MCP validate_token_resource: the resource a Sume token is for

Python SDK 2.2.0 adds validate_token_resource for servers. A Sume OAuth token's resource audience is https://mcp.sume.com/mcp; confirm it in the metadata.

4 min readSume
All posts

Sume documents its OAuth resource audience as https://mcp.sume.com/mcp, the same URL as the canonical endpoint. A client-side or server-side resource check should compare against that value.

MCP Python SDK 2.2.0 (2026-09-07) adds "AuthSettings.validate_token_resource: only accept tokens your TokenVerifier reports as issued for this server". Sume side: MCP OAuth and API keys, read 2026-10-01.

Who does validate_token_resource apply to?

The setting is on AuthSettings, which is how you build an MCP server with the SDK. The notes also warn that with resource_server_url set and validate_token_resource unset, you should set it to True or False, since 3.0 defaults it to True. If you only connect to Sume as a client, you do not verify tokens; Sume does. The value matters when your own server or proxy sits in front of Sume tokens.

Which resource value does Sume bind?

The docs list the audience. In the code, the protected resource metadata carries resource from the same binding that sets the canonical endpoint, so the metadata and the endpoint agree.

Resource values from the Sume docs and MCP server code, read 2026-10-01: https://docs.sume.com/mcp/oauth
ItemValue
OAuth resource audiencehttps://mcp.sume.com/mcp
Canonical endpointSame resource binding
resource field in the metadataFrom that same binding

How do I check it myself?

Fetch the metadata and compare the resource field to the endpoint you connect to.

import httpx

url = "https://mcp.sume.com/.well-known/oauth-protected-resource/mcp"
meta = httpx.get(url, timeout=10).json()
assert meta["resource"] == "https://mcp.sume.com/mcp", meta
print("resource ok:", meta["resource"])

What if my check rejects a Sume token?

Check which URL you used as your server's resource. A value of the bare origin or a www host will not match https://mcp.sume.com/mcp, and the docs say authorization_servers is the MCP origin, not www or app.sume.com. Match the documented audience exactly, including the /mcp path.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume