Sume MCP OAuth metadata: curl the well-known URLs before you connect

Before a client fails at sign-in, curl Sume's protected-resource and authorization-server metadata on mcp.sume.com and check the resource audience matches.

3 min readSume
All posts

When a remote MCP client cannot finish OAuth, the problem is usually discovery, not the password. Sume publishes two metadata documents on the MCP host that you can read with curl in seconds.

The two URLs

The OAuth and API keys page lists them. The protected-resource metadata says which authorization server protects the endpoint, and the authorization-server metadata describes it. The resource audience is the MCP URL itself.

curl -sS https://mcp.sume.com/.well-known/oauth-protected-resource/mcp
curl -sS https://mcp.sume.com/.well-known/oauth-authorization-server

What to look for

  • authorization_servers should be the MCP origin, https://mcp.sume.com, not www.sume.com or app.sume.com. The docs call www a secondary and deprecated surface that metadata no longer advertises.
  • The resource audience should be https://mcp.sume.com/mcp. A client that requests a different audience will be refused.
  • Sign-in goes to https://mcp.sume.com/oauth/authorize, which redirects to the consent page on the MCP host, then the client exchanges the code with PKCE.

Dev and the key fallback

Development uses the same shape on https://mcp.dev.sume.com; do not mix a dev connector with a production key. If the client cannot do OAuth at all, send Authorization: Bearer $SUME_API_KEY or x-api-key instead: API-key sessions see the full hosted tool set, and paid calls still need idempotency_key.

Never send interactive clients to app.sume.com for MCP OAuth. The MCP quickstart shows the supported connection steps for Claude Code, Cursor and Codex.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume