Sume MCP token lasts 3600 s with no refresh grant: plan for it

Sume's hosted MCP OAuth issues one-hour access tokens and only the authorization code grant. What a long agent run should do at minute 61.

4 min readSume
All posts

A Sume hosted MCP access token lasts 3600 seconds, and the authorization server offers only the authorization_code grant, so there is no refresh token to renew it. In practice an OAuth-connected agent has to sign in again after an hour. The values come from the OAuth code and the architecture note on origin/main, read on 2026-10-04. If a run must outlast an hour without a person, use an API key instead.

What does the server publish?

Values from the mcp-oauth package and the remote MCP OAuth architecture note on origin/main, read 2026-10-04.
SettingValue
grant_types_supportedauthorization_code
Code challenge methodS256
token_endpoint_auth_methods_supportednone
Access token TTL3600 seconds
refresh_token in a registration requestignored
Revocation endpoint/oauth/revoke

What should a client do at the one-hour mark?

Treat an expired token as a re-authorization, not a retry. The client sends the user back through https://mcp.sume.com/oauth/authorize and the consent page, as the MCP OAuth and API keys page describes, then exchanges the new code with PKCE. Before the hour ends, avoid starting steps you cannot finish, and prefer short waits: jobs_wait holds at most 55 seconds per slice.

A job you submitted does not depend on the token that submitted it. Reconnect, read it with jobs_status or jobs_result, and do not create it again. If you must re-send a create, reuse the same idempotency_key.

Which credential should I choose?

Use OAuth for a person at a keyboard in Cursor or Claude, where a fresh sign-in is cheap. Use an API key for a pipeline that runs overnight. The key path gives the full hosted tool set, so keep paid tools behind idempotency_key and dry_run, as MCP tools and gates states.

Some hosts handle the token for you. Anthropic's MCP connector documentation says the API consumer manages OAuth and token refresh, which does not help here, since there is no refresh grant to call. Plan the re-consent, and remember the 2026-07-28 MCP changelog also adds iss validation for authorization responses.

How do I revoke?

Call /oauth/revoke to end a grant you no longer want. An OAuth token is not an API key, and the docs say not to store it in CLI config or paste it into prompts. If a key shows up in logs or chat history, rotate it from the dashboard.

What is the short version?

One hour of OAuth is plenty for a chat session and too little for a nightly batch. Choose by who is present. If a person is present, let the token expire and sign in again. If nobody is, use an API key with an idempotency_key on every create, and rely on job ids, not the token, to find your work the next morning.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume