claude plugin install --config: setting a bundled MCP server

Claude Code 2.1.285 added claude plugin install --config for bundled MCP server settings. What to put there for a Sume plugin, and what never to.

5 min readSume
All posts

Claude Code 2.1.285 (2026-09-29) added <server>.<key>=<value> to claude plugin install --config for bundled MCP server settings, and claude plugin configure <plugin> to show and save plugin options (read 2026-10-03). For a plugin that bundles Sume's hosted MCP, the safe use is to set non-secret values there, such as a name or a dry-run default, and to leave authentication to OAuth, so no key lands in a command line or a shell history.

The Claude Code facts are in the changelog. The Sume connection facts are in the MCP quickstart and MCP OAuth and API keys. For the plugin file itself, see the plugin .mcp.json post.

What the new flag does and does not do

The changelog line is short: the flag sets settings for a bundled server at install time, and the configure subcommand shows and saves options afterwards. It does not change how Sume authenticates. Sume's documented Claude Code connection is claude mcp add --transport http sume https://mcp.sume.com/mcp, then claude mcp login sume, which runs the OAuth flow. A bundled server with the same URL goes through the same discovery.

Install-time setting vs credential, read 2026-10-03
ValuePut it in --config?Reason
Server display nameYesNot secret
https://mcp.sume.com/mcpYesPublic endpoint
A default max_spend_usd for your own wrapperYesNot secret, and reviewable
A Sume API keyNoLands in shell history and process lists
An OAuth tokenNeverSume says an OAuth token is not an API key; do not store it

The install command

The exact key names depend on what the plugin's manifest declares, so run claude plugin configure first and read the options it lists. This shows only the flag shape from the changelog, using placeholder names for the plugin and its options.

# show the options a plugin declares
claude plugin configure my-sume-plugin

# set a bundled server's non-secret option at install time
claude plugin install my-sume-plugin --config sume.region_hint=us

# authenticate separately; this runs the documented OAuth flow
claude mcp login sume

Check the result

After install, open the MCP status view and confirm the server is connected, then ask Claude to call mcp_health, which reports the auth source and safety posture, and tools_list. Under a default OAuth grant, you should see only read-only tools; paid and write tools appear after you grant mcp:write at consent. If you see them without having done that, you are on an API key.

One related fix in the same changelog stream, from 2.1.288, matters for plugin authors: plugins loaded with --plugin-dir did not show "Configure options" and now do. If you are testing a plugin from a local folder and the configure step is missing, update first.

  • Install with non-secret options only.
  • Run claude mcp login sume for OAuth.
  • Call mcp_health, then tools_list, then a read tool such as catalog_list.
  • Only then grant Write, deliberately, for the person who needs paid generation.

Plugin hygiene for a Sume connector

Treat the plugin as something others will install. Document the URL, the auth flow, and the default posture in the README: read-only OAuth first, Write only when the user asks for generation. Do not ship a key, even a test key, inside the plugin, and do not ask users to pass one with --config, since command lines end up in shell history and process listings.

If a user does need an API key because they run headless, point them to the documented header options, Authorization: Bearer or x-api-key, and to reading the value from an environment variable at launch. Remind them that Sume says to rotate a key that appears in logs.

Version the plugin when the Sume tool list changes. Because Sume says not to assume HTTP API parity and to rely on tools_list, a plugin that hard-codes tool names in prompts should say which names it expects, and a quick tools_list check on first run can warn the user when something is missing.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume