Claude Code plugin .mcp.json: bundle a Sume MCP server

Put Sume's hosted MCP server in a Claude Code plugin's .mcp.json, prompt each teammate for their own API key, and install it from a team marketplace.

5 min readSume
All posts

To bundle a remote MCP server in a Claude Code plugin, put a .mcp.json at the plugin root with an mcpServers object, then list the plugin in a marketplace and install it. For Sume the entry is an http server at https://mcp.sume.com/mcp with an Authorization: Bearer header. A userConfig field with sensitive: true lets each teammate enter their own API key instead of you committing one.

Plugin behavior is from Anthropic's plugins reference and marketplaces page, read 2026-09-29. The endpoint and header are from Sume's MCP OAuth and API keys page. Sume's docs do not list a Claude plugin or a Claude directory listing, so this is a plugin you write yourself around Sume's hosted MCP endpoint.

What goes in the plugin manifest?

The manifest lives at .claude-plugin/plugin.json. Only name is required. Anthropic's reference says a userConfig option with sensitive: true masks the input and stores the value in secure storage instead of settings.json, and that ${user_config.KEY} is substituted in MCP server config. Every other plugin file goes at the plugin root, not inside .claude-plugin/.

{
  "name": "sume-media",
  "description": "Sume video and image tools over hosted MCP",
  "userConfig": {
    "sume_api_key": {
      "type": "string",
      "title": "Sume API key",
      "description": "Your own Sume API key. Never commit it.",
      "sensitive": true
    }
  }
}

What goes in .mcp.json?

Claude Code loads .mcp.json at the plugin root first. The url and headers of an http server accept the placeholder, and the API-key header is Authorization: Bearer <SUME_API_KEY> per Sume's docs.

{
  "mcpServers": {
    "sume": {
      "type": "http",
      "url": "https://mcp.sume.com/mcp",
      "headers": {
        "Authorization": "Bearer ${user_config.sume_api_key}"
      }
    }
  }
}

How do teammates install it?

A marketplace is a directory or repository with a .claude-plugin/marketplace.json that lists plugins; name, owner and a plugins array are required, and each plugin entry needs a name and a source. Anthropic's walkthrough validates, adds and installs with these commands:

claude plugin validate ./my-marketplace
claude plugin marketplace add ./my-marketplace
claude plugin install sume-media@my-marketplace
claude plugin list

Where does each file go?

Anthropic's reference puts only the manifest inside .claude-plugin/. The rest sits at the plugin root, and a marketplace has its own manifest one level up.

From Anthropic's plugins reference and marketplaces page, read 2026-09-29.
FileLocationPurpose
plugin.json.claude-plugin/ in the pluginName, description and userConfig prompts
.mcp.jsonPlugin rootThe mcpServers object with the Sume http server
marketplace.json.claude-plugin/ in the marketplaceLists plugins with a name and a source

What changes for the tool names?

Tools from a plugin-bundled server are not called mcp__sume__generate_video. Anthropic's MCP page gives the form mcp__plugin_<plugin-name>_<server-name>__<tool-name>, so this one is mcp__plugin_sume-media_sume__generate_video. Permission rules, a skill's allowed-tools, a subagent's tools and hook matchers all need that scoped name. A matcher written against the bare server key never fires.

You add and remove a plugin's servers by installing or uninstalling the plugin, not with /mcp commands, though you can toggle the server off in /mcp.

Should the key be an API key or OAuth?

Sume accepts both. The MCP quickstart prefers the OAuth connector flow for interactive clients, and an API-key session sees the whole hosted tool set, while OAuth is read-only until Write is turned on at consent. The plugin route above uses a key. Give each teammate their own key. See API key vs OAuth for an MCP server.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume