Zed MCP OAuth scopes: what Sume asks for (mcp:read, mcp:write)

Zed 1.18.0 fixed OAuth for MCP servers with non-default scopes. Sume has two scopes, mcp:read (required) and mcp:write (opt-in on the consent page).

4 min readSume
All posts

Sume's hosted MCP advertises exactly two OAuth scopes: mcp:read, which is required, and mcp:write, which is opt-in. Zed 1.18.0 (Sep 2, 2026) fixed OAuth "failing with MCP servers that require non-default scopes", and Sume's server is reached at https://mcp.sume.com/mcp. The write grant is chosen on Sume's consent page, not by Zed.

What did Zed 1.18.0 change?

The release note, read 2026-09-30, is one line: "Fixed OAuth authentication failing with MCP servers that require non-default scopes." It does not say which servers or which scope strings were affected, so this post does not claim Sume was one of them. If an earlier Zed build failed against a server for scope reasons, update Zed first.

Which scopes does Sume support?

The Sume docs list the scopes and what each session sees. See MCP OAuth and API keys.

Sume hosted-MCP OAuth scopes from the docs, read 2026-09-30.
ScopeStatusWhat the session gets
mcp:readRequiredRead-only tools only
mcp:writeOpt-in; includes readMutating and paid tools
mcp:paidDoes not existPaid submits use wallet and admission

How do I get write access from Zed?

Sign in through the OAuth flow and, on the consent page, turn the Write toggle on. It defaults to off, and Read is locked on. A read-only session that calls a mutating tool gets insufficient_scope. After connecting, call mcp_health and check that authenticated.auth_source is mcp_oauth, then tools_list to see what the session can use; the tools and gates page has the playbook.

What if I need automation without a browser?

API keys are the other path: send Authorization: Bearer or x-api-key. Those sessions see write and paid tools, and writes still need an idempotency_key. An OAuth token is not a Sume API key, so do not mix them. For the Zed setup itself see Zed MCP server for Sume.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume