MCP workload identity federation: Sume takes code grant only
MCP's roadmap names Workload Identity Federation. Sume's hosted MCP advertises only the authorization_code grant, so headless workloads use an API key.

A cloud workload with no browser cannot use Sume's hosted MCP OAuth today. The authorization server advertises one grant type, authorization_code, and any other grant gets unsupported_grant_type. For headless automation the docs point to API-key remote MCP.
The roadmap side is from the MCP roadmap (last updated 2026-08-22), read 2026-10-01; Sume's side from packages/mcp-oauth and MCP OAuth and API keys.
What does the roadmap mean by Workload Identity Federation?
The roadmap says MCP authorization assumes a person with a browser at consent time, while the caller is increasingly an agent such as a cloud workload with its own identity. It names Workload Identity Federation (SEP-1933) as part of an opinionated way for servers to be reached by agents, and it is still work for the Agent Identity group.
What does Sume accept at the token endpoint?
| Request | Result |
|---|---|
grant_type=authorization_code (PKCE) | Accepted |
Any other grant_type | unsupported_grant_type |
| Error text | "OAuth grant_type must be authorization_code." |
Metadata grant_types_supported | ["authorization_code"] |
What should an unattended workload use instead?
The docs say API-key remote MCP remains the other path for automation that does not speak OAuth. Send Authorization: Bearer <SUME_API_KEY> or x-api-key. API-key sessions see the full tool set, and write or paid calls still need an idempotency_key. Store the key in your secret manager and rotate it if it shows up in logs.
Can I mint an API key for an OAuth client?
No. The docs say not to mint API keys for hosted OAuth clients as a workaround, and an MCP OAuth token is not a Sume API key. See also why client credentials fail against Sume.
Sources
Related posts
More in Developers
- MCP x-mcp-header and Mcp-Param headers vs Sume idempotency_key
The MCP 2026-07-28 spec can mirror tool parameters into Mcp-Param headers via x-mcp-header. Sume takes idempotency_key as a tool argument in the JSON body.
- Ming Design-Layer splits a design into RGBA layers: Sume does not
Ming-Image-0.1-Design-Layer decomposes a flat design into RGBA PNG layers. Sume's Image API returns finished images, so build layers from transparent elements.
- Ming-Image-0.1-Design on Sume: not in the catalog, use these
Ming-Image-0.1-Design is an open 6B design model. Sume's image catalog does not list it, so send a listed model id such as openai/gpt-image-2.5 for posters.
- MiniMax H3 first_frame and reference roles can't mix: Sume rule
MiniMax H3 treats first/last frames and reference roles as mutually exclusive. On Sume, frame_images takes precedence over input_references. Which to send.
Written by Sume