MCP validate_token_resource: the resource a Sume token is for
Python SDK 2.2.0 adds validate_token_resource for servers. A Sume OAuth token's resource audience is https://mcp.sume.com/mcp; confirm it in the metadata.

Sume documents its OAuth resource audience as https://mcp.sume.com/mcp, the same URL as the canonical endpoint. A client-side or server-side resource check should compare against that value.
MCP Python SDK 2.2.0 (2026-09-07) adds "AuthSettings.validate_token_resource: only accept tokens your TokenVerifier reports as issued for this server". Sume side: MCP OAuth and API keys, read 2026-10-01.
Who does validate_token_resource apply to?
The setting is on AuthSettings, which is how you build an MCP server with the SDK. The notes also warn that with resource_server_url set and validate_token_resource unset, you should set it to True or False, since 3.0 defaults it to True. If you only connect to Sume as a client, you do not verify tokens; Sume does. The value matters when your own server or proxy sits in front of Sume tokens.
Which resource value does Sume bind?
The docs list the audience. In the code, the protected resource metadata carries resource from the same binding that sets the canonical endpoint, so the metadata and the endpoint agree.
| Item | Value |
|---|---|
| OAuth resource audience | https://mcp.sume.com/mcp |
| Canonical endpoint | Same resource binding |
resource field in the metadata | From that same binding |
How do I check it myself?
Fetch the metadata and compare the resource field to the endpoint you connect to.
import httpx
url = "https://mcp.sume.com/.well-known/oauth-protected-resource/mcp"
meta = httpx.get(url, timeout=10).json()
assert meta["resource"] == "https://mcp.sume.com/mcp", meta
print("resource ok:", meta["resource"])What if my check rejects a Sume token?
Check which URL you used as your server's resource. A value of the bare origin or a www host will not match https://mcp.sume.com/mcp, and the docs say authorization_servers is the MCP origin, not www or app.sume.com. Match the documented audience exactly, including the /mcp path.
Sources
Related posts
More in Developers
- MCP resource not found -32602: Sume is tools-only, so -32601
MCP 2026-07-28 moves resource-not-found from -32002 to -32602. Sume's hosted MCP advertises tools only, so resources/read gets method-not-found -32601.
- What are MCP extensions? Sume's capabilities list tools only
MCP 2026-07-28 adds an optional extensions field to client and server capabilities. Sume's initialize reply advertises only tools, with listChanged false.
- MCP standardized error handling: Sume's named outcomes
MCP has no single error standard across surfaces yet. Here is how Sume's named outcomes map to retry, re-auth, or stop in a hosted MCP client.
- MCP sub-agent with narrower authority: a read-only Sume token
Give a sub-agent a Sume token granted only mcp:read and it sees read-only tools, so it can inspect jobs and assets but never submit a paid generation.
Written by Sume