Claude Code .mcp.json: why ${ANTHROPIC_API_KEY} reads empty for Sume
Claude Code reads credential variables like ANTHROPIC_API_KEY and NPM_TOKEN as empty in a remote url or headers. Name your Sume key variable SUME_API_KEY.

If a ${...} reference in a remote server's url or headers names one of Claude Code's covered credential variables, it expands to an empty string, so Authorization: Bearer ${NPM_TOKEN} sent to Sume would carry no key. Claude Code's MCP page lists the covered names and says a name outside that set expands as written. Store the Sume key in a variable you name yourself, for example SUME_API_KEY.
Source: Connect Claude Code to tools via MCP, read 2026-10-02, together with Sume's MCP OAuth and API keys.
Which variables does Claude Code treat as credentials?
The page names three groups: Claude Code's own credentials such as ANTHROPIC_API_KEY and ANTHROPIC_AUTH_TOKEN; cloud provider credentials such as AWS_BEARER_TOKEN_BEDROCK; and other credentials your environment carries, such as HTTPS_PROXY and NPM_TOKEN. A covered name reads as empty whether or not you set it, and a :-default fallback on it is ignored. A provider base URL such as ANTHROPIC_BASE_URL still expands.
| Reference | What the page says | Result for Sume |
|---|---|---|
${SUME_API_KEY} | Name outside the covered set | Expands as written, key is sent |
${NPM_TOKEN} | Covered name, reads as empty | Bearer with no key |
${ANTHROPIC_API_KEY:-x} | Covered name, default ignored | Empty |
${ANTHROPIC_BASE_URL} | Base URLs still expand | Not relevant to Sume |
What does the Sume entry look like?
Sume accepts Authorization: Bearer <key> or x-api-key: <key> on hosted MCP. In .mcp.json, reference your own variable, so the file can be committed with no secret in it.
{
"mcpServers": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp",
"headers": {
"Authorization": "Bearer ${SUME_API_KEY}"
}
}
}
}How do I tell the value is empty?
The page says a server that receives Bearer with no credential rejects the request, usually with a 401, and Claude Code reports that as a failed connection. When a remote entry references a covered variable you have set, Claude Code names it in a debug-log line. Run claude --debug-file /tmp/claude-debug.log and search the file for never expanded toward a remote server.
What if my key already lives in a covered variable?
Copy it into a name of your own, as the page advises, and reference that name. Do not reuse ANTHROPIC_API_KEY for a Sume key: they are different credentials. Create Sume keys in the dashboard and keep one per environment.
Sources
Related posts
More in Integrations
- Claude Code: same MCP name in two scopes, one Sume entry, no merge
If a Sume server is defined in local and project scope, Claude Code loads one definition whole and warns. Order, no field merge, and which tools you get.
- claude -p loads project .mcp.json with no approval: Sume paid tools
In claude -p, Agent SDK and cloud sessions, Claude Code loads .mcp.json servers without asking. What that means for a committed Sume entry, and how to block it.
- Claude connector sign-in now, when needed or none: pick for Sume
For Sume's hosted MCP, pick Sign in now with OAuth, or add one auth header for an API key. No sign in fails, because the server needs a credential.
- Claude Desktop: add Sume's hosted MCP as a custom connector
Claude Desktop adds a remote MCP server through Customize > Connectors, not claude_desktop_config.json. Paste Sume's URL, sign in, and call tools_list.
Written by Sume