Codex mcp_oauth_callback_port and the Sume OAuth login
Pin the Codex OAuth callback port for a remote Sume MCP login, and how the login flows from Codex to the Sume consent page on mcp.sume.com.

Codex's MCP page names mcp_oauth_callback_port as the fixed listener port for OAuth callbacks, and a per-server callback_port under [mcp_servers.<name>.oauth]. Set one, then run codex mcp login sume. The Sume side is unchanged: Codex is sent to https://mcp.sume.com/oauth/authorize, which continues to the consent page on the MCP host.
Codex keys come from its MCP page; the Sume flow comes from OAuth and API keys and the quickstart, read 2026-09-30.
What can Codex configure for the callback?
| Setting | What the Codex page says |
|---|---|
mcp_oauth_callback_url | Custom callback path or remote ingress URL |
mcp_oauth_callback_port | Fixed listener port for OAuth callbacks |
[mcp_servers.<name>.oauth] | Per-server callback_url and callback_port overrides |
| Default | Loopback callback at http://127.0.0.1/callback |
What happens on the Sume side during login?
The docs describe six steps: the client connects to https://mcp.sume.com/mcp, receives an OAuth challenge and protected-resource metadata, and sends you to https://mcp.sume.com/oauth/authorize. That redirects to GET /oauth/consent on the MCP host, where Read is locked on and the Write toggle defaults off. The client then exchanges the authorization code with PKCE and calls the endpoint with the bearer token.
How do I pin the port and log in?
Pick a free port, put it in the server's oauth table, and log in by server name. The Sume docs do not list allowed redirect URIs, so confirm by finishing one login rather than assuming.
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
[mcp_servers.sume.oauth]
callback_port = 8765
# then, in a shell:
# codex mcp login sumeWhat should I check after the login?
Ask Codex to call mcp_health and confirm authenticated.auth_source is mcp_oauth, then tools_list. With Write off you see read-only tools only. An OAuth token is not a Sume API key, and the docs say sume login does not broker hosted MCP tokens.
What if the login runs on a remote machine?
Codex's page names mcp_oauth_callback_url for a custom callback path or remote ingress URL, which the page describes that way. Sume's own docs say to complete the sign-in on the MCP host at https://mcp.sume.com/oauth/consent, not on app.sume.com, and that www.sume.com is a secondary and deprecated authorization surface that protected-resource metadata no longer advertises. The public metadata endpoints are https://mcp.sume.com/.well-known/oauth-protected-resource/mcp and https://mcp.sume.com/.well-known/oauth-authorization-server.
Sources
Related posts
More in Developers
- Codex MCP output_token_limit: what to set for Sume tools
Codex lets you cap one MCP tool's output with output_token_limit. Sume tools return ids and media.sume.com URLs, not file bytes, so the cap can stay small.
- Computer use origin approval is not a spend approval
OpenAI's computer use approves each new website origin, not spend. When such an agent calls Sume, the spend check is dry_run, max_spend_usd and the wallet.
- Content Credentials after download: check the file you deliver
C2PA 2.2 defines Content Credentials and a separate Soft Binding API. Sume's docs do not say a downloaded output keeps one, so check the delivered file.
- Can I continue a Sume Agent Completion with thread_id?
Not yet. Every Agent Completion runs in a fresh thread, so a follow-up call cannot reuse thread_id. Pass earlier results back in the next request instead.
Written by Sume