AgentCore Gateway Sume MCP target: pick authorization code or API key

AgentCore Gateway offers three OAuth grant types for an MCP target. Sume's hosted MCP issues only the authorization code grant, so the choices narrow to two.

4 min readSume
All posts

When you add Sume's hosted MCP server (https://mcp.sume.com/mcp) as an Amazon Bedrock AgentCore Gateway target, two outbound authorization choices fit: OAuth with the authorization code grant, or an API key. The client credentials grant does not, because Sume's authorization server issues the authorization_code grant only. AWS's documentation, read on 2026-10-04, offers five modes for MCP targets, and this post narrows them for Sume.

What can AgentCore send outbound?

The AgentCore Gateway MCP targets page lists outbound authorization as none, OAuth (client credentials, authorization code, or token exchange), IAM with SigV4 signing, or an API key. It also requires the target server to declare tool capabilities, and Sume's server does: it advertises tools in its initialize result.

Which of those fit Sume?

AWS options from the AgentCore Gateway MCP targets page; Sume values from the OAuth docs and mcp-oauth package, read 2026-10-04.
AgentCore optionFits Sume?Why
No authorizationnothe hosted endpoint answers with an OAuth challenge
OAuth client credentialsnogrant_types_supported is authorization_code only
OAuth authorization codeyesPKCE S256, public client, mcp:read or mcp:write
OAuth token exchangenono such grant on the Sume server
IAM SigV4nonot an auth mode in Sume's docs
API keyyesAuthorization: Bearer or x-api-key

What does the authorization code route cost?

A person has to consent. AWS's page says the three-legged authorization URL and session URI are valid for 10 minutes, so the sign-in has to be completed inside that window. Sume's consent page shows Read locked on and Write off by default. Tokens last 3600 seconds, and the server ignores a refresh_token request, per the MCP OAuth and API keys page, so plan for another sign-in after an hour.

When should I use the API key?

For unattended agents. A key gives the full tool set, so choose which tools you register rather than relying on the scope to hide them, and require idempotency_key on every write and paid call, as MCP tools and gates states. Use dry_run=true before an expensive burst.

Pick the key for an overnight pipeline and the authorization code for a person-in-the-loop assistant. Do not mix them in one target. The MCP overview shows both setups.

What is the checklist?

Confirm the target URL is https://mcp.sume.com/mcp, pick one of the two fitting auth modes, register only the tools the agent needs, and synchronize before the first call. Then test one read call, such as mcp_health, before a paid create. For the paid create, send an idempotency_key and a max_spend_usd so the first live call has a ceiling, and read the result with jobs_wait and jobs_result.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume