MCP step-up scopes (SEP-2350) vs Sume's mcp:write re-consent
The MCP 2026-07-28 draft adds step-up scope accumulation. On Sume today, getting from mcp:read to mcp:write means a new consent and a new token.

Sume's documented way to gain write access is to run the OAuth flow again and tick mcp:write on the consent page. The MCP 2026-07-28 release candidate lists step-up scope accumulation (SEP-2350) among six authorization changes, which is about requesting more scope later without losing what you already hold. This post does not say Sume implements SEP-2350.
The spec items are named in the release candidate post. Sume's current behavior is in the OAuth docs.
Where the two meet
| Topic | MCP release candidate | Sume today |
|---|---|---|
| Scope growth | Step-up scope accumulation (SEP-2350) | Re-run consent with mcp:write ticked |
| Issuer check | iss validation per RFC 9207 (SEP-2468) | See the Sume OAuth docs for the metadata it serves |
| Credential binding | Credentials bound to the issuer (SEP-2352) | Not documented as a Sume feature |
| Baseline | Not specified here | mcp:read required and read-only |
What a client should do now
When a tool is missing, do not guess its name. A read-only token hides write and paid tools from tools_list, and calling one returns insufficient_scope (tools and gates). Treat that error as the cue to send the user back through consent, then open a new session so the tool list is rebuilt.
If your client library implements step-up per the draft, expect it to be unused against Sume until Sume documents support.
Checklist
- Ask for
mcp:readfirst. - On
insufficient_scope, explain what the user would be allowing before you re-consent. - Rebuild the tool list after a new token.
- Revisit when Sume's docs mention a scope challenge.
Sources
Related posts
More in Developers
- MCP tasks extension and Sume job statuses: mapping for render tools
In MCP 2026-07-28 tasks are an extension polled with tasks/get. Map task handles, polling, update and list onto Sume job ids, status reads and jobs_cancel.
- MCP tasks/get vs Sume's Agent Completion status_url polling
The MCP 2026-07-28 tasks extension polls by handle with tasks/get. Sume's Agent Completions poll a status_url until next_action is not poll_status.
- MCP tool ran twice: idempotency_key saves your Sume render
Claude Code fixed MCP tool calls that sometimes ran twice on large results. Sume's paid MCP tools require an idempotency_key so a repeat does not bill twice.
- MCP TS SDK 2.3 enforces one server per request: where state lives
TypeScript SDK 2.3.0 enforces one server instance per request. For a media tool that means job state belongs in job ids, as Sume's jobs_wait does.
Written by Sume