Claude Code --callback-port: do you need it for Sume MCP?

No. --callback-port is for servers that need a pre-registered redirect URI. Sume registers clients dynamically, so Claude Code's default random port works.

5 min readSume
All posts

You do not need --callback-port to connect Claude Code to Sume's hosted MCP server. The flag fixes the local port of the OAuth callback for servers that make you register a redirect URI in advance. Sume's authorization server advertises a registration endpoint, so claude mcp add then claude mcp login sume works with Claude Code's default of a random available port.

Claude Code's flags come from its MCP documentation, read 2026-09-29. Sume's side comes from MCP OAuth and API keys and, where marked, current code.

What does --callback-port do?

By default Claude Code picks a random available port for the OAuth callback. Some servers require a specific redirect URI registered ahead of time, of the form http://localhost:PORT/callback. --callback-port fixes the port so it matches that registration.

It can be used alone, with dynamic client registration, or together with --client-id for pre-configured credentials. The --client-secret flag prompts for the secret with masked input, and a public client with no secret uses only --client-id.

From the Claude Code MCP page, read 2026-09-29.
FlagUse it when
--callback-portThe server needs a redirect URI registered in advance
--client-idYou created an OAuth app in the server's developer portal
--client-secretThat app is a confidential client with a secret

Why doesn't Sume need a fixed port?

Sume publishes discovery documents at https://mcp.sume.com/.well-known/oauth-protected-resource/mcp and https://mcp.sume.com/.well-known/oauth-authorization-server, listed in MCP OAuth and API keys. In current code, the authorization-server metadata includes a registration endpoint, so a client can register itself instead of being pre-registered by hand.

The same code accepts an http redirect URI whose host is localhost or 127.0.0.1 without pinning a port, and accepts any https redirect URI. Registration is for public clients only (token_endpoint_auth_method none) and uses PKCE, so there is no client secret to pass.

What does the connect flow look like without the flag?

These are the two commands in Sume's MCP quickstart. Claude Code discovers the endpoint's protected-resource metadata, sends you to https://mcp.sume.com/oauth/authorize, and the consent page on the MCP host shows Read locked on and Write off by default.

claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume

Why do I get a redirect URI error anyway?

In current code, Sume refuses a redirect URI that is not registered for the client id with the message OAuth redirect_uri is not registered for this client, and refuses a redirect that is not https, a loopback http address, or Cursor's own scheme with OAuth redirect_uri is not allowed. The first means that address is not in the list registered for that client id. The second means the address is not one of the accepted kinds.

Claude Code's docs say that removing a remote server deletes the OAuth tokens and client registration it stored. So the clean retry is claude mcp remove sume, then add and log in again with no --callback-port. If a firewall rule forces a known port, --callback-port on its own still works with dynamic registration, per Claude Code's page.

Sume's rules also accept Cursor's own callback scheme.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume