MCP step-up scopes (SEP-2350) vs Sume's mcp:write re-consent

The MCP 2026-07-28 draft adds step-up scope accumulation. On Sume today, getting from mcp:read to mcp:write means a new consent and a new token.

4 min readSume
All posts

Sume's documented way to gain write access is to run the OAuth flow again and tick mcp:write on the consent page. The MCP 2026-07-28 release candidate lists step-up scope accumulation (SEP-2350) among six authorization changes, which is about requesting more scope later without losing what you already hold. This post does not say Sume implements SEP-2350.

The spec items are named in the release candidate post. Sume's current behavior is in the OAuth docs.

Where the two meet

Authorization items (read 2026-10-04)
TopicMCP release candidateSume today
Scope growthStep-up scope accumulation (SEP-2350)Re-run consent with mcp:write ticked
Issuer checkiss validation per RFC 9207 (SEP-2468)See the Sume OAuth docs for the metadata it serves
Credential bindingCredentials bound to the issuer (SEP-2352)Not documented as a Sume feature
BaselineNot specified heremcp:read required and read-only

What a client should do now

When a tool is missing, do not guess its name. A read-only token hides write and paid tools from tools_list, and calling one returns insufficient_scope (tools and gates). Treat that error as the cue to send the user back through consent, then open a new session so the tool list is rebuilt.

If your client library implements step-up per the draft, expect it to be unused against Sume until Sume documents support.

Checklist

  • Ask for mcp:read first.
  • On insufficient_scope, explain what the user would be allowing before you re-consent.
  • Rebuild the tool list after a new token.
  • Revisit when Sume's docs mention a scope challenge.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume