OAuthFlowError issuer mismatch in the MCP Python SDK 2.2
Python SDK 2.2 rejects authorization server metadata whose issuer is not the server's origin. Sume's metadata sets issuer to the MCP origin.

Sume's authorization server metadata sets issuer to the MCP origin, which is what the check in Python SDK 2.2 compares against, so Sume metadata is built to pass. If you see OAuthFlowError: Authorization server metadata issuer mismatch against a Sume URL, check that you are pointing the client at https://mcp.sume.com/mcp and not at another host.
SDK facts are from the Python SDK release notes; Sume facts from MCP OAuth and API keys and the OAuth package source, read 2026-09-30.
When does the SDK raise this error?
The notes say that for servers without protected resource metadata, authorization server metadata whose issuer is not the server's own origin is now rejected with this error. The protected-resource-metadata path has done the same check since 2.0.
What does Sume return?
| Item | Value |
|---|---|
issuer | The MCP origin |
authorization_servers in protected-resource metadata | The MCP origin, not www or app.sume.com |
grant_types_supported | ["authorization_code"] |
token_endpoint_auth_methods_supported | ["none"] (public client) |
| Consent page | First-party, on the MCP host |
How do I fix a mismatch against Sume?
Use the MCP origin as the server URL, then let the client discover metadata from https://mcp.sume.com/.well-known/oauth-protected-resource/mcp. The docs say www.sume.com remains a secondary, deprecated authorization-server surface that protected-resource metadata no longer advertises, and not to send interactive clients to app.sume.com. If a proxy rewrites the host, the issuer will no longer match the origin the client connected to.
Is there a different issuer problem I might be hitting?
A missing iss parameter on the redirect is a separate check; see the missing-issuer case for Gemini CLI and Codex. For unattended jobs, the API key route avoids OAuth altogether: API key vs OAuth.
Sources
Related posts
More in Developers
- MCP Python SDK idle session 404: what it means for Sume jobs
Python SDK 2.2 closes stateful sessions idle for 30 minutes, then 404s. Sume's hosted MCP is POST-only; re-poll jobs_wait with the same ids, never resubmit.
- MCP server/discover against Sume's hosted endpoint
The 2026-07-28 MCP spec adds server/discover. Sume's hosted server does not implement it and answers -32601; read initialize and tools/list instead.
- MCP server notify when work finished: Sume webhooks vs jobs_wait
The MCP roadmap lists push delivery for finished work. On Sume today, MCP agents wait in bounded jobs_wait slices; HMAC webhooks are a REST job feature.
- MCP subscriptions/listen: Sume has no push stream to join
MCP's 2026-07-28 spec adds subscriptions/listen for change notifications. Sume's hosted MCP answers POST only and declares listChanged false.
Written by Sume