Gemini CLI keeps the OAuth refresh token: what Sume's MCP does
Gemini CLI 0.62 retains the OAuth refresh token on refresh. Sume's MCP token endpoint accepts only authorization_code, so expect a fresh sign-in, not a refresh.

The Gemini CLI fix keeps a refresh token it already has; it does not make a server issue one. Sume's hosted MCP token endpoint accepts only the authorization_code grant and rejects any other grant_type, so against Sume the stored credential expires and the CLI has to run the sign-in again, or you use an API key.
The CLI fact is from the Gemini CLI release notes; the Sume facts are from the MCP OAuth package source and MCP OAuth and API keys, read 2026-09-30.
What changed in Gemini CLI 0.62?
The v0.62.0 release notes (dated 2026-09-29) list one entry: "fix(core): retain oauth refresh token on refresh and make credential deletion idempotent" (pull request 29339). The notes say nothing more about how it behaves per server, so this post does not either.
What does Sume's token endpoint accept?
| Item | Value in source |
|---|---|
grant_types_supported | ["authorization_code"] |
Other grant_type values | Error: "OAuth grant_type must be authorization_code." |
token_endpoint_auth_methods_supported | ["none"] (public clients) |
| Scopes | mcp:read (required), mcp:write (opt-in) |
So is there a refresh token to retain?
A code comment in the package says clients often advertise refresh_token, that Sume ignores it, and that refresh is not implemented yet. Treat that as today's behavior, not a promise. The longer explanation is in Sume's one-hour token with no refresh.
What should I do for a long Gemini CLI session?
Two options from the docs. Re-authorize when the token lapses: the consent screen shows Read locked on and a Write toggle that defaults to off, and a read-only (mcp:read) session sees only read tools. Or send an API key, which gets the full hosted tool set, with idempotency_key required on write and paid calls. Pick one per job; a read-only session that hits a write tool gets insufficient_scope, not a prompt to refresh.
Sources
Related posts
More in Developers
- Gemini CLI trust: true on a Sume MCP server: what it skips
Gemini CLI's trust setting bypasses every tool confirmation dialog. What that means for Sume's paid tools, and which Sume gates still apply.
- Gemini Omni first and last frame: image_url + end_image_url
Google calls it Interpolation (first + last frame). On Sume you send image_url plus end_image_url to gemini-omni-flash-1.1 through the Video Router.
- Gemini rate limits: per project, not per API key. And Sume?
Google says Gemini rate limits apply per project, not per API key, so a second key adds nothing. What Sume's docs say about plan limits and how to read them.
- Gemini TTS regional voices vs Sume's language tag
Google says Gemini 3.8 TTS covers Mexican Spanish and Quebec French. Sume's language takes a BCP-47 tag of 2 to 16 characters; dialect output is not promised.
Written by Sume