One-hour Sume OAuth token in an OpenAI MCP authorization field

OpenAI does not store the MCP authorization token and wants it on every request. Sume's token lasts one hour with no refresh, so track expiry yourself.

4 min readSume
All posts

Store the token and its expiry on your side and resend the token in the authorization field on every Responses request. OpenAI's MCP guide says it does not store that OAuth token, so a follow-up turn without it will fail. Sume's access tokens last one hour and the server advertises no refresh grant (OAuth docs), so a long conversation needs a plan for the hour mark.

The result is a simple rule: the token is your state, not OpenAI's.

Who holds what

Token handling (read 2026-10-04)
ItemHeld bySource
OAuth token for the MCP serverYour backend; resent each requestOpenAI MCP guide
Access token lifetimeOne hourSume OAuth docs
Refresh tokenNot advertisedSume OAuth docs
Long unattended jobUse an API key insteadSume hosted MCP docs

A small expiry guard

The guard below returns the token if it has more than five minutes left and otherwise throws, so your code can send the user back through consent instead of making a request that will fail halfway through a paid job.

const TOKEN_LIFETIME_MS = 60 * 60 * 1000;
const SAFETY_MS = 5 * 60 * 1000;

export function usableToken(token: string, issuedAtMs: number): string {
  const left = issuedAtMs + TOKEN_LIFETIME_MS - Date.now();
  if (left < SAFETY_MS) throw new Error("Sume token expired: re-run OAuth consent");
  return token;
}

When to skip OAuth

  • Scheduled and server-side agents: use an API key, which the hosted MCP docs describe as seeing the full tool set.
  • Interactive assistants: OAuth, with mcp:read first.
  • Never put the token in the model's visible context; keep it in the tool config.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume