Claude Code: local Sume entry vs claude.ai connector, who wins
Claude Code ranks a local Sume MCP entry above a claude.ai connector. That decides whether you get the API key's full tool set or OAuth's read-only one.

When Claude Code finds the same server defined twice, a local entry beats a claude.ai connector. The Claude Code page lists precedence from highest to lowest as Managed MCP, Local, Project, User, Plugin-provided, then claude.ai connectors. For Sume this matters because the two entries can use different credentials. A local entry with an API key sees the full tool set. A connector signed in over OAuth is read-only unless Write was ticked on the consent page.
The order, and what it means for Sume
| Tier | Where it lives | Typical Sume credential |
|---|---|---|
| Managed MCP | Set by an administrator | Whatever the admin configured |
| Local | ~/.claude.json, default scope | API key via --header |
| Project | Shared .mcp.json | Should hold no secret |
| User | ~/.claude.json, all projects | API key or OAuth |
| Plugin-provided | A plugin | Plugin author's choice |
| claude.ai connector | Your claude.ai account | OAuth, read-only by default |
A symptom to recognise
Suppose you added the Sume connector in claude.ai with Write off, then later ran claude mcp add with an API key header. Claude Code will use the local entry, and write tools such as job creation appear. Delete the local entry and the connector takes over, and those tools vanish: under the read scope, write tools are hidden, and calling one returns insufficient_scope with required_scope mcp:write.
The reverse surprise is also possible. A project .mcp.json that names a Sume server will shadow a user-level entry. A teammate who clones the repo may then see a different tool list from yours with no change on their side.
Check which entry is live
Run /mcp in Claude Code to see the server and the sign-in state, and call mcp_health from the model to read the credential and scopes the session is using. The tools list is the surface that credential sees, so a missing write tool points at an OAuth session, and an unexpected one points at a key.
Keep API keys out of the Project tier. A shared .mcp.json is committed to the repository, so put the key in Local scope with the --header flag, or use headersHelper to fetch it at run time.
A safe setup for a team
Pick one credential per person and one entry per scope, so precedence never has to decide. For a person who only reads, use the claude.ai connector or a User-scope OAuth entry and leave Write off. For a person who submits paid jobs, use a Local-scope entry with an API key and keep it out of the repository.
If an administrator wants to settle the question for everyone, a Managed MCP entry sits at the top of the order and overrides anything a user adds. Give that entry the credential you want the whole team to use, and remember that an API key in a managed entry exposes the full tool set to every user it reaches.
Whatever you choose, remember what the credential allows. Write and paid calls need an idempotency_key on every call, and max_spend_usd is enforced only when the model sends it. The entry you choose decides who can reach those tools; it does not cap their spend.
Sources
Related posts
More in Integrations
- claude --strict-mcp-config: run CI with only the Sume server
--strict-mcp-config makes Claude Code use only servers from --mcp-config. A CI recipe for loading just Sume's hosted MCP, with a key, a wait limit and a cap.
- Cursor mcp.json for Sume: a URL and nothing else
The Cursor entry for hosted Sume MCP is one url field with no key in the file; OAuth sign-in happens in the client and the consent page lives on the MCP host.
- Devin Desktop ${file:} interpolation for the Sume API key
Devin Desktop expands ${file:/path} and ${env:NAME} in mcp_config.json. Put the Sume API key in a file outside the config; the 100-tool cap still applies.
- Gemini CLI authProviderType: connect Sume with dynamic_discovery
Gemini CLI defaults authProviderType to dynamic_discovery. For Sume that means OAuth discovery, not Google credentials. What each of the three values does.
Written by Sume