Can I put my Sume API key in the MCP server URL? No, use a header

Do not put a Sume key in the MCP URL. The MCP auth spec bans tokens in the query string. Send a Bearer or x-api-key header, or use OAuth, in each client.

4 min readSume
All posts

No. Do not put a Sume API key in the MCP server URL. The MCP authorization spec says access tokens must not be in the URI query string and that authorization must be sent on every request, so the right place for the key is a request header. Sume accepts Authorization: Bearer $SUME_API_KEY or x-api-key on the hosted server at https://mcp.sume.com/mcp, and OAuth is available for clients that support it.

Why the URL stays clean

A URL with a secret in it ends up in shell history, process lists, proxy logs, screenshots and shared config files. The MCP spec closes this off for token-based auth: the 2025-06-18 authorization page requires the Authorization header on every request and forbids tokens in the query string. Your Sume URL stays public: https://mcp.sume.com/mcp.

Where each client takes the key

Every major client has a header field for this. The table lists where each one takes it, from each vendor's own page.

Header fields for a remote MCP key, per vendor docs (read 2026-10-05)
ClientWhere the key goesNotes
Claude Code--header "Authorization: Bearer ..." on claude mcp addOr use OAuth with claude mcp login
Cursorheaders in mcp.json, with ${env:VAR} interpolationKeeps the key out of the file
Codexbearer_token_env_var or http_headers in configReads the token from an environment variable

OAuth or a key

For a coding agent on your laptop, OAuth is the cleaner path. claude mcp add --transport http sume https://mcp.sume.com/mcp and claude mcp login sume give a read-only session by default, and mcp:write is an opt-in at the consent screen, which unlocks the tools that change state or cost money. For CI, where nobody can click a consent page, a key in an environment variable is the usual choice.

Add it with a header

The two commands below add the server to Claude Code with the key in a header from an environment variable, so the URL carries nothing secret. Run them in a shell where SUME_API_KEY is set, and use claude mcp list to see the entry.

claude mcp add --transport http sume https://mcp.sume.com/mcp \
  --header "Authorization: Bearer $SUME_API_KEY"
claude mcp list

A note on shell expansion

Keep one thing in mind with the shell form. The shell expands $SUME_API_KEY when you run the command, so the key is stored in Claude Code's config for that scope. If that is not acceptable, use OAuth, or a client that reads an environment variable at connect time, like Codex with bearer_token_env_var.

One more place to check

The same rule applies to webhooks and callbacks. If a URL you give to any service has a secret in the query string, rotate it, because it has already been logged somewhere.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume