MCP DCR application_type: what Sume's register endpoint reads
The 2026-07-28 MCP spec asks clients to send application_type in dynamic registration. Sume's /oauth/register reads redirect_uris and other named fields.

Send the application_type your client library requires; Sume's registration code does not read it and does not echo it back. What Sume does check is redirect_uris, which is where a registration most often fails, plus two fields it only accepts with fixed values (token_endpoint_auth_method and grant_types).
Vendor facts are from the MCP 2026-07-28 changelog; Sume facts are from the packages/mcp-oauth source and the MCP OAuth docs, read 2026-10-01. See also how Codex registers with Sume.
What does the MCP changelog say?
Two relevant lines. MCP clients are required to specify an appropriate application_type during Dynamic Client Registration. Separately, the changelog deprecates the OAuth 2.0 Dynamic Client Registration protocol, with a twelve-month deprecation window.
Which fields does Sume's registration read?
| Field | Handling |
|---|---|
redirect_uris | Required non-empty array of strings, at most 10 |
client_name, scope | Read and normalized |
token_endpoint_auth_method | Must be none if sent (anything else is rejected); response is always none |
grant_types | Must include authorization_code (refresh_token is tolerated); response is ["authorization_code"] |
application_type | Not read, not returned |
Which redirect URIs are allowed?
https: URIs are accepted, http: only for localhost and 127.0.0.1, and the Cursor callback cursor://anysphere.cursor-mcp/oauth/callback. Anything else is rejected at registration with invalid_redirect_uri. This is the practical difference between a native and a web client at Sume: a desktop client uses a loopback URL, a hosted client an https one.
Does the deprecation change what I should build?
Authorization server metadata at Sume still advertises a registration endpoint at /oauth/register. Keep registration working for now and watch the changelog for the end of the window.
Sources
Related posts
More in Developers
- MCP server URL trailing slash 404: use mcp.sume.com/mcp
Sume's hosted MCP URL is https://mcp.sume.com/mcp with no trailing slash. The server registers that exact path, so write it as documented; skip redirect flags.
- MCP ETag on tool results: Sume idempotency_key and job reads
ETag-versioned MCP tool results are a roadmap idea. In Sume, idempotency_key is write dedup, not a cache validator; job reads are separate read tools.
- MCP GET stream endpoint removed: Sume GET /mcp returns 405
MCP 2026-07-28 removes the GET stream endpoint. Sume's remote MCP already answers GET /mcp with 405 and Allow: POST, so send every message as an HTTP POST.
- MCP human-presence attestation: Sume consent vs API key
Human-presence attestation is only a roadmap topic. Sume separates people from automation by credential: OAuth consent in a browser, or an API key.
Written by Sume