claude plugin validate: a clean .mcp.json entry for Sume
Claude Code v2.1.281 makes claude plugin validate check .mcp.json entries. A Sume entry needs only the URL https://mcp.sume.com/mcp and no secret.

Claude Code v2.1.281 makes claude plugin validate check .mcp.json entries and undeclared user_config references. A Sume entry should pass cleanly because it needs only the hosted URL, https://mcp.sume.com/mcp, and no key in the file: Sume's docs say to use OAuth and not paste API keys into chat.
What the release says
The line is from the Claude Code release notes. I have not read the validator's full output format, so the example below is what the Sume docs show, not a captured run.
| Item | Detail |
|---|---|
| Command | claude plugin validate |
| New checks | Entries in .mcp.json, and undeclared ${user_config.*} references |
The Sume entry
Sume's docs show a remote MCP entry for Cursor with only a url under mcpServers. For Claude Code the docs use the command line instead. Both point at the production endpoint; the dev host mcp.dev.sume.com exists for Sume's own environments, and customer configs should use mcp.sume.com.
Because auth is OAuth, the file carries no secret and no user_config reference, which is the thing the new check looks for. With read access by default, a session sees read-only tools; write and paid tools need mcp:write at consent.
{
"mcpServers": {
"sume": {
"url": "https://mcp.sume.com/mcp"
}
}
}Add it from the command line
The docs give two commands for Claude Code: add the server over HTTP, then log in. Afterward ask the agent to call tools_list or mcp_health to confirm the session.
claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume
claude plugin validate .Keep the file clean
- Do not put an API key in .mcp.json; use OAuth for interactive clients.
- If you need a key for automation, keep it in a secret store, not the plugin.
- Run claude plugin validate before you publish the plugin.
- Check the validator's output yourself, since I describe the release note and not a run.
Sources
Related posts
More in Developers
- Cloudflare AI Search bills from Nov 1: split retrieval from renders
Cloudflare's October 1 changelog makes AI Search GA with usage billing from November 1, 2026. How to keep retrieval costs separate from Sume render costs.
- Cloudflare Sandbox SDK 1.0: run the Sume SDK inside one
The @sume-com/sdk has no runtime dependencies and needs only fetch and WebCrypto, so it can run in a sandbox. Pass the key as an env var, server-side only.
- Cloudflare Worker for Sume webhooks: log fields a dashboard needs
Cloudflare added Workers Observability to Custom Dashboards on Oct 1. A Sume webhook Worker should log event, job_id, outcome and the secret fingerprint.
- Codex 0.160 agent history 'Show more': recover Sume jobs by job list
Codex CLI 0.160.0 adds Show more pagination to agent command center history. If a thread scrolls away, Sume's GET /v1/jobs list still holds every job.
Written by Sume