Claude Code: same MCP name in two scopes, one Sume entry, no merge

If a Sume server is defined in local and project scope, Claude Code loads one definition whole and warns. Order, no field merge, and which tools you get.

4 min readSume
All posts

When the same server name exists in more than one Claude Code scope, Claude Code connects once, using the highest-precedence definition, and uses that entire entry. Fields are not merged. So a local-scope sume entry with an API-key header replaces a teammate's project sume entry that relies on OAuth, and the tools you see follow the credential in the entry that won.

Source: Connect Claude Code to tools via MCP, read 2026-10-02, with Sume's MCP OAuth and API keys and tools and gates.

Which scope wins?

The page orders sources: local scope, project scope, user scope, plugin-provided servers, then claude.ai connectors. Duplicates across the three scopes are matched by name; plugins and connectors are matched by endpoint. A server your organization provides through the managedMcpServers managed setting ranks above all of these on Claude Code v2.1.259 or later.

Precedence from Claude Code's MCP page, read 2026-10-02, with a Sume example.
OrderSourceExample for Sume
1Local scopeYour private entry with a key header
2Project scope (.mcp.json)The team entry with no secret
3User scopeA personal OAuth entry
4Plugin-provided serversA bundled entry, matched by endpoint
5claude.ai connectorsA connector pointing at the same URL

What does Claude Code warn about?

The page says that if you define the same name in more than one scope with different endpoints, Claude Code warns in claude mcp list output and in /mcp, quoting each scope's endpoint as written. It stores OAuth sign-ins per endpoint, so signing in to the definition that loads in one project does not sign you in where a different definition loads. Keep the endpoint you want and remove the others with claude mcp remove <name> --scope <scope>.

How does this change what Sume tools I get?

Sume's docs say an OAuth session gets mcp:read and read-only tools, with mcp:write opt-in at consent, while an API-key session gets the full hosted tool set. If the winning entry has a key, you may see paid tools you did not expect from the team file. If it is OAuth, expect only the read set unless Write was granted.

After any scope change, call mcp_health and confirm authenticated.auth_source; Sume's docs say mcp_oauth means an OAuth session. Then call tools_list to see which set you hold.

When do two spellings of the URL count as one?

Two URL spellings count as the same endpoint when they differ only in the letter case of the scheme or host, the scheme's default port such as :443 on https, or a trailing slash. A different path, query string, userinfo or non-default port makes two servers. That matters for duplicates between a plugin or connector and your own entry. Use the exact URL, https://mcp.sume.com/mcp, in every scope, so duplicates collapse instead of becoming two servers.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume