One-hour Sume OAuth token in an OpenAI MCP authorization field
OpenAI does not store the MCP authorization token and wants it on every request. Sume's token lasts one hour with no refresh, so track expiry yourself.

Store the token and its expiry on your side and resend the token in the authorization field on every Responses request. OpenAI's MCP guide says it does not store that OAuth token, so a follow-up turn without it will fail. Sume's access tokens last one hour and the server advertises no refresh grant (OAuth docs), so a long conversation needs a plan for the hour mark.
The result is a simple rule: the token is your state, not OpenAI's.
Who holds what
| Item | Held by | Source |
|---|---|---|
| OAuth token for the MCP server | Your backend; resent each request | OpenAI MCP guide |
| Access token lifetime | One hour | Sume OAuth docs |
| Refresh token | Not advertised | Sume OAuth docs |
| Long unattended job | Use an API key instead | Sume hosted MCP docs |
A small expiry guard
The guard below returns the token if it has more than five minutes left and otherwise throws, so your code can send the user back through consent instead of making a request that will fail halfway through a paid job.
const TOKEN_LIFETIME_MS = 60 * 60 * 1000;
const SAFETY_MS = 5 * 60 * 1000;
export function usableToken(token: string, issuedAtMs: number): string {
const left = issuedAtMs + TOKEN_LIFETIME_MS - Date.now();
if (left < SAFETY_MS) throw new Error("Sume token expired: re-run OAuth consent");
return token;
}When to skip OAuth
- Scheduled and server-side agents: use an API key, which the hosted MCP docs describe as seeing the full tool set.
- Interactive assistants: OAuth, with
mcp:readfirst. - Never put the token in the model's visible context; keep it in the tool config.
Sources
Related posts
More in Developers
- One TypeScript job shape for Sume /v1/videos and /v1/jobs responses
Sume's /v1/videos returns a bare object and /v1/jobs wraps in data. A short normalizer maps both to one state, including the cancelled versus canceled spelling.
- One TTS job with sentence segments vs one job per sentence
Sume TTS can return gapless sentence timings and per-sentence wav slices from one job. The price per character is the same; the jobs, keys and polls are not.
- OpenAI Agents API hosted sandbox: which Sume hosts to allow
OpenAI's Agents API is in public beta with hosted or connected sandboxes. Which Sume hosts to allow, how to pass the MCP URL, and why the key stays in a secret.
- OpenAI Agents API sandbox: keep the Sume API key out of it
The OpenAI Agents API beta adds a sandbox and hosted-browser computer use. Where a Sume API key can live when an agent runs there, and what to hand it instead.
Written by Sume