Claude Code plugin .mcp.json: bundle a Sume MCP server
Put Sume's hosted MCP server in a Claude Code plugin's .mcp.json, prompt each teammate for their own API key, and install it from a team marketplace.

To bundle a remote MCP server in a Claude Code plugin, put a .mcp.json at the plugin root with an mcpServers object, then list the plugin in a marketplace and install it. For Sume the entry is an http server at https://mcp.sume.com/mcp with an Authorization: Bearer header. A userConfig field with sensitive: true lets each teammate enter their own API key instead of you committing one.
Plugin behavior is from Anthropic's plugins reference and marketplaces page, read 2026-09-29. The endpoint and header are from Sume's MCP OAuth and API keys page. Sume's docs do not list a Claude plugin or a Claude directory listing, so this is a plugin you write yourself around Sume's hosted MCP endpoint.
What goes in the plugin manifest?
The manifest lives at .claude-plugin/plugin.json. Only name is required. Anthropic's reference says a userConfig option with sensitive: true masks the input and stores the value in secure storage instead of settings.json, and that ${user_config.KEY} is substituted in MCP server config. Every other plugin file goes at the plugin root, not inside .claude-plugin/.
{
"name": "sume-media",
"description": "Sume video and image tools over hosted MCP",
"userConfig": {
"sume_api_key": {
"type": "string",
"title": "Sume API key",
"description": "Your own Sume API key. Never commit it.",
"sensitive": true
}
}
}What goes in .mcp.json?
Claude Code loads .mcp.json at the plugin root first. The url and headers of an http server accept the placeholder, and the API-key header is Authorization: Bearer <SUME_API_KEY> per Sume's docs.
{
"mcpServers": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp",
"headers": {
"Authorization": "Bearer ${user_config.sume_api_key}"
}
}
}
}How do teammates install it?
A marketplace is a directory or repository with a .claude-plugin/marketplace.json that lists plugins; name, owner and a plugins array are required, and each plugin entry needs a name and a source. Anthropic's walkthrough validates, adds and installs with these commands:
claude plugin validate ./my-marketplace
claude plugin marketplace add ./my-marketplace
claude plugin install sume-media@my-marketplace
claude plugin listWhere does each file go?
Anthropic's reference puts only the manifest inside .claude-plugin/. The rest sits at the plugin root, and a marketplace has its own manifest one level up.
| File | Location | Purpose |
|---|---|---|
plugin.json | .claude-plugin/ in the plugin | Name, description and userConfig prompts |
.mcp.json | Plugin root | The mcpServers object with the Sume http server |
marketplace.json | .claude-plugin/ in the marketplace | Lists plugins with a name and a source |
What changes for the tool names?
Tools from a plugin-bundled server are not called mcp__sume__generate_video. Anthropic's MCP page gives the form mcp__plugin_<plugin-name>_<server-name>__<tool-name>, so this one is mcp__plugin_sume-media_sume__generate_video. Permission rules, a skill's allowed-tools, a subagent's tools and hook matchers all need that scoped name. A matcher written against the bare server key never fires.
You add and remove a plugin's servers by installing or uninstalling the plugin, not with /mcp commands, though you can toggle the server off in /mcp.
Should the key be an API key or OAuth?
Sume accepts both. The MCP quickstart prefers the OAuth connector flow for interactive clients, and an API-key session sees the whole hosted tool set, while OAuth is read-only until Write is turned on at consent. The plugin route above uses a key. Give each teammate their own key. See API key vs OAuth for an MCP server.
Sources
Related posts
More in Integrations
- claude mcp login over SSH: sign in to Sume with no browser
On a machine with no browser, claude mcp login prints the sign-in URL. Open it on your laptop, then paste the redirect URL back. Sume's MCP works this way.
- claude mcp logout: how to sign out of a remote MCP server
Run claude mcp logout <name> or pick Clear authentication in /mcp to remove stored credentials. What that does for Sume's hosted MCP, and the hourly token.
- Claude Sonnet 5.5 MCP tools in Claude Code: add Sume video/image tools
Claude Code v2.1.284 made Sonnet 5.5 the default Sonnet. Add Sume's hosted MCP server in two commands and give that model video and image generation tools.
- Codex bearer_token_env_var: connect Sume MCP with an API key, no OAuth
Set url and bearer_token_env_var in Codex's config.toml so a Sume API key from the environment authenticates hosted MCP, with enabled_tools to shorten the list.
Written by Sume