Workers OAuth Provider v1 or Sume's hosted MCP: which do I need?
Cloudflare's v1 OAuth library is for building your own MCP server. To call Sume tools from Claude or Cursor, connect Sume's hosted endpoint and skip the build.

If you want an agent to call Sume tools, connect the hosted endpoint at https://mcp.sume.com/mcp and stop there. Cloudflare's Workers OAuth Provider v1, released October 1, is for the opposite job: putting OAuth in front of an MCP server that you write. Reach for it when the tools you are exposing are yours.
What v1 changes
Cloudflare describes a split design. One Worker is the authorization server that signs users in and issues tokens, and your MCP server is the resource server. The release lists support for the MCP 2026-07-28 authorization specification, Client ID Metadata Documents, an insufficientScope() helper for step-up authorization, and one authorization server issuing tokens for several MCP servers. Cloudflare says v1 works with 0.x deployments, where the only required change is to add resourceMetadata: { resource }.
Build or connect
| Need | Workers OAuth Provider v1 | Sume hosted endpoint |
|---|---|---|
| Who writes the OAuth server | You, on Workers | Sume, on the MCP host |
| Scopes | Whatever you define | mcp:read required, mcp:write opt-in; no mcp:paid scope |
| Step-up | insufficientScope() in your code | A read-only session that calls a data-changing tool gets insufficient_scope |
| Token lifetime | refreshTokenIdleTTL sliding refresh expiry | Bearer token from the consent flow; API keys skip OAuth |
| Best when | You wrap your own system | You want Sume's generation, crawl and timeline tools |
The consent screen is the scope decision
On Sume's consent page Read is locked on and Write is off by default. That default is why a first connection can list tools and read balances but fails when the agent tries to generate media. Turn Write on only for clients that should spend. API-key sessions skip OAuth and see the full tool set, so paid calls there still need an idempotency_key, and an optional max_spend_usd caps the spend when you pass it.
Check the consent text before you approve. The page lists permissions, and Write grants access to the tools that change data and the paid tools. Read-only sessions are a good default for research agents that only inspect balances and usage.
Practical rule
Building a split authorization server makes sense when you have tools nobody else hosts. For Sume's own tools it duplicates work Sume already ships. The Sume docs I read do not state how long an OAuth token lasts, so for unattended jobs use an API key and pass max_spend_usd on paid calls.
Cloudflare also ships a migration skill inside the npm package and a migration guide. None of that changes the decision above: the library solves authorization for servers you own, and the hosted endpoint solves it for Sume's tools. If you have both kinds of tools, the agent client can list two servers: your own and the hosted endpoint.
Sources
More in Developers
- Zed context_servers for the hosted Sume server: no header means OAuth
Add the hosted Sume server to Zed's settings.json context_servers with a url. With no Authorization header Zed runs the MCP OAuth flow, so start with mcp:read.
- Which MCP server lets Claude Code or Cursor generate video and images?
MCP servers that let Claude Code and Cursor make video and images: Sume, fal, Replicate, Runway, Higgsfield. Endpoints, sign-in, billing, setup.
- Idempotency keys for AI video APIs: retry without paying twice
An idempotency key makes a retried create return the original run or job instead of a second paid one. How Sume's Idempotency-Key works on each API.
- Signed webhooks for Sume video runs: events, retries, verification
Sume sends one HMAC-SHA256 signed POST when a Format, Action, or Agent Completion run completes or fails. Verify the raw body and dedupe on request_id.
Written by Sume