OAuthFlowError issuer mismatch in the MCP Python SDK 2.2

Python SDK 2.2 rejects authorization server metadata whose issuer is not the server's origin. Sume's metadata sets issuer to the MCP origin.

4 min readSume
All posts

Sume's authorization server metadata sets issuer to the MCP origin, which is what the check in Python SDK 2.2 compares against, so Sume metadata is built to pass. If you see OAuthFlowError: Authorization server metadata issuer mismatch against a Sume URL, check that you are pointing the client at https://mcp.sume.com/mcp and not at another host.

SDK facts are from the Python SDK release notes; Sume facts from MCP OAuth and API keys and the OAuth package source, read 2026-09-30.

When does the SDK raise this error?

The notes say that for servers without protected resource metadata, authorization server metadata whose issuer is not the server's own origin is now rejected with this error. The protected-resource-metadata path has done the same check since 2.0.

What does Sume return?

Sume OAuth metadata, read 2026-09-30
ItemValue
issuerThe MCP origin
authorization_servers in protected-resource metadataThe MCP origin, not www or app.sume.com
grant_types_supported["authorization_code"]
token_endpoint_auth_methods_supported["none"] (public client)
Consent pageFirst-party, on the MCP host

How do I fix a mismatch against Sume?

Use the MCP origin as the server URL, then let the client discover metadata from https://mcp.sume.com/.well-known/oauth-protected-resource/mcp. The docs say www.sume.com remains a secondary, deprecated authorization-server surface that protected-resource metadata no longer advertises, and not to send interactive clients to app.sume.com. If a proxy rewrites the host, the issuer will no longer match the origin the client connected to.

Is there a different issuer problem I might be hitting?

A missing iss parameter on the redirect is a separate check; see the missing-issuer case for Gemini CLI and Codex. For unattended jobs, the API key route avoids OAuth altogether: API key vs OAuth.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume