Amp MCP server: amp mcp remote add with a bearer token file for Sume
Add Sume's hosted MCP to Amp with amp mcp remote add --auth bearer --bearer-token-file, so the Sume API key never appears in a command line.

To add Sume to Amp, run amp mcp remote add sume https://mcp.sume.com/mcp --auth bearer --bearer-token-file /path/to/token --personal. Amp's docs say to pass credentials by file and never as command arguments (read 2026-10-02), which suits a Sume API key that would otherwise sit in your shell history.
What Amp's MCP page documents
Amp's page lists three auth modes for remote servers and a set of scopes. Sume accepts a bearer API key in the Authorization header, so --auth bearer is the match for the key route (OAuth and API keys).
| Option | What Amp's docs say | For Sume |
|---|---|---|
--auth oauth | OAuth, detected automatically or set explicitly | Not covered by Sume's docs for Amp |
--auth bearer --bearer-token-file | Bearer token passed through a file, never as an argument | The Sume API key in a file |
--auth none | No authentication | Not applicable; Sume requires auth |
--personal | Scope for your own config; others are --workspace, --project, --current-project | --personal |
amp.mcpServers | Settings key with url and optional headers | The hosted URL |
check and remove | Verify or delete a remote server | Use check after adding |
umask 077
printf '%s' "$SUME_API_KEY" > ~/.config/sume-mcp-token
amp mcp remote add sume https://mcp.sume.com/mcp \
--auth bearer \
--bearer-token-file ~/.config/sume-mcp-token \
--personal
amp mcp remote --personal check sumeWhy a token file helps here
Sume's docs tell you to rotate an API key if it appears in logs or chat history. A command argument can end up in both shell history and process listings, and a file path cannot leak the value that way. Create the file with a restrictive mode, as the snippet does, and keep it out of any repository.
The check subcommand from Amp's page is a sensible first step. Then ask Amp to call Sume's mcp_health, which reports the endpoint, auth source and safety posture (MCP quickstart).
What the key unlocks
An API-key session sees the full hosted tool set, including paid generation. Paid and write tools need an idempotency_key; dry_run=true previews the cost; max_spend_usd is enforced only when provided (MCP tools and gates).
The Amp page I read does not describe a per-tool filter, so I will not claim one. If you need a read-only session, the route in Sume's docs is OAuth with mcp:read only, and I have not verified that Amp completes it. Otherwise keep the instruction explicit: run tools_schema and dry_run before spending, and read results with jobs_status rather than resubmitting.
Two cautions
After connecting, a jobs_wait call can hold for up to 55 seconds, so watch for client timeouts on long video jobs (Jobs and results).
- Amp's docs example for a hosted server uses an SSE-style path; Sume's endpoint is the streamable HTTP URL in the table, so do not swap it for another path.
- If
checkreports a failure, re-read the token file for a trailing newline or empty content before suspecting the endpoint.
Sources
Related posts
More in Integrations
- Apps Script doPost and the Sume webhook signature: what you can verify
An Apps Script web app doPost documents the body but no headers, and Sume signs in headers. Treat the callback as a hint and re-read the job with your key.
- Apps Script 90-minute daily trigger runtime: polling Sume jobs
Consumer Google accounts get 90 minutes of trigger runtime a day. Poll Sume jobs from one time-driven trigger that scans the sheet, not one trigger per row.
- Apps Script UrlFetch 20,000 calls a day: budget Sume polling
Consumer Apps Script allows 20,000 UrlFetch calls a day and 90 minutes of trigger time. One Sume bulk run per sheet plus a slow poll fits well inside both.
- Apps Script UrlFetch 20,000/day and 6 min: size a Sume sheet run
Apps Script allows 20,000 UrlFetch calls a day and 6 minutes per run on a consumer account. How to size a Sume sheet batch inside both limits.
Written by Sume