Devin Desktop MCP authorization opens the provider: Sume page
Devin Desktop 3.10.23 opens MCP authorization at the provider directly. For Sume that is mcp.sume.com/oauth/authorize, then a consent page on the MCP host.

The Devin Desktop changelog for v3.10.23 (September 10) says "MCP authorization opens the provider directly." The changelog line is one sentence and does not name Sume; reading it against Sume's docs, the provider is the MCP host: the client sends the user to https://mcp.sume.com/oauth/authorize, which redirects to a first-party consent page on the same host.
Vendor facts are from the changelog; Sume facts from MCP OAuth, read 2026-10-01.
What is the Sume authorization flow?
The docs list six steps for the hosted flow.
| Step | What happens |
|---|---|
| 1 | Client connects to https://mcp.sume.com/mcp |
| 2 | Sume returns an OAuth challenge and protected-resource metadata |
| 3 | Client sends the user to https://mcp.sume.com/oauth/authorize, which redirects to /oauth/consent on the MCP host |
| 4 | Consent shows Read locked on and Write default off |
| 5 | Client exchanges the code (PKCE) for an access token |
| 6 | Client calls /mcp with the bearer token |
Which origin is the authorization server?
The MCP origin. The docs say authorization_servers is the MCP origin, not www or app.sume.com, and tell clients not to send interactive users to app.sume.com for MCP OAuth. Metadata is public at https://mcp.sume.com/.well-known/oauth-authorization-server and https://mcp.sume.com/.well-known/oauth-protected-resource/mcp.
What if the browser shows a redirect error?
Sume's server rejects a redirect_uri that is not allowed with the message "OAuth redirect_uri is not allowed." Check that the client registered the callback it actually uses. Cursor has a page on the same class of problem.
How do I add Sume in Devin Desktop?
Add https://mcp.sume.com/mcp as a remote MCP server (the exact menu labels are in Devin Desktop's own docs), complete the browser sign-in, and leave Write off unless the agent needs it. The Windsurf page covers the older editor naming: Windsurf MCP server for Sume.
Sources
Related posts
More in Integrations
- Devin MCP write scopes by default: Sume keeps write opt-in
Devin now requests read/write scopes by default for Microsoft 365 MCP. Sume's hosted MCP asks for read only unless the user turns Write on at consent.
- Discord attachment file_types: image-only option for Sume video
Discord ATTACHMENT command options now accept file_types. Limit a slash command to images, then pass the attachment's public URL to a Sume image-to-video job.
- fal MCP "why did my request fail": the Sume job equivalent
fal's Platform MCP lets an assistant debug a failed request. For a failed Sume media job, read jobs_events and the error, then retry by the error rules.
- Gemini CLI 0.62 MCP tool titles: read a Sume call before approving
Gemini CLI 0.62.0 formats MCP tool call titles as structured signatures. The fields to check on a paid Sume call before you approve it.
Written by Sume