MCP workload identity federation: Sume takes code grant only
MCP's roadmap names Workload Identity Federation. Sume's hosted MCP advertises only the authorization_code grant, so headless workloads use an API key.

A cloud workload with no browser cannot use Sume's hosted MCP OAuth today. The authorization server advertises one grant type, authorization_code, and any other grant gets unsupported_grant_type. For headless automation the docs point to API-key remote MCP.
The roadmap side is from the MCP roadmap (last updated 2026-08-22), read 2026-10-01; Sume's side from packages/mcp-oauth and MCP OAuth and API keys.
What does the roadmap mean by Workload Identity Federation?
The roadmap says MCP authorization assumes a person with a browser at consent time, while the caller is increasingly an agent such as a cloud workload with its own identity. It names Workload Identity Federation (SEP-1933) as part of an opinionated way for servers to be reached by agents, and it is still work for the Agent Identity group.
What does Sume accept at the token endpoint?
| Request | Result |
|---|---|
grant_type=authorization_code (PKCE) | Accepted |
Any other grant_type | unsupported_grant_type |
| Error text | "OAuth grant_type must be authorization_code." |
Metadata grant_types_supported | ["authorization_code"] |
What should an unattended workload use instead?
The docs say API-key remote MCP remains the other path for automation that does not speak OAuth. Send Authorization: Bearer <SUME_API_KEY> or x-api-key. API-key sessions see the full tool set, and write or paid calls still need an idempotency_key. Store the key in your secret manager and rotate it if it shows up in logs.
Can I mint an API key for an OAuth client?
No. The docs say not to mint API keys for hosted OAuth clients as a workaround, and an MCP OAuth token is not a Sume API key. See also why client credentials fail against Sume.
Sources
Related posts
More in Developers
- Modal 150-second web timeout and 303 redirect: Sume polling
Modal web endpoints return a 303 redirect after 150 seconds. Sume returns 202 with status_url and result_url, so a client polls and follows no redirects.
- Nano Banana batch API: Gemini's 24 h batch vs Sume async jobs
Gemini's Batch API trades up to 24 hours of turnaround for higher rate limits. Sume has no batch tier for images: send async or webhook jobs per request.
- OpenAI Agents API durable sessions and Sume job ids
A durable OpenAI Agents API session continues across turns; a Sume render is a separate job. Keep the job id in the session and re-read it, never re-create.
- OpenAI Agents Python MCP error content: reading Sume tool errors
openai-agents-python v0.20.0 keeps MCP error content with structured output. Sume tool failures arrive as isError text with code, message and http_status.
Written by Sume