Claude Code headless MCP auth reminder: Sume key vs OAuth expiry
Claude Code 2.1.286 fixed a repeated MCP auth reminder in headless runs. Sume OAuth tokens last one hour with no refresh, so unattended runs should use a key.

For an unattended Claude Code run, connect Sume with an API key instead of OAuth. Sume's hosted OAuth access token lasts one hour and the server does not implement refresh, so a long headless job would eventually need a fresh interactive sign-in; an API key does not expire on that clock.
Claude Code 2.1.286's changelog says it fixed headless sessions repeating the "MCP servers require authentication" reminder after a successful re-authentication when the MCP discovery cache is enabled. Sume details are from MCP OAuth and API keys and the OAuth package source, read 2026-10-01.
What did the Claude Code fix change?
Only the repeated reminder: after you re-authenticated, a headless session with the discovery cache on kept printing it. The fix does not make a token last longer, and a headless run has nobody to click through consent anyway.
How long does a Sume OAuth token last?
MCP_OAUTH_ACCESS_TOKEN_TTL_SECONDS is 60 * 60, one hour. The registration code notes that clients such as Cursor advertise refresh_token, but the server ignores it because refresh is not implemented yet and it only stores authorization_code. Plan on a re-consent after an hour.
| Credential | Lifetime | Fits unattended runs? |
|---|---|---|
| OAuth access token | 1 hour, no refresh grant | No |
API key (Authorization: Bearer or x-api-key) | until you rotate it | Yes |
How do I run headless with a key?
Send the key as a bearer header from an environment variable, never inline in a committed config; the docs call API-key remote MCP the path for automation that does not speak OAuth. Writes still need an idempotency_key. A config example is in headless MCP config for video.
Sources
Related posts
More in Developers
- Claude Code MCP OAuth token lost, keychain locked: Sume tokens
Claude Code 2.1.281 stops a locked macOS keychain from dropping stored MCP OAuth tokens. A Sume token lasts one hour with no refresh grant.
- CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTH and Sume server instructions
Claude Code 2.1.280 lets CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTH change the 2,048-character cap. Sume's instructions are long; use tools_schema.
- claude mcp add refused: managed settings, plugins only, Sume
Claude Code 2.1.284 refuses claude mcp add when managed settings limit MCP servers to plugins. What the Sume remote URL needs from your admin.
- Claude Code MCP connector lists no tools: Sume handshake versions
Claude Code 2.1.286 fixed connectors showing no tools after a server dropped an older handshake. Sume answers 2025-03-26, 2025-06-18 and 2025-11-25.
Written by Sume