Sume MCP token lasts 3600 s with no refresh grant: plan for it
Sume's hosted MCP OAuth issues one-hour access tokens and only the authorization code grant. What a long agent run should do at minute 61.

A Sume hosted MCP access token lasts 3600 seconds, and the authorization server offers only the authorization_code grant, so there is no refresh token to renew it. In practice an OAuth-connected agent has to sign in again after an hour. The values come from the OAuth code and the architecture note on origin/main, read on 2026-10-04. If a run must outlast an hour without a person, use an API key instead.
What does the server publish?
| Setting | Value |
|---|---|
grant_types_supported | authorization_code |
| Code challenge method | S256 |
token_endpoint_auth_methods_supported | none |
| Access token TTL | 3600 seconds |
refresh_token in a registration request | ignored |
| Revocation endpoint | /oauth/revoke |
What should a client do at the one-hour mark?
Treat an expired token as a re-authorization, not a retry. The client sends the user back through https://mcp.sume.com/oauth/authorize and the consent page, as the MCP OAuth and API keys page describes, then exchanges the new code with PKCE. Before the hour ends, avoid starting steps you cannot finish, and prefer short waits: jobs_wait holds at most 55 seconds per slice.
A job you submitted does not depend on the token that submitted it. Reconnect, read it with jobs_status or jobs_result, and do not create it again. If you must re-send a create, reuse the same idempotency_key.
Which credential should I choose?
Use OAuth for a person at a keyboard in Cursor or Claude, where a fresh sign-in is cheap. Use an API key for a pipeline that runs overnight. The key path gives the full hosted tool set, so keep paid tools behind idempotency_key and dry_run, as MCP tools and gates states.
Some hosts handle the token for you. Anthropic's MCP connector documentation says the API consumer manages OAuth and token refresh, which does not help here, since there is no refresh grant to call. Plan the re-consent, and remember the 2026-07-28 MCP changelog also adds iss validation for authorization responses.
How do I revoke?
Call /oauth/revoke to end a grant you no longer want. An OAuth token is not an API key, and the docs say not to store it in CLI config or paste it into prompts. If a key shows up in logs or chat history, rotate it from the dashboard.
What is the short version?
One hour of OAuth is plenty for a chat session and too little for a nightly batch. Choose by who is present. If a person is present, let the token expire and sign in again. If nobody is, use an API key with an idempotency_key on every create, and rely on job ids, not the token, to find your work the next morning.
Sources
Related posts
More in Developers
- Sume MCP rate limit: one write per run created, none per status poll
Over Sume's hosted MCP, a tool call spends one write for the run it creates, and a jobs_status poll spends none. The numbers per plan and a Python budget check.
- Sume SDK: try/catch misses a 402, generated calls return { error }
Generated @sume-com/sdk operations return { data, error, response } instead of throwing, so a 402 or 429 slips past try/catch. Check error on every call.
- Sume SDK error.retryable: server flag first, status only as fallback
SumeApiError.retryable uses the error envelope's retryable flag when present and falls back to 408, 429 or 5xx otherwise. A 409 is never retried by status.
- Sume STT language_code: set a hint or omit it for auto-detect?
language_code is optional on Sume STT. Omit it to auto-detect, pass a BCP-47 hint like en or ko when you know the language. A quick way to choose.
Written by Sume