MCP DCR application_type: what Sume's register endpoint reads

The 2026-07-28 MCP spec asks clients to send application_type in dynamic registration. Sume's /oauth/register reads redirect_uris and other named fields.

4 min readSume
All posts

Send the application_type your client library requires; Sume's registration code does not read it and does not echo it back. What Sume does check is redirect_uris, which is where a registration most often fails, plus two fields it only accepts with fixed values (token_endpoint_auth_method and grant_types).

Vendor facts are from the MCP 2026-07-28 changelog; Sume facts are from the packages/mcp-oauth source and the MCP OAuth docs, read 2026-10-01. See also how Codex registers with Sume.

What does the MCP changelog say?

Two relevant lines. MCP clients are required to specify an appropriate application_type during Dynamic Client Registration. Separately, the changelog deprecates the OAuth 2.0 Dynamic Client Registration protocol, with a twelve-month deprecation window.

Which fields does Sume's registration read?

Sume registration handling, from packages/mcp-oauth, read 2026-10-01
FieldHandling
redirect_urisRequired non-empty array of strings, at most 10
client_name, scopeRead and normalized
token_endpoint_auth_methodMust be none if sent (anything else is rejected); response is always none
grant_typesMust include authorization_code (refresh_token is tolerated); response is ["authorization_code"]
application_typeNot read, not returned

Which redirect URIs are allowed?

https: URIs are accepted, http: only for localhost and 127.0.0.1, and the Cursor callback cursor://anysphere.cursor-mcp/oauth/callback. Anything else is rejected at registration with invalid_redirect_uri. This is the practical difference between a native and a web client at Sume: a desktop client uses a loopback URL, a hosted client an https one.

Does the deprecation change what I should build?

Authorization server metadata at Sume still advertises a registration endpoint at /oauth/register. Keep registration working for now and watch the changelog for the end of the window.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume