Sume MCP OAuth: the consent page is on mcp.sume.com, not app
A Sume MCP client OAuth flow goes /oauth/authorize then /oauth/consent on the MCP host. Do not send users to app.sume.com; here is what the flow checks.

Sume's MCP consent screen is served from the MCP host. /oauth/authorize redirects to /oauth/consent on mcp.sume.com, and that is where the user approves mcp:read and, optionally, mcp:write. Do not send users to app.sume.com to approve a client.
This follows Sume's OAuth and API keys page, read 2026-10-06.
Where does a client discover this?
Protected-resource metadata is published at /.well-known/oauth-protected-resource/mcp. A compliant client reads it, finds the authorization server, and follows the redirects without any hard-coded consent URL.
| Step | Path | Host |
|---|---|---|
| Discover | /.well-known/oauth-protected-resource/mcp | mcp.sume.com |
| Authorize | /oauth/authorize | mcp.sume.com |
| Consent | /oauth/consent | mcp.sume.com |
| Call tools | /mcp | mcp.sume.com |
What goes wrong if I hard-code another host?
The user lands on a page that is not part of the OAuth flow, and the client never receives a code. If you maintain a custom client or a connector listing, use the discovery document instead of a pasted consent link.
Sources
Related posts
More in Developers
- MCP server for video editing: which tools can an agent call?
An agent can trim, strip audio, filter and compose clips through Sume's remote MCP endpoint. Here are the tool names, order of calls, and what each step costs.
- MiniMax H3 on Sume: 9 images, 3 videos, 3 audio, 12 in total check
On Sume, minimax-h3 and minimax-h3-max take at most 9 reference images, 3 videos and 3 audio clips, 12 in all, and audio cannot be alone. Check it in Python.
- Music-only Short: Timeline silence mode with a soundtrack bed
Build a Short with no voice: audio mode silence plus a soundtrack. The bed plays alone at the default -16 dB with no amix loss. Fields, limits, tail rule.
- n above the ceiling returns 400 on Sume images: split the batch
The images schema allows n up to 10, but each model's own range is lower: 4 on most, 1 on Grok Image. Read the descriptor and split the batch. Python helper.
Written by Sume