MCP SEP-2352: credentials bound to issuer, re-register on a new host

MCP SEP-2352 binds client credentials to the issuer and deprecates DCR for Client ID Metadata Documents. Re-register if the Sume host changes.

4 min readSume
All posts

The 2026-07-28 MCP changelog lists SEP-2352, which binds client credentials to the issuer, and it deprecates Dynamic Client Registration in favor of Client ID Metadata Documents. In practice, a client credential minted for one authorization server should not be presented to another. Sume's authorization server is the MCP origin, so credentials that were registered against a different Sume host, including the deprecated www.sume.com surface, should be treated as belonging to that issuer.

What the pages say

Issuer facts, read 2026-10-05
ItemValue
SEP-2352Client credentials bound to the issuer
RegistrationDCR deprecated for Client ID Metadata Documents
Sume authorization serverThe MCP origin; https://mcp.sume.com
www.sume.comSecondary and deprecated authorization-server surface, not advertised in metadata

When to re-register

The Sume docs do not describe a migration of stored client credentials, so the rule below is my reading of the spec change. If a client stored a registration while pointed at one host and you now point it at another, the registration is for a different issuer. Start a fresh OAuth login for the new server entry. For Claude Code that is the documented pair of commands:

claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume

Do not mix environments

Public configs should use mcp.sume.com. If you ever keep more than one server entry, give each its own name, so a credential from one cannot be sent to the other. If you use an API key instead of OAuth, the key is not an OAuth client credential.

Checklist

  • Name entries by host, for example one for production only.
  • After changing a server URL, run the login again and call mcp_health to see the auth source (mcp_oauth for OAuth).
  • Check which scopes the consent granted: mcp:read, and mcp:write only if you toggled it.
  • Watch client release notes for the move from DCR to Client ID Metadata Documents.

Symptoms of a stale registration

The Sume docs do not list a specific error for a stale registration, so I only suggest the fix: remove the old server entry, add it again and log in again. Then call mcp_health and check that authenticated.auth_source reads mcp_oauth.

If you are using an API key instead, none of this applies, but the same discipline does: keep each key only on the endpoint it was issued for.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume