Plugin lists Sume twice? In Claude Code the later declaration wins
Claude Code loads a plugin's .mcp.json first, then mcpServers from plugin.json; a name declared later replaces an earlier one. Keep one Sume entry.

If a Claude Code plugin declares a server called sume in both .mcp.json and the mcpServers field of plugin.json, only one survives. The plugin manifest reference says Claude Code loads .mcp.json at the plugin root first and then each declared shape in order, and a server name declared later replaces an earlier one. So the manifest entry beats the file, and a later array element beats an earlier one.
This is easy to trip over when two people maintain the same plugin: one adds an OAuth entry in .mcp.json, another adds an API-key entry in the manifest, and the plugin quietly uses the second one.
Load order for a Sume entry
The reference gives the accepted shapes for mcpServers. The order below is how they combine.
| Step | Source | Effect on a server named sume |
|---|---|---|
| 1 | .mcp.json at the plugin root | Loaded first |
| 2 | mcpServers as a .json path | Replaces the same name from step 1 |
| 3 | mcpServers inline map | Replaces the same name from earlier steps |
| 4 | Later elements of an mcpServers array | Replace earlier elements with the same name |
Pick one auth mode per name
Sume accepts two kinds of caller at https://mcp.sume.com/mcp. OAuth with the mcp:read scope sees read-only tools, and opting in to mcp:write exposes the tools that change data and the paid ones. An API key sent as Authorization: Bearer or x-api-key gets the full tool set. If your plugin ships both, give them different names, for example sume for OAuth and sume-key for the key, so the user knows which tool prefix belongs to which access level.
Different names also keep hook matchers honest. A guard written for the key-backed server should not silently apply to the read-only one.
Steps to audit
Open the plugin directory and search for the string mcp.sume.com in .mcp.json, plugin.json and any file named in mcpServers. Count entries per server name. Run claude plugin validate; it checks every MCP entry the plugin declares in those three places and errors on an entry Claude Code would drop.
- One name, one URL, one auth mode.
- Put the final intended entry last, or delete the duplicate.
- After enabling the plugin, call
mcp_healthand readauthenticated.auth_sourceto confirm which mode actually connected.
A symptom to look for
If a teammate says the paid tools work for them but not for you, compare tools_list output. Under OAuth mcp:read Sume hides the write and paid tools, so a shorter list points at a read-only session rather than a bug in the plugin.
What Sume does not do
Sume does not merge two connections from the same client, and it does not know your plugin has a duplicate. It only sees whichever Authorization header or OAuth session arrives. If you expected a read-only OAuth session and got an API-key session, the difference shows up as more tools in tools_list and as paid tools becoming callable.
Sources
Related posts
More in Developers
- claude plugin validate --strict in CI: what it checks in a Sume entry
Run claude plugin validate with --strict so warnings fail the build. The MCP checks that hit a Sume entry: undeclared keys, bad URLs, literal credentials.
- Claude tool search limits: 200-char regex, 500-char BM25, 5 results
Claude's tool search tool has fixed limits on pattern length, results and deferred tools. What they mean for a Sume hosted MCP tool list.
- Cloudflare Queue consumer 15 min wall time: poll a Sume job
A Queue consumer on Cloudflare can run 15 minutes of wall time, but a Sume job can wait longer. Re-enqueue with a delay and honor next_poll_after_seconds.
- Sume webhooks in a Cloudflare Worker: verify, queue, 204
A Worker that verifies a Sume delivery with verifyWebhook, hands the event to a queue with ctx.waitUntil, and replies 204 inside Sume's 10-second limit.
Written by Sume