Sume MCP OAuth metadata: curl the well-known URLs before you connect
Before a client fails at sign-in, curl Sume's protected-resource and authorization-server metadata on mcp.sume.com and check the resource audience matches.

When a remote MCP client cannot finish OAuth, the problem is usually discovery, not the password. Sume publishes two metadata documents on the MCP host that you can read with curl in seconds.
The two URLs
The OAuth and API keys page lists them. The protected-resource metadata says which authorization server protects the endpoint, and the authorization-server metadata describes it. The resource audience is the MCP URL itself.
curl -sS https://mcp.sume.com/.well-known/oauth-protected-resource/mcp
curl -sS https://mcp.sume.com/.well-known/oauth-authorization-serverWhat to look for
authorization_serversshould be the MCP origin,https://mcp.sume.com, notwww.sume.comorapp.sume.com. The docs callwwwa secondary and deprecated surface that metadata no longer advertises.- The resource audience should be
https://mcp.sume.com/mcp. A client that requests a different audience will be refused. - Sign-in goes to
https://mcp.sume.com/oauth/authorize, which redirects to the consent page on the MCP host, then the client exchanges the code with PKCE.
Dev and the key fallback
Development uses the same shape on https://mcp.dev.sume.com; do not mix a dev connector with a production key. If the client cannot do OAuth at all, send Authorization: Bearer $SUME_API_KEY or x-api-key instead: API-key sessions see the full hosted tool set, and paid calls still need idempotency_key.
Never send interactive clients to app.sume.com for MCP OAuth. The MCP quickstart shows the supported connection steps for Claude Code, Cursor and Codex.
Sources
Related posts
More in Developers
- Avatar preview failed on Sume MCP: stop_and_ask, do not generate video
When an avatar video preview fails or is canceled, Sume MCP returns recovery code stop_and_ask: do not call generate_video, report the reason, offer a rewrite.
- timeline_get 409 job_not_completed on Sume MCP: retry, do not give up
A 409 job_not_completed from timeline_get means the render is still running, so retry. Call jobs_wait on the same job_id; never report the run blocked.
- Sume MCP tools_schema safety object: build a tool allowlist from it
Sume's tools_schema returns a safety object per tool: paid_generation, read_only, requires_idempotency_key and more. Build your agent allowlist from it.
- Why a Sume output schema is rejected: the strict subset rules
Sume saves an output schema only in the strict subset: object root, additionalProperties false, all properties required, nullable unions, 10 levels.
Written by Sume