Claude connector sign-in now, when needed or none: pick for Sume
For Sume's hosted MCP, pick Sign in now with OAuth, or add one auth header for an API key. No sign in fails, because the server needs a credential.

When Claude's custom connector dialog asks how to authenticate, choose Sign in now for Sume's hosted MCP server and finish the OAuth consent, or add a single API-key header if you want a key instead. Do not choose No sign in: Sume's server requires a credential, so a connector with no auth cannot list tools.
The dialog's options come from Anthropic's help article Get started with custom connectors using remote MCP, read on 2026-10-02. Sume's rules come from OAuth and API keys and Authentication.
What are the three sign-in choices?
Anthropic lists three: Sign in now, Sign in when needed, and No sign in. The article also describes three authentication types: OAuth, fixed credentials sent as request headers, and no authentication. The article names the choices but this post does not rely on more than their names, so the Claude column below reads them from the label; the Sume column is from Sume's docs.
| Choice | What Claude does | Result with Sume |
|---|---|---|
| Sign in now | Signs in at once, as the label says | You see consent at once and learn immediately if it works |
| Sign in when needed | Signs in later, as the label says | Works, but the first call prompts you mid-chat |
| No sign in | Sends no credential | Sume requires OAuth or an API key, so the connection cannot list tools |
Which should I pick for OAuth?
Pick Sign in now when you are setting the connector up, because a failed consent shows while you are still in the dialog. Sign in when needed suits a shared setup where not everyone will use Sume. Either way the consent page lives on the MCP host, shows Read locked on and Write off by default, and returns tokens by authorization code with PKCE.
Sume's authorization-server metadata, published at https://mcp.sume.com/.well-known/oauth-authorization-server, lists the authorization-code grant, S256 code challenges and the token endpoint auth method none. In plain terms Sume's OAuth client is public: it has no client secret. If the dialog offers a custom client option, you do not need to invent a client secret for Sume, and the metadata also advertises a registration endpoint at /oauth/register for clients that register themselves.
How do I use an API key in the connector instead?
The dialog has an add request headers step for API keys. Sume's docs accept either Authorization: Bearer <SUME_API_KEY> or x-api-key: <SUME_API_KEY>. Send exactly one: Sume's authentication page says a request carrying both is rejected with 401 unauthorized. Create the key in the dashboard, and rotate it if it ever appears in a log or a chat.
A key session sees the full hosted tool set, so the Write toggle does not apply. Paid and write calls still need an idempotency_key, and wallet admission is the spend gate. dry_run=true previews a cost without submitting, and max_spend_usd caps spend when you pass it. For that reason an OAuth session with Write off is the safer default for a person at a keyboard, and a key is for automation.
What if I picked the wrong one?
Remove the connector and add it again, or edit its authentication settings. Two symptoms are worth telling apart. A connector that cannot connect or lists no tools usually means no credential reached Sume. A connector that connects but lacks generate_image is usually an OAuth session without mcp:write, and a call to a hidden tool returns insufficient_scope.
Check with mcp_health: it reports the auth source, mcp_oauth for OAuth or an API-key source for a key, and tools_list shows what this session can see. The insufficient scope troubleshooting post walks through the fix.
What does this not cover?
Claude's connector dialog is Anthropic's product and its menu names can change; re-check the help article if a label differs. Sume has no mcp:paid scope. The connector only reaches the tools in tools_list, so Image 1.0 and Video 1.0 still need the REST API.
Sources
Related posts
More in Integrations
- Claude Team or Enterprise: owner adds the Sume connector first
On Claude Team and Enterprise an owner adds the custom connector in Organization settings first, then members connect. Free plans get one custom connector.
- Cloudflare Cron Triggers: 5 free, 250 paid, one Sume bulk run
Free Workers accounts get 5 Cron Triggers, Paid get 250. Use one trigger to fan out many Sume Format runs through a bulk queue instead of one cron each.
- Workers 50 subrequests on free: poll one Sume queue, not 100 jobs
A free Cloudflare Worker gets 50 subrequests per invocation (10,000 paid). Polling 100 Sume jobs one by one fails; one bulk-queue read does not.
- Cloudflare Workers waitUntil: 30 seconds to submit a Sume run
ctx.waitUntil extends a Worker up to 30 seconds past the response: enough to submit a Sume job with an Idempotency-Key, not to wait on sync mode.
Written by Sume