ChatGPT desktop app and Codex share one MCP config: add Sume

OpenAI says the ChatGPT desktop app, Codex CLI and IDE extension share one config.toml. Add Sume once with a url, plus the 60 second tool timeout to check.

5 min readSume
All posts

Add Sume once to ~/.codex/config.toml and the ChatGPT desktop app, Codex CLI and IDE extension all pick it up. OpenAI's MCP page says so in one line: "The ChatGPT desktop app, Codex CLI, and IDE extension share this configuration." For Sume that means one url entry, one codex mcp login, and a tool timeout you check against Sume's 55-second wait.

Where does the shared config live?

The page (read 2026-10-03) says the file is by default ~/.codex/config.toml, and that you can scope servers to a project with .codex/config.toml. A streamable HTTP server takes url (required) plus optional bearer_token_env_var, http_headers and env_http_headers.

What does the Sume entry look like?

Use the production endpoint from the MCP overview. For OAuth, you only need the URL; the client discovers the rest from Sume's protected-resource metadata.

  • The login command is on the vendor page: "Run codex mcp login <server-name> separately to start an MCP OAuth login".
  • For an API key instead, use bearer_token_env_var with the name of an environment variable that holds the key. Do not paste the key into the file.
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
tool_timeout_sec = 90

# Then, once, in a terminal:
#   codex mcp login sume

Which timeout should I set?

The page lists startup_timeout_sec default 10 seconds and tool_timeout_sec default 60 seconds. Sume's jobs_wait holds a slice for up to 55 seconds on the remote server (default 50), which sits close to the 60-second default once network time is added. Raising tool_timeout_sec gives the slice room to return normally instead of timing out on the client.

Timeouts that meet in one jobs_wait call (read 2026-10-03)
SettingValueSource
Codex startup_timeout_sec10 s defaultOpenAI MCP page
Codex tool_timeout_sec60 s defaultOpenAI MCP page
Sume jobs_wait remote default50 spackages/mcp-server jobs-wait.ts
Sume jobs_wait remote maximum slice55 spackages/mcp-server jobs-wait.ts

How do I keep paid tools behind a prompt?

The same page documents enabled_tools (an allow list) and disabled_tools (applied after it). A read-only list is a quick way to try Sume with no spend risk; on Sume's side, an OAuth grant without Write already hides paid tools. Neither setting changes the idempotency_key Sume requires on write and paid calls.

A timed-out jobs_wait is not a failed job. Repeat the wait on the same job id rather than submitting the create again; see tools and gates.

What changed recently in Codex that touches MCP?

The Codex changelog page (read 2026-10-03) lists three recent CLI releases. Version 0.158.0 (2026-09-28) added support for MCP servers that require pre-registered OAuth client secrets. Sume's hosted OAuth does not need one: it is a public client flow with PKCE, so you leave any client-secret option empty.

Version 0.159.0 (2026-09-29) added an opt-in instant_interrupt that lets new input steer Codex during model responses. Version 0.160.0 (2026-10-01) lists caching of parsed plugin manifests and a clarification of how provider credentials use the configured storage backend. None of those entries is specific to Sume, and none changes the config shape above.

Since the file is shared, a mistake in it shows up in every surface at once. Edit it with the app closed, then run codex mcp login sume, and ask for tools_list in whichever surface you use first. If the call lists tools, the others will too.

What should I check if one surface sees Sume and another does not?

Since the page says the three surfaces share one configuration, a difference usually comes from scope, not from a separate setup. A project-level .codex/config.toml only applies in that project, while ~/.codex/config.toml applies everywhere. Check which file holds the entry, and whether the app was opened on the project you think it was.

Then compare sign-in state. The login is per server name, so run codex mcp login sume once and confirm in the surface that failed. If tools list but a paid call is refused, the OAuth grant is read-only; Sume's consent page has a Write toggle that is off by default, and re-running the login is how you turn it on.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume