Claude Code MCP error showed a Bearer token: rotate the Sume key

If an MCP error or log exposed a Sume Bearer value, rotate the API key. An OAuth token is not an API key. Report issues with the request id, not the key.

4 min readSume
All posts

If an MCP error message or log showed your Sume Bearer value, treat that key as exposed and rotate it. Sume's docs say to rotate API keys if they appear in logs or chat history.

The Claude Code changelog, read 2026-09-30, lists 2.1.286 fixes: MCP error messages showing a credential's value when "Bearer" or "Basic" came before its key name, and percent-encoded Bearer tokens being only partly masked. Updating Claude Code stops new leaks of that kind; it does not un-leak a value already in a log.

What do I rotate?

It depends on which credential was shown. Per MCP OAuth and API keys, an MCP OAuth token is not a Sume API key.

Credential handling from the Sume docs, read 2026-09-30.
Credential in the logWhat the docs say
Sume API keyRotate if it appears in logs or chat history; create keys in the dashboard
MCP OAuth tokenNot an API key; do not store in CLI config, paste into prompts, or forward

How do I rotate and clean up?

Create a replacement key in the dashboard, switch your Claude Code MCP header or secret to it, then revoke the old one. Search the places the error could have landed, such as CI logs, terminal scrollback and pasted chat, and redact them. Step-by-step help is in exposed API key: what to do.

What do I send when I report the error?

Send the Sume request id, which is in the response body and headers. The errors docs say not to include API keys, signed URLs, raw media URLs, or private workspace and user ids.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume