ChatGPT Plugins: Public endpoint or Secure MCP Tunnel for Sume?

Sume's MCP server is already public at mcp.sume.com/mcp, so pick Public endpoint in ChatGPT. The Secure MCP Tunnel is for servers that are not exposed.

4 min readSume
All posts

Choose Public endpoint and enter https://mcp.sume.com/mcp. The Secure MCP Tunnel option exists for servers you cannot expose to the internet, which does not describe Sume's hosted MCP.

OpenAI's connect page puts developer mode under Settings, Security and login. After turning it on you open the ChatGPT Plugins page, add a new one, give it a name and description, and choose how ChatGPT reaches the server.

The two connection modes

The page offers a public endpoint, entered as a URL ending in the /mcp path, or a Secure MCP Tunnel identified by a tunnel_id. Here is how each fits Sume.

ChatGPT connection modes and Sume (read 2026-10-03)
ModeWhat you enterFits Sume when
Public endpointThe server URL with the /mcp pathAlways for the hosted server: https://mcp.sume.com/mcp
Secure MCP TunnelA tunnel_idOnly for a private server of your own that Sume does not host

What happens at sign-in

Sume's hosted MCP supports OAuth for browser clients. The client is a public client using PKCE with the S256 method, and the consent page on the MCP host asks for mcp:read, with mcp:write as an opt-in. Read-only access lets ChatGPT list tools, check balance and read jobs. Granting write exposes the tools that create paid renders. Details are on the OAuth page.

Access tokens last 60 minutes and there is no refresh token, so a long ChatGPT session may ask you to sign in again. Jobs started before that point keep running on Sume, and you can read them after reconnecting.

After connecting

Ask for something harmless first: the account, then the balance. Then ask for a dry run of an image so you see the price before spending. For long renders, the agent should wait with jobs_wait and call it again with the same job id when a slice expires, instead of creating the job again.

If you are choosing between ChatGPT and other hosts, the client credential comparison shows which can send an API key. The basic walkthrough is in add an MCP server to ChatGPT.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume