Sume hosted MCP OAuth scopes: mcp:read, mcp:write, and no paid scope

What a client gets after OAuth consent on https://mcp.sume.com/mcp: mcp:read always, mcp:write opt-in, and an API key for the full tool set.

5 min readSume
All posts

The hosted server is https://mcp.sume.com/mcp. OAuth grants two scopes: mcp:read, which is required and limits the session to read-only tools, and mcp:write, which the user opts into on the consent screen. There is no mcp:paid scope. Paid generation is governed by write access plus per-call fields: idempotency_key is required on writes and paid calls, and dry_run and max_spend_usd are optional.

A client that authenticates with an API key, via Authorization: Bearer or x-api-key, sees the full tool set.

Scope outcomes

MCP access per Sume docs (read 2026-10-03)
CredentialTools visiblePaid generation
OAuth, mcp:read onlyRead-only toolsRefused
OAuth with mcp:writeRead and write toolsAllowed with idempotency_key
API keyFull tool setAllowed with idempotency_key

Connect two clients

claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume

# Cursor: .cursor/mcp.json
# {"mcpServers":{"sume":{"url":"https://mcp.sume.com/mcp"}}}

Discovery

OAuth metadata is published at https://mcp.sume.com/.well-known/oauth-protected-resource/mcp and /.well-known/oauth-authorization-server. The flow is PKCE through /oauth/authorize, then /oauth/consent on the MCP host.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume