MCP error text showed a Bearer token: rotate the Sume API key
Claude Code 2.1.286 masks credentials after Bearer or Basic in MCP errors. If an old log shows a Sume key, replace it and keep keys out of logs.

If an MCP error message in a Claude Code session or log showed a Sume API key, treat the key as exposed and replace it. Claude Code 2.1.286 fixed two masking bugs: error messages that showed a credential's value when "Bearer" or "Basic" came before its key name, and percent-encoded Bearer tokens that were only partly masked (Claude Code changelog, read 2026-10-04). The fix stops new leaks; it does not clean logs you already saved.
What to look for
Search saved transcripts, CI logs and bug reports from before the update for the Authorization header form. A Sume API key can be sent as Authorization: Bearer <key> or as x-api-key, so search for both.
- Terminal scrollback or CI output from a failed MCP call.
- Debug logs and exported transcripts attached to tickets.
- Shared screenshots of an error banner.
How to rotate on Sume
Create a new key at the API Keys page in the dashboard and move every client to it. Sume's docs describe this for older keys that lack new scopes: scopes cannot be added to an existing key, so you create a new one and rotate to it (Agent Completions). The same move replaces an exposed key.
| Place the key is used | After a suspected leak |
|---|---|
| MCP client header (Bearer or x-api-key) | Update to the new key, then reconnect |
| CI secret store | Replace the secret value, not the variable name |
| Shell profile or env file | Replace it, and check it is not committed |
| Webhook receiver | The signing secret is separate; rotate it only if it was shown |
Keep keys out of logs from now on
Sume's safe-automation guidance lists what logs should hold: request ids, job ids when needed, high-level status and sanitized media metadata. It lists as unsafe API keys, signed URLs, raw private media URLs and excessive user content (Safe automation).
Prefer OAuth for interactive clients, so no long-lived key is in a header at all. For automation, read the key from an environment variable that your runner masks, and never echo the request headers.
Check what the old key could do
An API key to the hosted MCP gets the full tool set, including paid tools. After replacing it, look at recent usage and jobs for calls you did not make, and keep a spend ceiling in your prompts with max_spend_usd, since that cap is enforced only when you send it.
Sources
Related posts
More in Developers
- Claude Code scope re-authenticate prompt vs unattended Sume runs
Claude Code 2.1.288 prompts to re-authenticate when a server asks for more OAuth scope. Unattended runs cannot answer it, so grant write up front.
- Claude Code 2.1.289 plugin loading fix: recheck Sume MCP after upgrade
Claude Code 2.1.289 fixed plugin loading after an upgrade. A four-call read-only check confirms the Sume MCP connection and scopes before you run a paid job.
- Claude Code's 60 s MCP timeout: Sume sync waits 30 s, video polls
Claude Code 2.1.287 caps MCP tool calls at 60 seconds per server. Sume's 30 s sync wait and 55 s jobs_wait fit under it; a video render needs repeated waits.
- Claude Code MCP startup wait: Sume tools missing on the first -p turn
Headless Claude Code bounds how long turn one waits for MCP servers with CLAUDE_CODE_MCP_STARTUP_WAIT_MS. Name Sume tools and check mcp_health first.
Written by Sume