Chatbox MCP one-click install link for Sume (base64 deep link)
Chatbox documents a chatbox://mcp/install deep link carrying a base64 server config. Build one for Sume's hosted MCP URL and know what the page leaves out.

The answer
Chatbox's MCP guide says a website can launch Chatbox and configure an MCP service with a deep link in the form chatbox://mcp/install?server=$BASE64_ENCODED_CONFIG. The config is JSON, stringified and base64 encoded. For a remote server the page's example has just a name and a url, so the Sume link carries https://mcp.sume.com/mcp.
What the page does not show is any field for headers or OAuth settings. Sume's hosted MCP needs either OAuth or an API key, so the deep link gets the server into Chatbox and the sign-in step is something to check in the app itself rather than something the link can carry.
What Chatbox documents
The guide says Chatbox version 1.14 introduced MCP support, that you add a server under Settings, MCP with Add Server (or pick a built-in one), and that the deep link works the same way for a local command or a remote URL.
| Item | Chatbox page | Sume |
|---|---|---|
| Link scheme | chatbox://mcp/install?server=... | Not applicable |
| Config encoding | JSON.stringify, then base64 | Not applicable |
| Remote server example | name and url fields | url is https://mcp.sume.com/mcp |
| Authentication | Not shown on the page | OAuth mcp:read / mcp:write, or an API key |
Generate the link
This Node script builds the link. Run it with node make-link.mjs and open the printed URL on a machine that has Chatbox installed. The name sume is your choice; it is what the app will list.
const config = {
name: "sume",
url: "https://mcp.sume.com/mcp",
};
const encoded = Buffer.from(JSON.stringify(config)).toString("base64");
console.log(`chatbox://mcp/install?server=${encoded}`);Before you publish the link
Check three things in the app after the install. First, whether Chatbox starts a sign-in when the server challenges it; Sume's OAuth docs describe the challenge and the protected-resource metadata the client follows. Second, which tools appear: under OAuth with only mcp:read you see read-only tools, and the write and paid tools appear only with mcp:write or an API key.
Third, remember the gates. Write and paid tools require an idempotency_key, and spend is wallet and admission, not a scope. A link that installs the server does not change any of that, so tell readers what the first sign-in will ask them to grant.
Where to put the link
A deep link only works on a machine where Chatbox is installed and registered for the chatbox:// scheme, so show it next to a normal fallback: the Settings, MCP, Add Server path from the same guide, with the URL typed by hand. On a docs page, a plain link labelled with the app name is enough; on a marketing page, say what the click will do before the user presses it.
Do not embed an API key in the link. The encoded config is trivially reversible (base64 is encoding, not encryption), and a link pasted into chat, a forum or a ticket carries whatever you put in it. Sume's hosted MCP supports OAuth, so the link does not need to carry any secret and the safe link carries only the URL.
If you want the link to land users in a read-only state, the choice is made at consent time: Sume's OAuth consent has a Write toggle, and without it the session sees read-only tools. That keeps a first click from ever reaching a paid tool.
Testing the round trip
Decode your own link before publishing it. In a shell, take the part after server= and run it through a base64 decoder; you should see exactly the two-field JSON you built. Then open the link on a clean profile, confirm the server shows up under Settings, MCP, and ask the app to list tools. If tool listing needs a sign-in, you have confirmed that the link alone does not authenticate anything, which is the behaviour Sume's hosted MCP expects.
Keep a short note of the Chatbox version you tested. The page says MCP arrived in version 1.14, and the deep link behaviour is documented on the current page, but a settings screen can move between releases.
Sources
Related posts
More in Integrations
- ChatGPT desktop app and Codex share one MCP config: add Sume
OpenAI says the ChatGPT desktop app, Codex CLI and IDE extension share one config.toml. Add Sume once with a url, plus the 60 second tool timeout to check.
- Claude allowedPluginMcpServers and denied list for Sume URL
Claude admins can allow or deny plugin MCP servers by URL pattern. How to allow mcp.sume.com/mcp and what a deny match does even when allowed.
- Claude Code Elicitation hook block: does Sume ever elicit?
Claude Code 2.1.283 lets an Elicitation hook decline with decision block. Sume's hosted MCP server is tools-only, so it has no prompt to decline.
- Claude Code 2.1.288: MCP call ran twice on a 16 MB result
Claude Code 2.1.288 fixed MCP tool calls that ran twice when a result passed 16 MB or would not parse. Sume caps output at 256 KiB and keys paid calls.
Written by Sume