Amp MCP server: amp mcp remote add with a bearer token file for Sume

Add Sume's hosted MCP to Amp with amp mcp remote add --auth bearer --bearer-token-file, so the Sume API key never appears in a command line.

5 min readSume
All posts

To add Sume to Amp, run amp mcp remote add sume https://mcp.sume.com/mcp --auth bearer --bearer-token-file /path/to/token --personal. Amp's docs say to pass credentials by file and never as command arguments (read 2026-10-02), which suits a Sume API key that would otherwise sit in your shell history.

What Amp's MCP page documents

Amp's page lists three auth modes for remote servers and a set of scopes. Sume accepts a bearer API key in the Authorization header, so --auth bearer is the match for the key route (OAuth and API keys).

Amp remote MCP options, read 2026-10-02 from Amp's docs; the last column is the Sume value.
OptionWhat Amp's docs sayFor Sume
--auth oauthOAuth, detected automatically or set explicitlyNot covered by Sume's docs for Amp
--auth bearer --bearer-token-fileBearer token passed through a file, never as an argumentThe Sume API key in a file
--auth noneNo authenticationNot applicable; Sume requires auth
--personalScope for your own config; others are --workspace, --project, --current-project--personal
amp.mcpServersSettings key with url and optional headersThe hosted URL
check and removeVerify or delete a remote serverUse check after adding
umask 077
printf '%s' "$SUME_API_KEY" > ~/.config/sume-mcp-token
amp mcp remote add sume https://mcp.sume.com/mcp \
  --auth bearer \
  --bearer-token-file ~/.config/sume-mcp-token \
  --personal
amp mcp remote --personal check sume

Why a token file helps here

Sume's docs tell you to rotate an API key if it appears in logs or chat history. A command argument can end up in both shell history and process listings, and a file path cannot leak the value that way. Create the file with a restrictive mode, as the snippet does, and keep it out of any repository.

The check subcommand from Amp's page is a sensible first step. Then ask Amp to call Sume's mcp_health, which reports the endpoint, auth source and safety posture (MCP quickstart).

What the key unlocks

An API-key session sees the full hosted tool set, including paid generation. Paid and write tools need an idempotency_key; dry_run=true previews the cost; max_spend_usd is enforced only when provided (MCP tools and gates).

The Amp page I read does not describe a per-tool filter, so I will not claim one. If you need a read-only session, the route in Sume's docs is OAuth with mcp:read only, and I have not verified that Amp completes it. Otherwise keep the instruction explicit: run tools_schema and dry_run before spending, and read results with jobs_status rather than resubmitting.

Two cautions

After connecting, a jobs_wait call can hold for up to 55 seconds, so watch for client timeouts on long video jobs (Jobs and results).

  • Amp's docs example for a hosted server uses an SSE-style path; Sume's endpoint is the streamable HTTP URL in the table, so do not swap it for another path.
  • If check reports a failure, re-read the token file for a trailing newline or empty content before suspecting the endpoint.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume