claude plugin validate: a clean .mcp.json entry for Sume

Claude Code v2.1.281 makes claude plugin validate check .mcp.json entries. A Sume entry needs only the URL https://mcp.sume.com/mcp and no secret.

3 min readSume
All posts

Claude Code v2.1.281 makes claude plugin validate check .mcp.json entries and undeclared user_config references. A Sume entry should pass cleanly because it needs only the hosted URL, https://mcp.sume.com/mcp, and no key in the file: Sume's docs say to use OAuth and not paste API keys into chat.

What the release says

The line is from the Claude Code release notes. I have not read the validator's full output format, so the example below is what the Sume docs show, not a captured run.

Claude Code v2.1.281 (read 2026-10-03)
ItemDetail
Commandclaude plugin validate
New checksEntries in .mcp.json, and undeclared ${user_config.*} references

The Sume entry

Sume's docs show a remote MCP entry for Cursor with only a url under mcpServers. For Claude Code the docs use the command line instead. Both point at the production endpoint; the dev host mcp.dev.sume.com exists for Sume's own environments, and customer configs should use mcp.sume.com.

Because auth is OAuth, the file carries no secret and no user_config reference, which is the thing the new check looks for. With read access by default, a session sees read-only tools; write and paid tools need mcp:write at consent.

{
  "mcpServers": {
    "sume": {
      "url": "https://mcp.sume.com/mcp"
    }
  }
}

Add it from the command line

The docs give two commands for Claude Code: add the server over HTTP, then log in. Afterward ask the agent to call tools_list or mcp_health to confirm the session.

claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume
claude plugin validate .

Keep the file clean

  • Do not put an API key in .mcp.json; use OAuth for interactive clients.
  • If you need a key for automation, keep it in a secret store, not the plugin.
  • Run claude plugin validate before you publish the plugin.
  • Check the validator's output yourself, since I describe the release note and not a run.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume