume's authorization server advertise?
| Field | Value |
|---|---|
issuer | The MCP origin |
grant_types_supported | ["authorization_code"] |
token_endpoint_auth_methods_supported | ["none"] |
Other grant_type | Error: "OAuth grant_type must be authorization_code." |
So what do I use for an unattended agent?
The OAuth docs list the API key mode as full hosted tool set, sent as Authorization: Bearer <SUME_API_KEY> or x-api-key. Spend goes through wallet admission, and idempotency_key is required on writes and paid calls. The same page calls API-key remote MCP the path for automation that does not speak OAuth. See API key vs OAuth for MCP.
Does expectedIssuer matter for Sume at all?
Only for an interactive OAuth client. There the issuer Sume returns is the MCP origin, which is what a client would compare against; the full flow is in the MCP OAuth flow. Read-only mcp:read is required and mcp:write is opt-in on consent.
Sources
Related posts
More in Developers
- MCP listTools nextCursor: Sume returns a single page
TypeScript SDK 2.2.0 follows nextCursor in listTools(). Sume's tools/list returns a tools array with no cursor, so the walk ends after one request.
- MCP OAuth token expires: Sume's one-hour token, no refresh
Sume's hosted MCP OAuth access tokens last one hour and the server advertises only the authorization_code grant, so re-login or use an API key for long runs.
- MCP traceparent in _meta: tracing a Sume tool call end to end
MCP 2026-07-28 documents traceparent in _meta. Sume's docs don't describe reading it, so correlate with the job id and x-sume-request-id instead.
- OAuthFlowError issuer mismatch in the MCP Python SDK 2.2
Python SDK 2.2 rejects authorization server metadata whose issuer is not the server's origin. Sume's metadata sets issuer to the MCP origin.
Written by Sume