opencode mcp auth: sign in to Sume, list, debug, log out

Run opencode mcp auth sume to start Sume's OAuth consent, then list, debug or logout. v1.18.33 now reports browser launch failures and redacts debug output.

4 min readSume
All posts

Run opencode mcp auth <server-name> with the name you gave your Sume entry. It starts the OAuth flow, which sends you to Sume's consent page on the MCP host, where Read is locked on and Write is an optional toggle. Then use opencode mcp list to check status, opencode mcp debug <server-name> to diagnose, and opencode mcp logout <server-name> to clear the stored token.

What do the four opencode commands do?

From the OpenCode docs, read 2026-09-30: remote servers use type: "remote" and a url, and OAuth falls back to Dynamic Client Registration (RFC 7591) when credentials are not pre-configured. Tokens are stored at ~/.local/share/opencode/mcp-auth.json.

opencode MCP commands from the OpenCode docs, read 2026-09-30.
CommandUse
opencode mcp auth <server-name>Start the OAuth sign-in
opencode mcp listList configured servers
opencode mcp debug <server-name>Diagnose one server
opencode mcp logout <server-name>Remove stored credentials

What changed in opencode v1.18.33?

The Sep 28, 2026 changelog says "MCP browser launch failures are now reported when the launcher exits immediately" and "Debug configuration output now redacts credentials and sensitive headers". In practice: if no browser opens on a headless box, you now get a message instead of a silent wait, and a pasted debug dump should not carry your headers. Still check it before sharing.

How do I confirm the Sume session after login?

Sume registers clients dynamically through /oauth/register, so no client id is needed. After sign-in, call mcp_health and confirm authenticated.auth_source is mcp_oauth, then tools_list. A session without Write sees only read-only tools, and mutating tools return insufficient_scope. See MCP tools and gates.

What if the browser cannot open?

Use an API key. Sume accepts Authorization: Bearer or x-api-key, and API-key sessions can see write and paid tools. Do not copy an OAuth token into config as a workaround; the docs say an OAuth token is not a Sume API key. Setup basics are in OpenCode MCP server for Sume and the auth matrix.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume