ChatGPT desktop app and Codex share one MCP config: add Sume
OpenAI says the ChatGPT desktop app, Codex CLI and IDE extension share one config.toml. Add Sume once with a url, plus the 60 second tool timeout to check.

Add Sume once to ~/.codex/config.toml and the ChatGPT desktop app, Codex CLI and IDE extension all pick it up. OpenAI's MCP page says so in one line: "The ChatGPT desktop app, Codex CLI, and IDE extension share this configuration." For Sume that means one url entry, one codex mcp login, and a tool timeout you check against Sume's 55-second wait.
Where does the shared config live?
The page (read 2026-10-03) says the file is by default ~/.codex/config.toml, and that you can scope servers to a project with .codex/config.toml. A streamable HTTP server takes url (required) plus optional bearer_token_env_var, http_headers and env_http_headers.
What does the Sume entry look like?
Use the production endpoint from the MCP overview. For OAuth, you only need the URL; the client discovers the rest from Sume's protected-resource metadata.
- The login command is on the vendor page: "Run
codex mcp login <server-name>separately to start an MCP OAuth login". - For an API key instead, use
bearer_token_env_varwith the name of an environment variable that holds the key. Do not paste the key into the file.
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
tool_timeout_sec = 90
# Then, once, in a terminal:
# codex mcp login sumeWhich timeout should I set?
The page lists startup_timeout_sec default 10 seconds and tool_timeout_sec default 60 seconds. Sume's jobs_wait holds a slice for up to 55 seconds on the remote server (default 50), which sits close to the 60-second default once network time is added. Raising tool_timeout_sec gives the slice room to return normally instead of timing out on the client.
| Setting | Value | Source |
|---|---|---|
| Codex startup_timeout_sec | 10 s default | OpenAI MCP page |
| Codex tool_timeout_sec | 60 s default | OpenAI MCP page |
| Sume jobs_wait remote default | 50 s | packages/mcp-server jobs-wait.ts |
| Sume jobs_wait remote maximum slice | 55 s | packages/mcp-server jobs-wait.ts |
How do I keep paid tools behind a prompt?
The same page documents enabled_tools (an allow list) and disabled_tools (applied after it). A read-only list is a quick way to try Sume with no spend risk; on Sume's side, an OAuth grant without Write already hides paid tools. Neither setting changes the idempotency_key Sume requires on write and paid calls.
A timed-out jobs_wait is not a failed job. Repeat the wait on the same job id rather than submitting the create again; see tools and gates.
What changed recently in Codex that touches MCP?
The Codex changelog page (read 2026-10-03) lists three recent CLI releases. Version 0.158.0 (2026-09-28) added support for MCP servers that require pre-registered OAuth client secrets. Sume's hosted OAuth does not need one: it is a public client flow with PKCE, so you leave any client-secret option empty.
Version 0.159.0 (2026-09-29) added an opt-in instant_interrupt that lets new input steer Codex during model responses. Version 0.160.0 (2026-10-01) lists caching of parsed plugin manifests and a clarification of how provider credentials use the configured storage backend. None of those entries is specific to Sume, and none changes the config shape above.
Since the file is shared, a mistake in it shows up in every surface at once. Edit it with the app closed, then run codex mcp login sume, and ask for tools_list in whichever surface you use first. If the call lists tools, the others will too.
What should I check if one surface sees Sume and another does not?
Since the page says the three surfaces share one configuration, a difference usually comes from scope, not from a separate setup. A project-level .codex/config.toml only applies in that project, while ~/.codex/config.toml applies everywhere. Check which file holds the entry, and whether the app was opened on the project you think it was.
Then compare sign-in state. The login is per server name, so run codex mcp login sume once and confirm in the surface that failed. If tools list but a paid call is refused, the OAuth grant is read-only; Sume's consent page has a Write toggle that is off by default, and re-running the login is how you turn it on.
Sources
Related posts
More in Integrations
- Claude Code 2.1.288: MCP call ran twice on a 16 MB result
Claude Code 2.1.288 fixed MCP tool calls that ran twice when a result passed 16 MB or would not parse. Sume caps output at 256 KiB and keys paid calls.
- Claude Code 2.1.288 re-authenticate prompt: Sume's mcp:write
Claude Code 2.1.288 asks you to re-authenticate when an MCP server wants more OAuth scope mid-call. What that means for a read-only Sume grant.
- Claude Code URL prompts wait for "I'm done": does Sume send any?
Claude Code 2.1.288 now waits for I'm done, continue after an MCP URL prompt. Sume signs you in through OAuth, and its server has no elicitation code.
- claude mcp add-from-claude-desktop: will your Sume server import?
Claude Code can import Claude Desktop MCP servers on macOS and WSL, but only names with letters, digits, hyphens and underscores. Sume is named sume.
Written by Sume