Codex http_headers_helper: send the Sume API key without storing it

Codex's http_headers_helper runs a local command that prints header JSON, so a Sume API key can come from a secret manager instead of config.toml.

5 min readSume
All posts

Set http_headers_helper on the Sume server in ~/.codex/config.toml to a local command that prints a JSON object of header names and values, for example {"x-api-key": "..."} fetched from a secret manager. Codex's reference describes the key as a local command that prints a JSON object of header names (read 2026-10-02), and Sume accepts a key in x-api-key or an Authorization: Bearer header.

Four ways Codex can send a header

The Codex reference lists several HTTP options for a server. They differ in where the secret lives.

Codex HTTP header options, read 2026-10-02 from the Codex docs; the last column says where the Sume key lives.
KeyWhat the Codex docs sayWhere the key lives
http_headersStatic header name-value pairsIn config.toml, as text
env_http_headersHeaders mapped to environment variablesIn the shell environment
bearer_token_env_varEnvironment variable for the bearer tokenIn the shell environment
http_headers_helperLocal command that prints a JSON object of header namesIn the secret manager
authAuthentication method, oauth or chatgptNot a key route
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
http_headers_helper = "/usr/local/bin/sume-mcp-headers"
tool_timeout_sec = 90

# /usr/local/bin/sume-mcp-headers (chmod 700)
#!/bin/sh
printf '{"x-api-key": "%s"}' "$(my-secret-tool get sume-api-key)"

Why use a helper over an env var

An environment variable is simple, but it is visible to every process the shell starts. A helper keeps the key in a store with its own access control and reads it only when Codex needs headers. Sume's docs say to rotate a key that appears in logs or chat history, and a helper that never prints the key to stdout outside the JSON line makes that less likely (OAuth and API keys).

Replace my-secret-tool with your own tool; the snippet is a shape, not a product. If the key could contain a double quote or a backslash, build the JSON with a tool that escapes it rather than printf.

What stays the same

The helper only changes where the header comes from. An API-key session still sees the full hosted tool set, paid tools need an idempotency_key, and dry_run and max_spend_usd are the preview and cap (MCP tools and gates). Pair the helper with the per-server approval settings if you want prompts on the paid tools.

Keep tool_timeout_sec above Sume's 55-second jobs_wait hold; Codex's documented default is 60 seconds.

Limits

Check the connection with mcp_health and tools_list, the read-only first calls in the MCP quickstart.

  • The Codex page I read does not say how often the helper runs, so test it by checking mcp_health after a restart.
  • A helper that fails or prints invalid JSON should be treated as a connection failure; check the helper by running it by hand.
  • Sume's OAuth path is separate and does not use this key.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume