Chatbox MCP one-click install link for Sume (base64 deep link)

Chatbox documents a chatbox://mcp/install deep link carrying a base64 server config. Build one for Sume's hosted MCP URL and know what the page leaves out.

5 min readSume
All posts

The answer

Chatbox's MCP guide says a website can launch Chatbox and configure an MCP service with a deep link in the form chatbox://mcp/install?server=$BASE64_ENCODED_CONFIG. The config is JSON, stringified and base64 encoded. For a remote server the page's example has just a name and a url, so the Sume link carries https://mcp.sume.com/mcp.

What the page does not show is any field for headers or OAuth settings. Sume's hosted MCP needs either OAuth or an API key, so the deep link gets the server into Chatbox and the sign-in step is something to check in the app itself rather than something the link can carry.

What Chatbox documents

The guide says Chatbox version 1.14 introduced MCP support, that you add a server under Settings, MCP with Add Server (or pick a built-in one), and that the deep link works the same way for a local command or a remote URL.

Chatbox MCP install link against Sume's hosted server (read 2026-10-03)
ItemChatbox pageSume
Link schemechatbox://mcp/install?server=...Not applicable
Config encodingJSON.stringify, then base64Not applicable
Remote server examplename and url fieldsurl is https://mcp.sume.com/mcp
AuthenticationNot shown on the pageOAuth mcp:read / mcp:write, or an API key

Generate the link

This Node script builds the link. Run it with node make-link.mjs and open the printed URL on a machine that has Chatbox installed. The name sume is your choice; it is what the app will list.

const config = {
  name: "sume",
  url: "https://mcp.sume.com/mcp",
};

const encoded = Buffer.from(JSON.stringify(config)).toString("base64");
console.log(`chatbox://mcp/install?server=${encoded}`);

Before you publish the link

Check three things in the app after the install. First, whether Chatbox starts a sign-in when the server challenges it; Sume's OAuth docs describe the challenge and the protected-resource metadata the client follows. Second, which tools appear: under OAuth with only mcp:read you see read-only tools, and the write and paid tools appear only with mcp:write or an API key.

Third, remember the gates. Write and paid tools require an idempotency_key, and spend is wallet and admission, not a scope. A link that installs the server does not change any of that, so tell readers what the first sign-in will ask them to grant.

Where to put the link

A deep link only works on a machine where Chatbox is installed and registered for the chatbox:// scheme, so show it next to a normal fallback: the Settings, MCP, Add Server path from the same guide, with the URL typed by hand. On a docs page, a plain link labelled with the app name is enough; on a marketing page, say what the click will do before the user presses it.

Do not embed an API key in the link. The encoded config is trivially reversible (base64 is encoding, not encryption), and a link pasted into chat, a forum or a ticket carries whatever you put in it. Sume's hosted MCP supports OAuth, so the link does not need to carry any secret and the safe link carries only the URL.

If you want the link to land users in a read-only state, the choice is made at consent time: Sume's OAuth consent has a Write toggle, and without it the session sees read-only tools. That keeps a first click from ever reaching a paid tool.

Testing the round trip

Decode your own link before publishing it. In a shell, take the part after server= and run it through a base64 decoder; you should see exactly the two-field JSON you built. Then open the link on a clean profile, confirm the server shows up under Settings, MCP, and ask the app to list tools. If tool listing needs a sign-in, you have confirmed that the link alone does not authenticate anything, which is the behaviour Sume's hosted MCP expects.

Keep a short note of the Chatbox version you tested. The page says MCP arrived in version 1.14, and the deep link behaviour is documented on the current page, but a settings screen can move between releases.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume