claude mcp add --header Bearer: a Sume API key for CI runs
For unattended Claude Code runs, pass a Sume API key as a Bearer header. That session sees every tool, so cap spend and send idempotency keys.

Claude Code adds a remote server with a token using claude mcp add --transport http <name> <url> --header "Authorization: Bearer ...". Sume accepts Authorization: Bearer <SUME_API_KEY> or an x-api-key header on https://mcp.sume.com/mcp. The catch is that an API-key session sees the full hosted tool set, write and paid tools included, so a CI job needs its own guardrails.
The command
Let the shell expand the key from your secret store so the literal never appears in the script:
claude mcp add --transport http sume https://mcp.sume.com/mcp \
--header "Authorization: Bearer $SUME_API_KEY"
claude mcp listWhat an API-key session can do
OAuth sessions are read-only unless the person grants mcp:write. API-key sessions skip that consent step. Writes and paid calls must still carry an idempotency_key, which is a dedup key and not an approval.
The spend limits are weaker than people expect. max_spend_usd on an MCP call is enforced only if you send it, and dry_run or generation_admission_preview only preview cost. Nothing on hosted MCP forces a cap.
When to use a different surface
If the CI job is really "run this task and give me the output", an Agent Completion has a required generation_spend_cap_usd with no default, so the call fails without a cap. It is asynchronous: you get a 202 receipt and poll it. Use MCP when an interactive agent needs to choose among tools, and Agent Completions when a backend just wants a result.
| Question | Hosted MCP with API key | Agent Completion |
|---|---|---|
| Spend cap | Optional max_spend_usd | Required generation_spend_cap_usd |
| Retry safety | idempotency_key on writes | Idempotency-Key header |
| Result | Tool results in the session | Poll the run receipt |
| Streaming | Per MCP client | Not available |
Sources
Related posts
More in Developers
- Claude Code MCP scope: local, project or user for the Sume server
Use project scope for a shared .mcp.json with the Sume URL only, user scope for your own machine, and keep API keys out of shared files.
- Codex 0.160.0 MCP status for one server: confirm Sume with mcp_health
Codex 0.160.0 adds single-server MCP status discovery with thread connection reuse. Confirm the Sume session itself with mcp_health and tools_list.
- Codex 0.160.1 remote stdio MCP fix: does it affect Sume?
Codex 0.160.1 preserves SYSTEMROOT, TEMP and TMP for remote stdio MCP launches on Windows hosts. Sume's hosted MCP is HTTP, so no process is launched.
- communication.webhook_url 400: HTTPS, public host, 2048 chars
A communication.webhook_url that is not public HTTPS, is over 2048 characters, or points at localhost or a private network returns 400 invalid_request.
Written by Sume