Claude Code MCP scope: local, project or user for the Sume server
Use project scope for a shared .mcp.json with the Sume URL only, user scope for your own machine, and keep API keys out of shared files.

Put Sume in project scope if the whole repo should offer it, and user scope if it is only for you. With OAuth, the shared file holds only the URL https://mcp.sume.com/mcp, so nothing secret goes into version control. Each person then signs in with claude mcp login sume.
The three scopes
The Claude Code docs describe three places a server can live. Local, the default, is the current project only and private to you. Project is shared through .mcp.json in version control. User is available across all your projects.
| Scope | Where it applies | Good fit for Sume |
|---|---|---|
| local (default) | This project, only you | Trying Sume in one repo |
| project | Everyone who clones the repo | A team that always wants Sume tools |
| user | All your projects | Your own media work across repos |
Project scope without a secret
Run the add command with the scope flag, then sign in. The file in the repo contains the server name, transport and URL.
Because Sume's hosted OAuth gives mcp:read by default, a teammate who signs in and does nothing else gets read-only tools. They opt into mcp:write themselves at the consent page, which lives on the MCP host, not on app.sume.com.
claude mcp add --transport http sume --scope project https://mcp.sume.com/mcp
claude mcp login sumeWhere an API key does not belong
The vendor page shows --header "Authorization: Bearer ..." for servers that use tokens. Sume accepts a Bearer or x-api-key header, and an API-key session sees every tool, including paid ones. That is exactly why you should not put one in a shared .mcp.json. If a key ever lands in a repo or chat log, rotate it, as the Sume docs advise.
For CI, use a key from a secret store in a user or local config on the runner, not a committed file.
What this does not do
A project entry does not sign anyone in or grant anyone write access. It also does not pin a tool list: after connecting, call tools_list to see what that person's session can use.
Sources
Related posts
More in Developers
- Codex 0.160.0 MCP status for one server: confirm Sume with mcp_health
Codex 0.160.0 adds single-server MCP status discovery with thread connection reuse. Confirm the Sume session itself with mcp_health and tools_list.
- Codex 0.160.1 remote stdio MCP fix: does it affect Sume?
Codex 0.160.1 preserves SYSTEMROOT, TEMP and TMP for remote stdio MCP launches on Windows hosts. Sume's hosted MCP is HTTP, so no process is launched.
- communication.webhook_url 400: HTTPS, public host, 2048 chars
A communication.webhook_url that is not public HTTPS, is over 2048 characters, or points at localhost or a private network returns 400 invalid_request.
- How long do 100 AI video clips take? Concurrency slots by plan
100 jobs take ceil(100 / slots) waves: 100 on Free, 25 on Pro, 13 on Startup, 5 on Scale. Multiply by one job's time. Math and a runnable snippet.
Written by Sume