ChatGPT Plugins: Public endpoint or Secure MCP Tunnel for Sume?
Sume's MCP server is already public at mcp.sume.com/mcp, so pick Public endpoint in ChatGPT. The Secure MCP Tunnel is for servers that are not exposed.

Choose Public endpoint and enter https://mcp.sume.com/mcp. The Secure MCP Tunnel option exists for servers you cannot expose to the internet, which does not describe Sume's hosted MCP.
OpenAI's connect page puts developer mode under Settings, Security and login. After turning it on you open the ChatGPT Plugins page, add a new one, give it a name and description, and choose how ChatGPT reaches the server.
The two connection modes
The page offers a public endpoint, entered as a URL ending in the /mcp path, or a Secure MCP Tunnel identified by a tunnel_id. Here is how each fits Sume.
| Mode | What you enter | Fits Sume when |
|---|---|---|
| Public endpoint | The server URL with the /mcp path | Always for the hosted server: https://mcp.sume.com/mcp |
| Secure MCP Tunnel | A tunnel_id | Only for a private server of your own that Sume does not host |
What happens at sign-in
Sume's hosted MCP supports OAuth for browser clients. The client is a public client using PKCE with the S256 method, and the consent page on the MCP host asks for mcp:read, with mcp:write as an opt-in. Read-only access lets ChatGPT list tools, check balance and read jobs. Granting write exposes the tools that create paid renders. Details are on the OAuth page.
Access tokens last 60 minutes and there is no refresh token, so a long ChatGPT session may ask you to sign in again. Jobs started before that point keep running on Sume, and you can read them after reconnecting.
After connecting
Ask for something harmless first: the account, then the balance. Then ask for a dry run of an image so you see the price before spending. For long renders, the agent should wait with jobs_wait and call it again with the same job id when a slice expires, instead of creating the job again.
If you are choosing between ChatGPT and other hosts, the client credential comparison shows which can send an API key. The basic walkthrough is in add an MCP server to ChatGPT.
Sources
Related posts
More in Integrations
- Claude allowedPluginMcpServers and denied list for Sume URL
Claude admins can allow or deny plugin MCP servers by URL pattern. How to allow mcp.sume.com/mcp and what a deny match does even when allowed.
- Claude Code Elicitation hook block: does Sume ever elicit?
Claude Code 2.1.283 lets an Elicitation hook decline with decision block. Sume's hosted MCP server is tools-only, so it has no prompt to decline.
- Claude Code 2.1.288: MCP call ran twice on a 16 MB result
Claude Code 2.1.288 fixed MCP tool calls that ran twice when a result passed 16 MB or would not parse. Sume caps output at 256 KiB and keys paid calls.
- Claude Code 2.1.288 re-authenticate prompt: Sume's mcp:write
Claude Code 2.1.288 asks you to re-authenticate when an MCP server wants more OAuth scope mid-call. What that means for a read-only Sume grant.
Written by Sume