Claude connector sign-in now, when needed or none: pick for Sume

For Sume's hosted MCP, pick Sign in now with OAuth, or add one auth header for an API key. No sign in fails, because the server needs a credential.

5 min readSume
All posts

When Claude's custom connector dialog asks how to authenticate, choose Sign in now for Sume's hosted MCP server and finish the OAuth consent, or add a single API-key header if you want a key instead. Do not choose No sign in: Sume's server requires a credential, so a connector with no auth cannot list tools.

The dialog's options come from Anthropic's help article Get started with custom connectors using remote MCP, read on 2026-10-02. Sume's rules come from OAuth and API keys and Authentication.

What are the three sign-in choices?

Anthropic lists three: Sign in now, Sign in when needed, and No sign in. The article also describes three authentication types: OAuth, fixed credentials sent as request headers, and no authentication. The article names the choices but this post does not rely on more than their names, so the Claude column below reads them from the label; the Sume column is from Sume's docs.

Claude connector sign-in choice against Sume's hosted MCP (read 2026-10-02)
ChoiceWhat Claude doesResult with Sume
Sign in nowSigns in at once, as the label saysYou see consent at once and learn immediately if it works
Sign in when neededSigns in later, as the label saysWorks, but the first call prompts you mid-chat
No sign inSends no credentialSume requires OAuth or an API key, so the connection cannot list tools

Which should I pick for OAuth?

Pick Sign in now when you are setting the connector up, because a failed consent shows while you are still in the dialog. Sign in when needed suits a shared setup where not everyone will use Sume. Either way the consent page lives on the MCP host, shows Read locked on and Write off by default, and returns tokens by authorization code with PKCE.

Sume's authorization-server metadata, published at https://mcp.sume.com/.well-known/oauth-authorization-server, lists the authorization-code grant, S256 code challenges and the token endpoint auth method none. In plain terms Sume's OAuth client is public: it has no client secret. If the dialog offers a custom client option, you do not need to invent a client secret for Sume, and the metadata also advertises a registration endpoint at /oauth/register for clients that register themselves.

How do I use an API key in the connector instead?

The dialog has an add request headers step for API keys. Sume's docs accept either Authorization: Bearer <SUME_API_KEY> or x-api-key: <SUME_API_KEY>. Send exactly one: Sume's authentication page says a request carrying both is rejected with 401 unauthorized. Create the key in the dashboard, and rotate it if it ever appears in a log or a chat.

A key session sees the full hosted tool set, so the Write toggle does not apply. Paid and write calls still need an idempotency_key, and wallet admission is the spend gate. dry_run=true previews a cost without submitting, and max_spend_usd caps spend when you pass it. For that reason an OAuth session with Write off is the safer default for a person at a keyboard, and a key is for automation.

What if I picked the wrong one?

Remove the connector and add it again, or edit its authentication settings. Two symptoms are worth telling apart. A connector that cannot connect or lists no tools usually means no credential reached Sume. A connector that connects but lacks generate_image is usually an OAuth session without mcp:write, and a call to a hidden tool returns insufficient_scope.

Check with mcp_health: it reports the auth source, mcp_oauth for OAuth or an API-key source for a key, and tools_list shows what this session can see. The insufficient scope troubleshooting post walks through the fix.

What does this not cover?

Claude's connector dialog is Anthropic's product and its menu names can change; re-check the help article if a label differs. Sume has no mcp:paid scope. The connector only reaches the tools in tools_list, so Image 1.0 and Video 1.0 still need the REST API.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume