Claude Code: local Sume entry vs claude.ai connector, who wins

Claude Code ranks a local Sume MCP entry above a claude.ai connector. That decides whether you get the API key's full tool set or OAuth's read-only one.

5 min readSume
All posts

When Claude Code finds the same server defined twice, a local entry beats a claude.ai connector. The Claude Code page lists precedence from highest to lowest as Managed MCP, Local, Project, User, Plugin-provided, then claude.ai connectors. For Sume this matters because the two entries can use different credentials. A local entry with an API key sees the full tool set. A connector signed in over OAuth is read-only unless Write was ticked on the consent page.

The order, and what it means for Sume

Claude Code precedence and storage (read 2026-10-09) with the Sume credential each tier usually carries (as of 2026-10-09)
TierWhere it livesTypical Sume credential
Managed MCPSet by an administratorWhatever the admin configured
Local~/.claude.json, default scopeAPI key via --header
ProjectShared .mcp.jsonShould hold no secret
User~/.claude.json, all projectsAPI key or OAuth
Plugin-providedA pluginPlugin author's choice
claude.ai connectorYour claude.ai accountOAuth, read-only by default

A symptom to recognise

Suppose you added the Sume connector in claude.ai with Write off, then later ran claude mcp add with an API key header. Claude Code will use the local entry, and write tools such as job creation appear. Delete the local entry and the connector takes over, and those tools vanish: under the read scope, write tools are hidden, and calling one returns insufficient_scope with required_scope mcp:write.

The reverse surprise is also possible. A project .mcp.json that names a Sume server will shadow a user-level entry. A teammate who clones the repo may then see a different tool list from yours with no change on their side.

Check which entry is live

Run /mcp in Claude Code to see the server and the sign-in state, and call mcp_health from the model to read the credential and scopes the session is using. The tools list is the surface that credential sees, so a missing write tool points at an OAuth session, and an unexpected one points at a key.

Keep API keys out of the Project tier. A shared .mcp.json is committed to the repository, so put the key in Local scope with the --header flag, or use headersHelper to fetch it at run time.

A safe setup for a team

Pick one credential per person and one entry per scope, so precedence never has to decide. For a person who only reads, use the claude.ai connector or a User-scope OAuth entry and leave Write off. For a person who submits paid jobs, use a Local-scope entry with an API key and keep it out of the repository.

If an administrator wants to settle the question for everyone, a Managed MCP entry sits at the top of the order and overrides anything a user adds. Give that entry the credential you want the whole team to use, and remember that an API key in a managed entry exposes the full tool set to every user it reaches.

Whatever you choose, remember what the credential allows. Write and paid calls need an idempotency_key on every call, and max_spend_usd is enforced only when the model sends it. The entry you choose decides who can reach those tools; it does not cap their spend.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume