Claude Team or Enterprise: owner adds the Sume connector first
On Claude Team and Enterprise an owner adds the custom connector in Organization settings first, then members connect. Free plans get one custom connector.

On Claude Team and Enterprise plans, an Owner or Primary Owner must add the custom connector under Organization settings > Connectors before members can connect; each member then connects it themselves under Customize > Connectors. For Sume, the URL to add is https://mcp.sume.com/mcp. On a Free plan you can add only one custom connector in total.
These plan rules are from Anthropic's help article Get started with custom connectors using remote MCP, read on 2026-10-02. Sume's rules come from OAuth and API keys, MCP tools and gates and the MCP quickstart.
Who can add the connector on each plan?
Anthropic's article says custom connectors using remote MCP are available on Claude, Cowork and Claude Desktop for Free, Pro, Max, Team and Enterprise plans. What differs is who does the adding.
| Plan | Who adds it | Limit |
|---|---|---|
| Free | The user, in Customize > Connectors | One custom connector |
| Pro and Max | The user, in Customize > Connectors | Not stated on the page |
| Team and Enterprise | An Owner or Primary Owner first, in Organization settings > Connectors; members then connect individually | Not stated on the page |
What should the owner set for Sume?
Enter the production URL, https://mcp.sume.com/mcp, and pick an authentication method. The help article offers OAuth, fixed credentials sent as request headers, or none. Sume needs one of the first two. For a team, OAuth is usually the better fit, because each member signs in as themselves on Sume's consent page instead of everyone sharing one credential.
A header-based API key is different: a key put in an organization-level connector would be a shared credential. Sume's docs say an API-key session sees the full hosted tool set, with paid calls gated by the wallet and by idempotency_key. Sharing one key means every member spends from the same place, and the key has to be rotated if it leaks. If you do that on purpose, say so in your team's rules first.
What does each member see after connecting?
Each member completes OAuth on the MCP host. The consent page has Read locked on and Write off by default, so a member who leaves Write off gets read-only tools such as jobs_list and catalog_list, and a paid tool such as generate_image returns insufficient_scope. A member who wants to run paid generations turns Write on at consent, or reconnects to change it.
Because there is no mcp:paid scope, the owner cannot grant spend as a separate permission. The controls available are the Write toggle at consent, the wallet, dry_run, and the optional max_spend_usd on a call. Anthropic's connector settings also let you enable or disable individual tools, which is a separate layer on the Claude side.
Why does a member see no tools after the owner added it?
Two common reasons. First, the member has not connected yet: the owner's step makes the connector available, but each member still connects it under Customize > Connectors. Second, the member's OAuth session has only mcp:read, so write and paid tools are hidden rather than greyed out. Ask the member to run mcp_health, which confirms the auth source, and tools_list, which shows what the session can use.
Anthropic also says the remote server must be reachable from Anthropic's IP ranges over the public internet. Sume's production endpoint is public, so a missing tool list is almost never a reachability problem; check the connection and the scope first.
What does Sume not do here?
Sume does not manage your Claude organization or read its member list. Image 1.0 and Video 1.0 are not on hosted MCP and stay on the REST API. Treat the connector as access to the tools in tools_list, nothing more.
Sources
Related posts
More in Integrations
- Cloudflare Cron Triggers: 5 free, 250 paid, one Sume bulk run
Free Workers accounts get 5 Cron Triggers, Paid get 250. Use one trigger to fan out many Sume Format runs through a bulk queue instead of one cron each.
- Workers 50 subrequests on free: poll one Sume queue, not 100 jobs
A free Cloudflare Worker gets 50 subrequests per invocation (10,000 paid). Polling 100 Sume jobs one by one fails; one bulk-queue read does not.
- Cloudflare Workers waitUntil: 30 seconds to submit a Sume run
ctx.waitUntil extends a Worker up to 30 seconds past the response: enough to submit a Sume job with an Idempotency-Key, not to wait on sync mode.
- codex mcp add --oauth-client-secret: do you need it for Sume?
Codex CLI 0.158.0 added --oauth-client-secret for MCP servers that require a pre-registered client secret. Sume's OAuth uses public clients, so you can skip it.
Written by Sume