opencode mcp auth: sign in to Sume, list, debug, log out
Run opencode mcp auth sume to start Sume's OAuth consent, then list, debug or logout. v1.18.33 now reports browser launch failures and redacts debug output.

Run opencode mcp auth <server-name> with the name you gave your Sume entry. It starts the OAuth flow, which sends you to Sume's consent page on the MCP host, where Read is locked on and Write is an optional toggle. Then use opencode mcp list to check status, opencode mcp debug <server-name> to diagnose, and opencode mcp logout <server-name> to clear the stored token.
What do the four opencode commands do?
From the OpenCode docs, read 2026-09-30: remote servers use type: "remote" and a url, and OAuth falls back to Dynamic Client Registration (RFC 7591) when credentials are not pre-configured. Tokens are stored at ~/.local/share/opencode/mcp-auth.json.
| Command | Use |
|---|---|
opencode mcp auth <server-name> | Start the OAuth sign-in |
opencode mcp list | List configured servers |
opencode mcp debug <server-name> | Diagnose one server |
opencode mcp logout <server-name> | Remove stored credentials |
What changed in opencode v1.18.33?
The Sep 28, 2026 changelog says "MCP browser launch failures are now reported when the launcher exits immediately" and "Debug configuration output now redacts credentials and sensitive headers". In practice: if no browser opens on a headless box, you now get a message instead of a silent wait, and a pasted debug dump should not carry your headers. Still check it before sharing.
How do I confirm the Sume session after login?
Sume registers clients dynamically through /oauth/register, so no client id is needed. After sign-in, call mcp_health and confirm authenticated.auth_source is mcp_oauth, then tools_list. A session without Write sees only read-only tools, and mutating tools return insufficient_scope. See MCP tools and gates.
What if the browser cannot open?
Use an API key. Sume accepts Authorization: Bearer or x-api-key, and API-key sessions can see write and paid tools. Do not copy an OAuth token into config as a workaround; the docs say an OAuth token is not a Sume API key. Setup basics are in OpenCode MCP server for Sume and the auth matrix.
Sources
Related posts
More in Integrations
- Vercel Blob signed URL as a Sume image_url is rejected
Sume rejects signed or private URLs in input fields such as input.image_url. A Vercel Blob signed URL will fail; use a public-access store for Sume inputs.
- Vercel Queues for Sume job webhooks: dedupe on job_id
Vercel Queues delivers at least once and bills keyed sends at 2x. To relay Sume webhooks through it, use job_id as the key and ack fast on the 10s limit.
- Zapier Catch Raw Hook: verify a Sume webhook signature
Zapier's Catch Raw Hook returns unparsed data plus headers, which a Sume HMAC check needs. Here is what to verify and the size limits to know.
- Zed MCP OAuth scopes: what Sume asks for (mcp:read, mcp:write)
Zed 1.18.0 fixed OAuth for MCP servers with non-default scopes. Sume has two scopes, mcp:read (required) and mcp:write (opt-in on the consent page).
Written by Sume