Claude Code MCP 403 insufficient_scope: re-auth Sume with Write
Claude Code 2.1.274 names the missing permission on a 403 insufficient_scope. For Sume, a read-only grant lacks mcp:write: re-authenticate and turn Write on.

If Claude Code shows a 403 insufficient_scope from the Sume server, your sign-in is valid but only has mcp:read. Run /mcp, re-authenticate Sume, and switch Write on at the consent screen so the session also gets mcp:write.
Claude Code 2.1.274 changed this message: per its changelog, the error now names the missing permissions and points to /mcp re-authentication instead of reading as an expired sign-in. Sume details are from MCP OAuth and API keys, read 2026-10-01.
Why does a read-only grant return insufficient_scope?
Hosted OAuth grants read-only access by default. The docs say mcp:read sessions only see read-only tools, and a mutating tool called without write returns insufficient_scope. In the server, that error carries a missing-write message and required_scope. The docs name the code insufficient_scope; whether your client shows it as an HTTP 403 is the client's reporting, which the changelog entry above improves.
What exactly do I click?
Consent shows Permissions with Read locked on and a Write toggle that defaults to off. Turn Write on and continue; granting write always includes read. There is no mcp:paid scope, so paid submits are governed by wallet and admission, not by a third permission.
| Grant | Tools visible | Mutating call result |
|---|---|---|
mcp:read (default) | read-only tools | insufficient_scope |
mcp:write (Write toggled on) | mutating and paid tools | runs |
| API key | full hosted tool set | runs |
Is there a way to skip the consent step?
Yes, for automation: an API key sent as Authorization: Bearer <SUME_API_KEY> or x-api-key gets the full hosted tool set, and idempotency_key is still required on writes. For an interactive session, re-consenting is the intended path. If the 403 persists after Write is on, see insufficient_scope troubleshooting.
Sources
Related posts
More in Developers
- Claude Code alwaysLoad meta false: deferred Sume tools
Claude Code 2.1.285: a tool with _meta anthropic/alwaysLoad false stays deferred under a server alwaysLoad. What that means for Sume's tool set.
- Claude Code API 400 after a tool returned an object: Sume results
Claude Code 2.1.286 fixed API 400s when a tool returned an object, number or boolean. Sume tools return text content blocks, errors too.
- Claude Code background Bash 30-minute limit and Sume jobs
Claude Code 2.1.285 stops background Bash after 30 minutes by default (2 h max). A Sume render is a job id, so poll it with jobs_wait slices, never resubmit.
- Claude Code Bedrock/Vertex MCP 2026-07-28 default vs Sume
Claude Code on Bedrock, Vertex and Foundry now negotiates MCP 2026-07-28 by default. The opt-out env vars, and the versions the Sume server accepts.
Written by Sume