Slow OAuth consent and MCP timeouts: Sume's Write toggle step
MCP Python SDK v2.3.0 stops counting interactive OAuth logins against request timeouts. Here is the consent step with Sume's Write toggle that benefits.

Yes, a slow consent screen is now safer on Python clients: the MCP Python SDK v2.3.0 release notes (Oct 2, 2026) say interactive OAuth logins no longer count against request timeouts. With Sume's hosted MCP, the slowest step is a person on the consent page deciding whether to turn Write on.
The Sume consent flow
Sume's hosted MCP lives at https://mcp.sume.com/mcp. The docs describe six steps. The client connects and gets an OAuth challenge with protected-resource metadata, the user is sent to /oauth/authorize, which redirects to the first-party consent page on the MCP host, and after sign-in the page shows Permissions.
- Read is locked on
- Write is a toggle, default off
- Continue posts to
POST /oauth/consent/decision - The client exchanges the authorization code with PKCE for an access token
- The client calls the MCP endpoint with that bearer token
Why the timeout matters
Between the challenge and the token exchange a human is in the loop. They may need to sign in, read the toggle and think. If the client's request timeout kept running during that time, a slow user could fail the connection for reasons unrelated to Sume. The SDK change, quoted from its release notes, removes that cause on the Python side. Check your own client version; other SDKs may behave differently.
What the Write toggle changes
| Choice on consent | Scope granted | Tools the session sees |
|---|---|---|
| Write off (default) | mcp:read | Read-only tools |
| Write on | mcp:read and mcp:write | Mutating and paid tools |
Plan for it
Sume documents no mcp:paid scope. Paid submits are controlled by wallet admission, and idempotency_key is required on writes and paid calls. A read-only session that tries a mutating tool gets insufficient_scope, so if your agent needs to generate, tell the user to turn Write on before they continue.
Fallback for automation
Unattended jobs cannot click a consent page. Sume also accepts an API key on hosted MCP, sent as Authorization: Bearer or x-api-key. Docs warn that an OAuth token is not an API key and that you should not mint keys as a workaround for an OAuth client.
Sources
Related posts
More in Developers
- Snap a requested video length to supported durations in Python
Veo 3.1 accepts only 4, 6 or 8 seconds. A short Python helper snaps any requested length to a model's supported_durations list from GET /v1/videos/models.
- Sora ended in two steps: app in April, API on September 24
OpenAI's docs say the Sora API shut down Sep 24, 2026 with no direct replacement. A help-center snippet dates the app and web end at Apr 26. What to inventory.
- Sora replacement smoke test: one prompt, three Sume models, in Python
A short Python script that sends the same 5-second prompt to seedance-2.5, wan-3.0 and gemini-omni-flash-1.1 on Sume and prints status, cost and URLs.
- Sora files lived 1 hour: storing Sume job results
OpenAI's Sora 2 and Videos API shut down Sept 24, 2026, and videos were downloadable for 1 hour. Download and store Sume job results promptly.
Written by Sume