Claude Code --bare and MCP: name the Sume server with a key

Claude Code --bare connects only MCP servers named on the command line. To use Sume there, name the server with an API-key header; no browser sign-in needed.

4 min readSume
All posts

In a --bare run, Claude Code connects only the MCP servers named on the command line, so a Sume server configured elsewhere is not loaded. Name it there with an API-key header, since an unattended run cannot do a browser sign-in.

The Claude Code changelog, read 2026-09-30, lists version 2.1.286 as changing --bare to connect only the named MCP servers, send the model no system reminders, and start no background tasks.

Which Sume endpoint and header do I name?

The hosted endpoint is https://mcp.sume.com/mcp. The OAuth and API key page gives two header forms for an API key. Check Claude Code's own docs for the exact flag syntax; this post does not cover it.

Sume remote MCP API-key headers, read 2026-09-30.
FormHeader
BearerAuthorization: Bearer $SUME_API_KEY
Key headerx-api-key: $SUME_API_KEY

Why an API key and not OAuth?

The docs call API-key remote MCP the other path for automation that does not speak OAuth. A CI job has no browser, so read the key from a secret store into SUME_API_KEY and keep it out of the committed command.

What can the run see and do?

API-key sessions can see write and paid tools. Execution still requires idempotency_key on mutating and paid calls, dry_run=true or generation_admission_preview is preferred before the first paid submit, and max_spend_usd caps spend only when you pass it. For an unattended job, pass the cap. More on header setup in Claude Code MCP headers helper with a Sume API key.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume