Claude Code MCP whitespace warning: a pasted Sume key with a newline
Claude Code warns when an MCP header or url has leading or trailing whitespace, often a pasted token with a newline. It does not trim it. Fix a Sume entry.

If claude mcp list or /mcp shows "Leading or trailing whitespace in: headers.Authorization" for your Sume entry, the pasted API key carries a hidden space or newline, and Claude Code sends it exactly as written. The fix is to re-add the entry with a clean value. Claude Code's MCP page says it warns about this and does not trim the value.
Source: Connect Claude Code to tools via MCP, read 2026-10-02; the Sume side is from MCP OAuth and API keys.
What exactly does Claude Code check?
The page says Claude Code warns when an MCP config value carries hidden leading or trailing whitespace, which often comes from pasting a token with a trailing newline. It checks command, url, each args entry, and the values and key names under env and headers. The warning names the affected fields without echoing their values, and appears in claude mcp list output and in /mcp.
| Field | Checked | In a Sume entry |
|---|---|---|
url | Yes | https://mcp.sume.com/mcp |
headers values | Yes | Authorization: Bearer <key> or x-api-key: <key> |
headers key names | Yes | Authorization or x-api-key |
env and args | Yes | Used by stdio servers; Sume's hosted MCP is remote |
Why does a stray newline matter for Sume?
Sume reads the key from either Authorization: Bearer <key> or x-api-key: <key>. A key with a trailing space or newline is a different string from the one in your dashboard. Claude Code uses the value exactly as written, so what you pasted is what is sent. If the connection then fails, check whitespace before you suspect the key. The page does not say how any particular server reacts to the extra character.
How do I fix it?
Remove the entry and add it again from a file instead of a paste. In a shell, command substitution drops trailing newlines, so reading the key from a file works where copy and paste may not.
claude mcp remove sume
claude mcp add --transport http sume https://mcp.sume.com/mcp \
--header "Authorization: Bearer $(cat ~/.config/sume/key)"
claude mcp listWhat else should I do after a bad paste?
Check the details, then decide whether the key needs replacing.
- Run
claude mcp get sume; for a failed connection the page says it shows anIssue:line with the HTTP status or error code, with credential-like text redacted. - If the key was echoed into chat or a log, create a new one in the dashboard and revoke the old one.
- For interactive use,
claude mcp login sumeruns OAuth from the shell, so you paste no secret; the default grant ismcp:read.
Sources
Related posts
More in Integrations
- Claude Code .mcp.json: why ${ANTHROPIC_API_KEY} reads empty for Sume
Claude Code reads credential variables like ANTHROPIC_API_KEY and NPM_TOKEN as empty in a remote url or headers. Name your Sume key variable SUME_API_KEY.
- Claude Code: same MCP name in two scopes, one Sume entry, no merge
If a Sume server is defined in local and project scope, Claude Code loads one definition whole and warns. Order, no field merge, and which tools you get.
- claude -p loads project .mcp.json with no approval: Sume paid tools
In claude -p, Agent SDK and cloud sessions, Claude Code loads .mcp.json servers without asking. What that means for a committed Sume entry, and how to block it.
- Claude connector sign-in now, when needed or none: pick for Sume
For Sume's hosted MCP, pick Sign in now with OAuth, or add one auth header for an API key. No sign in fails, because the server needs a credential.
Written by Sume