Workers OAuth Provider v1 or Sume's hosted MCP: which do I need?

Cloudflare's v1 OAuth library is for building your own MCP server. To call Sume tools from Claude or Cursor, connect Sume's hosted endpoint and skip the build.

4 min readSume
All posts

If you want an agent to call Sume tools, connect the hosted endpoint at https://mcp.sume.com/mcp and stop there. Cloudflare's Workers OAuth Provider v1, released October 1, is for the opposite job: putting OAuth in front of an MCP server that you write. Reach for it when the tools you are exposing are yours.

What v1 changes

Cloudflare describes a split design. One Worker is the authorization server that signs users in and issues tokens, and your MCP server is the resource server. The release lists support for the MCP 2026-07-28 authorization specification, Client ID Metadata Documents, an insufficientScope() helper for step-up authorization, and one authorization server issuing tokens for several MCP servers. Cloudflare says v1 works with 0.x deployments, where the only required change is to add resourceMetadata: { resource }.

Build or connect

Own MCP server versus Sume's hosted endpoint (read 2026-10-06)
NeedWorkers OAuth Provider v1Sume hosted endpoint
Who writes the OAuth serverYou, on WorkersSume, on the MCP host
ScopesWhatever you definemcp:read required, mcp:write opt-in; no mcp:paid scope
Step-upinsufficientScope() in your codeA read-only session that calls a data-changing tool gets insufficient_scope
Token lifetimerefreshTokenIdleTTL sliding refresh expiryBearer token from the consent flow; API keys skip OAuth
Best whenYou wrap your own systemYou want Sume's generation, crawl and timeline tools

The consent screen is the scope decision

On Sume's consent page Read is locked on and Write is off by default. That default is why a first connection can list tools and read balances but fails when the agent tries to generate media. Turn Write on only for clients that should spend. API-key sessions skip OAuth and see the full tool set, so paid calls there still need an idempotency_key, and an optional max_spend_usd caps the spend when you pass it.

Check the consent text before you approve. The page lists permissions, and Write grants access to the tools that change data and the paid tools. Read-only sessions are a good default for research agents that only inspect balances and usage.

Practical rule

Building a split authorization server makes sense when you have tools nobody else hosts. For Sume's own tools it duplicates work Sume already ships. The Sume docs I read do not state how long an OAuth token lasts, so for unattended jobs use an API key and pass max_spend_usd on paid calls.

Cloudflare also ships a migration skill inside the npm package and a migration guide. None of that changes the decision above: the library solves authorization for servers you own, and the hosted endpoint solves it for Sume's tools. If you have both kinds of tools, the agent client can list two servers: your own and the hosted endpoint.

Sources

More in Developers

All Developers posts

Written by Sume