claude plugin validate and an insecure URL in .mcp.json

Claude Code 2.1.283 added MCP checks to claude plugin validate, including insecure URLs. Sume's hosted endpoint is https, so a plain entry has nothing to flag.

4 min readSume
All posts

An .mcp.json entry for Sume passes the insecure-URL check as long as its url is https://mcp.sume.com/mcp, the only production endpoint in Sume's docs. The same release also reports undeclared user_config.* references, so the simplest entry carries no key placeholder at all and lets OAuth supply the credential.

The check list is from the Claude Code changelog, read 2026-09-30. The endpoint and auth options are from Sume's MCP quickstart and MCP OAuth and API keys. This page does not claim to know the exact rule behind each warning; the changelog gives one line.

What did claude plugin validate start checking?

Version 2.1.283 (Sept 25, 2026) added MCP server checks to claude plugin validate. The changelog says it reports three things in .mcp.json: entries that would be silently dropped at load, undeclared user_config.* references, and insecure URLs.

New validate checks and the Sume entry, from the Claude Code changelog and Sume docs, read 2026-09-30
Check in the changelogWhat the Sume entry does
Entries silently dropped at loadKeep the server under mcpServers with a url, as in the quickstart example
Undeclared user_config.* referencesNone needed with OAuth; only add one if you send an API key
Insecure URLshttps://mcp.sume.com/mcp, not an http:// address

Which Sume URL should the entry use?

Production is https://mcp.sume.com/mcp; use that one in a shared plugin. The quickstart adds the server from the command line like this:

claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume

Do I need a key placeholder in the file?

Not for OAuth. Sume returns an OAuth challenge and protected-resource metadata, and the client sends you through consent, so the file holds only the URL. The default grant is read-only (mcp:read); Write is a toggle on the consent page.

If you use an API key instead, Sume accepts Authorization: Bearer $SUME_API_KEY or x-api-key. Keep the key out of the committed file, and make sure any user_config.* placeholder you use is declared, since undeclared ones are what the new check reports. The existing walkthrough bundling a Sume server in a plugin shows that variant.

What should I check after validate passes?

The changelog describes validate as a file check, so it does not tell you the server connects. Confirm the connection in Claude Code's MCP status UI, then call tools_list or mcp_health, both read-only. Which key or OAuth mode to pick is covered in API key vs OAuth for an MCP server.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume