Zed MCP OAuth scopes: what Sume asks for (mcp:read, mcp:write)
Zed 1.18.0 fixed OAuth for MCP servers with non-default scopes. Sume has two scopes, mcp:read (required) and mcp:write (opt-in on the consent page).

Sume's hosted MCP advertises exactly two OAuth scopes: mcp:read, which is required, and mcp:write, which is opt-in. Zed 1.18.0 (Sep 2, 2026) fixed OAuth "failing with MCP servers that require non-default scopes", and Sume's server is reached at https://mcp.sume.com/mcp. The write grant is chosen on Sume's consent page, not by Zed.
What did Zed 1.18.0 change?
The release note, read 2026-09-30, is one line: "Fixed OAuth authentication failing with MCP servers that require non-default scopes." It does not say which servers or which scope strings were affected, so this post does not claim Sume was one of them. If an earlier Zed build failed against a server for scope reasons, update Zed first.
Which scopes does Sume support?
The Sume docs list the scopes and what each session sees. See MCP OAuth and API keys.
| Scope | Status | What the session gets |
|---|---|---|
mcp:read | Required | Read-only tools only |
mcp:write | Opt-in; includes read | Mutating and paid tools |
mcp:paid | Does not exist | Paid submits use wallet and admission |
How do I get write access from Zed?
Sign in through the OAuth flow and, on the consent page, turn the Write toggle on. It defaults to off, and Read is locked on. A read-only session that calls a mutating tool gets insufficient_scope. After connecting, call mcp_health and check that authenticated.auth_source is mcp_oauth, then tools_list to see what the session can use; the tools and gates page has the playbook.
What if I need automation without a browser?
API keys are the other path: send Authorization: Bearer or x-api-key. Those sessions see write and paid tools, and writes still need an idempotency_key. An OAuth token is not a Sume API key, so do not mix them. For the Zed setup itself see Zed MCP server for Sume.
Sources
Related posts
More in Integrations
- How to add an MCP server to ChatGPT with developer mode
Turn on ChatGPT developer mode, create an app for the server's URL, and sign in with OAuth. The steps, with Sume's hosted MCP server as the example.
- How to add subtitles to a video in Python
Add subtitles to a video in Python with Requests: POST the video URL to Sume's /v1/video-captions, poll the job, then read the captioned video_url.
- Add Sume to Claude as a custom connector (remote MCP)
Add Sume's hosted MCP server to Claude under Customize > Connectors, see what Sume's OAuth consent grants, and decide whether to allow paid tools.
- Airflow HTTP sensor: wait for an AI video job to finish
Submit an AI video job with Airflow's HttpOperator, then wait with an HttpSensor in reschedule mode that passes once the job's status is completed.
Written by Sume