MCP SEP-2352: credentials bound to issuer, re-register on a new host
MCP SEP-2352 binds client credentials to the issuer and deprecates DCR for Client ID Metadata Documents. Re-register if the Sume host changes.

The 2026-07-28 MCP changelog lists SEP-2352, which binds client credentials to the issuer, and it deprecates Dynamic Client Registration in favor of Client ID Metadata Documents. In practice, a client credential minted for one authorization server should not be presented to another. Sume's authorization server is the MCP origin, so credentials that were registered against a different Sume host, including the deprecated www.sume.com surface, should be treated as belonging to that issuer.
What the pages say
| Item | Value |
|---|---|
| SEP-2352 | Client credentials bound to the issuer |
| Registration | DCR deprecated for Client ID Metadata Documents |
| Sume authorization server | The MCP origin; https://mcp.sume.com |
www.sume.com | Secondary and deprecated authorization-server surface, not advertised in metadata |
When to re-register
The Sume docs do not describe a migration of stored client credentials, so the rule below is my reading of the spec change. If a client stored a registration while pointed at one host and you now point it at another, the registration is for a different issuer. Start a fresh OAuth login for the new server entry. For Claude Code that is the documented pair of commands:
claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sumeDo not mix environments
Public configs should use mcp.sume.com. If you ever keep more than one server entry, give each its own name, so a credential from one cannot be sent to the other. If you use an API key instead of OAuth, the key is not an OAuth client credential.
Checklist
- Name entries by host, for example one for production only.
- After changing a server URL, run the login again and call
mcp_healthto see the auth source (mcp_oauthfor OAuth). - Check which scopes the consent granted:
mcp:read, andmcp:writeonly if you toggled it. - Watch client release notes for the move from DCR to Client ID Metadata Documents.
Symptoms of a stale registration
The Sume docs do not list a specific error for a stale registration, so I only suggest the fix: remove the old server entry, add it again and log in again. Then call mcp_health and check that authenticated.auth_source reads mcp_oauth.
If you are using an API key instead, none of this applies, but the same discipline does: keep each key only on the endpoint it was issued for.
Sources
Related posts
More in Developers
- MCP timeline_create provider_fields_not_accepted: no ffmpeg fields
Sume's timeline_create refuses model, filtergraph, ffmpeg_args, codec, preset and crf with provider_fields_not_accepted. Describe the edit, not the encoder.
- MCP_TIMEOUT is a 30-second startup wait, not a Sume job limit
In claude -p, MCP_TIMEOUT is the wait for MCP servers to connect, 30 seconds by default. It does not limit a video job; Sume's jobs_wait does that.
- MiniMax H3 aigc_watermark defaults to false: what Sume exposes
MiniMax's H3 API has an aigc_watermark boolean, off by default. What it does, and what to do for a minimax-h3 clip made through Sume.
- Omni and Seedance clips in one timeline: the fps resample warning
Clips from two video models can have different frame rates. Sume's timeline warns with output_fps_resamples_sources; probe each clip, then set output.fps.
Written by Sume