MCP workload identity federation: Sume takes code grant only

MCP's roadmap names Workload Identity Federation. Sume's hosted MCP advertises only the authorization_code grant, so headless workloads use an API key.

4 min readSume
All posts

A cloud workload with no browser cannot use Sume's hosted MCP OAuth today. The authorization server advertises one grant type, authorization_code, and any other grant gets unsupported_grant_type. For headless automation the docs point to API-key remote MCP.

The roadmap side is from the MCP roadmap (last updated 2026-08-22), read 2026-10-01; Sume's side from packages/mcp-oauth and MCP OAuth and API keys.

What does the roadmap mean by Workload Identity Federation?

The roadmap says MCP authorization assumes a person with a browser at consent time, while the caller is increasingly an agent such as a cloud workload with its own identity. It names Workload Identity Federation (SEP-1933) as part of an opinionated way for servers to be reached by agents, and it is still work for the Agent Identity group.

What does Sume accept at the token endpoint?

Sume's hosted MCP token behavior from packages/mcp-oauth, read 2026-10-01.
RequestResult
grant_type=authorization_code (PKCE)Accepted
Any other grant_typeunsupported_grant_type
Error text"OAuth grant_type must be authorization_code."
Metadata grant_types_supported["authorization_code"]

What should an unattended workload use instead?

The docs say API-key remote MCP remains the other path for automation that does not speak OAuth. Send Authorization: Bearer <SUME_API_KEY> or x-api-key. API-key sessions see the full tool set, and write or paid calls still need an idempotency_key. Store the key in your secret manager and rotate it if it shows up in logs.

Can I mint an API key for an OAuth client?

No. The docs say not to mint API keys for hosted OAuth clients as a workaround, and an MCP OAuth token is not a Sume API key. See also why client credentials fail against Sume.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume