Claude Code MCP scope: local, project or user for the Sume server

Use project scope for a shared .mcp.json with the Sume URL only, user scope for your own machine, and keep API keys out of shared files.

4 min readSume
All posts

Put Sume in project scope if the whole repo should offer it, and user scope if it is only for you. With OAuth, the shared file holds only the URL https://mcp.sume.com/mcp, so nothing secret goes into version control. Each person then signs in with claude mcp login sume.

The three scopes

The Claude Code docs describe three places a server can live. Local, the default, is the current project only and private to you. Project is shared through .mcp.json in version control. User is available across all your projects.

Claude Code MCP scopes, read 2026-10-07
ScopeWhere it appliesGood fit for Sume
local (default)This project, only youTrying Sume in one repo
projectEveryone who clones the repoA team that always wants Sume tools
userAll your projectsYour own media work across repos

Project scope without a secret

Run the add command with the scope flag, then sign in. The file in the repo contains the server name, transport and URL.

Because Sume's hosted OAuth gives mcp:read by default, a teammate who signs in and does nothing else gets read-only tools. They opt into mcp:write themselves at the consent page, which lives on the MCP host, not on app.sume.com.

claude mcp add --transport http sume --scope project https://mcp.sume.com/mcp
claude mcp login sume

Where an API key does not belong

The vendor page shows --header "Authorization: Bearer ..." for servers that use tokens. Sume accepts a Bearer or x-api-key header, and an API-key session sees every tool, including paid ones. That is exactly why you should not put one in a shared .mcp.json. If a key ever lands in a repo or chat log, rotate it, as the Sume docs advise.

For CI, use a key from a secret store in a user or local config on the runner, not a committed file.

What this does not do

A project entry does not sign anyone in or grant anyone write access. It also does not pin a tool list: after connecting, call tools_list to see what that person's session can use.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume