Codex bearer_token_env_var: connect Sume MCP with an API key, no OAuth
Set url and bearer_token_env_var in Codex's config.toml so a Sume API key from the environment authenticates hosted MCP, with enabled_tools to shorten the list.

To connect Codex to Sume's hosted MCP server with an API key, add a server entry in Codex's config.toml with url set to https://mcp.sume.com/mcp and bearer_token_env_var set to the name of an environment variable that holds the key. Codex then sends the key as a Bearer token; the key itself never sits in the file.
The config keys come from Codex's MCP documentation, read 2026-09-29; the auth behavior comes from Sume's MCP OAuth and API keys page, which lists Authorization: Bearer and x-api-key as the two ways to send a key.
What does the config look like?
Codex's page lists url, bearer_token_env_var, http_headers, tool_timeout_sec and enabled_tools as options for a server. This entry uses three of them.
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
bearer_token_env_var = "SUME_API_KEY"
enabled_tools = ["mcp_health", "generate_video", "jobs_wait", "jobs_result"]When should I pick a key over OAuth?
OAuth suits a person at a keyboard. A key suits a script, a CI job or a machine with no browser. The two are not interchangeable credentials: an OAuth token is not an API key.
| Mode | How it connects | Tools |
|---|---|---|
| OAuth | codex mcp login, consent on the MCP host | mcp:read by default; mcp:write if Write is on |
| API key | Bearer token from an environment variable | Full hosted tool set |
What does a key change about spend?
With a key the paid tools are available without a consent step, so the controls matter more. Paid calls need an idempotency_key, dry_run=true previews admission and cost, and max_spend_usd is enforced when the call provides it.
Keep the key in your shell profile or secret store, rotate it if it appears in logs or chat, and do not paste it into a prompt.
Why list enabled_tools?
Sume's full tool set is long. Listing only the tools a task needs keeps the model's choice small; the four above cover a health check, one paid call, and collecting the result. A remote jobs_wait call holds at most 55 seconds, so set tool_timeout_sec above that if Codex cuts tool calls off sooner.
Sources
Related posts
More in Integrations
- C# HttpClient POST JSON with a Bearer token
Set Authorization with AuthenticationHeaderValue("Bearer", key), send a JSON body, then read the status and body before EnsureSuccessStatusCode.
- Cursor team MCP servers: share Sume's hosted MCP across a team
Cursor's docs describe project, global and team MCP servers. Where Sume's hosted MCP fits in each, how sign-in works per person, and what a shared key changes.
- EventBridge API destinations: call a paid API without Lambda
An EventBridge API destination calls an HTTPS API straight from a rule, with a 5-second timeout and retries on 409, 429 and 5xx. Key every call.
- Golang HTTP POST JSON with headers and a Bearer token
http.Post can't set headers. Marshal the JSON, build it with http.NewRequest, set headers, send with a Client that has a Timeout, and close the body.
Written by Sume