Claude Code MCP sign-in link stopped working: use the newest one

A repeat MCP sign-in request replaces the pending link in Claude Code, so the older link can stop working. Finish the newest Sume sign-in link only.

4 min readSume
All posts

If a Sume sign-in link from Claude Code does nothing, request sign-in once more and open only the newest link. The Claude Code changelog lists a fix where a repeat MCP sign-in request replaced the pending link, "which could stop that link from working".

The changelog line is the only vendor claim used here. The Sume flow is from MCP OAuth and API keys. Both were read 2026-10-01.

What does the changelog say?

One entry reads: "Fixed a repeat MCP sign-in request from Claude replacing the pending sign-in link, which could stop that link from working". It does not say which versions are affected beyond where it appears in the changelog, so check the entry against the version you run.

What does the Sume sign-in look like?

The docs describe six steps. Step 3 is the one that produces a link: the client sends the user to https://mcp.sume.com/oauth/authorize, which redirects to the consent page on the MCP host. Each new sign-in request starts that sequence again.

Hosted Sume OAuth steps, from the docs read 2026-10-01: https://docs.sume.com/mcp/oauth
StepWhat happens
1Client connects to https://mcp.sume.com/mcp.
2Sume returns an OAuth challenge and protected-resource metadata.
3Client sends the user to /oauth/authorize on the MCP host.
4Consent: Read locked on, Write off by default.
5Client exchanges the authorization code (PKCE) for an access token.
6Client calls the endpoint with that bearer token.

Why would an older link fail?

Because step 5 is a PKCE exchange, the code that comes back has to be completed by the client that started that request. If the client replaced its pending request, a link from the earlier attempt has no client waiting for it. That is an inference from the PKCE step and the changelog entry, not something either page states. Sume advertises S256 as the supported challenge method.

What should I do when the link fails?

Close the old browser tab, ask Claude Code to sign in once, and finish that one link without requesting another meanwhile. Access tokens last one hour, so you may repeat this later; see the one-hour token note. Over SSH with no browser, use the SSH login guide.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume