Sume MCP OAuth: the consent page is on mcp.sume.com, not app

A Sume MCP client OAuth flow goes /oauth/authorize then /oauth/consent on the MCP host. Do not send users to app.sume.com; here is what the flow checks.

5 min readSume
All posts

Sume's MCP consent screen is served from the MCP host. /oauth/authorize redirects to /oauth/consent on mcp.sume.com, and that is where the user approves mcp:read and, optionally, mcp:write. Do not send users to app.sume.com to approve a client.

This follows Sume's OAuth and API keys page, read 2026-10-06.

Where does a client discover this?

Protected-resource metadata is published at /.well-known/oauth-protected-resource/mcp. A compliant client reads it, finds the authorization server, and follows the redirects without any hard-coded consent URL.

OAuth endpoints from the Sume MCP docs, read 2026-10-06.
StepPathHost
Discover/.well-known/oauth-protected-resource/mcpmcp.sume.com
Authorize/oauth/authorizemcp.sume.com
Consent/oauth/consentmcp.sume.com
Call tools/mcpmcp.sume.com

What goes wrong if I hard-code another host?

The user lands on a page that is not part of the OAuth flow, and the client never receives a code. If you maintain a custom client or a connector listing, use the discovery document instead of a pasted consent link.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume