Codex MCP enabled = false: pause the Sume server safely

Turn the Sume server off in Codex with enabled = false instead of deleting it, and rotate the API key if it ever showed up in logs or chat.

4 min readSume
All posts

Set enabled = false on the Sume entry in Codex's config.toml to turn the server off without deleting its settings. Codex's page describes enabled as a toggle for the server that does not require deletion; Sume's docs add that keys exposed in logs or chat should be rotated.

Codex facts are from its MCP page; Sume facts from OAuth and API keys and Safe automation, read 2026-09-30.

What does the toggle look like?

Keep the url and any key variable name in place and flip one line. When you want Sume back, set it to true and ask the agent to call mcp_health, which the docs say confirms endpoint, auth source and safety posture.

[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
enabled = false

When is pausing not enough?

If a key leaked, disabling the server does not revoke it. The Sume docs say to rotate API keys if they appear in logs or chat history, and to create keys in the dashboard. An OAuth token is not a Sume API key, and the docs say not to store OAuth tokens in CLI config or paste them into prompts.

Which credential does the paused server use?

Credential rules from the Sume docs, read 2026-09-30: https://docs.sume.com/mcp/oauth
CredentialRule
OAuth tokenNot a Sume API key; do not paste into prompts
API keyBearer header or x-api-key; rotate if exposed
Minted keys for OAuth clientsDo not mint them as a workaround
LogsSafe: request ids, job ids, status. Unsafe: keys, signed URLs

Is there a read-only alternative to pausing?

Yes. Keep the server on and sign in with OAuth, leaving Write off. Then paid tools are hidden and return insufficient_scope. That preserves discovery calls like tools_list and catalog_list while blocking spend.

What about scheduled or unattended runs?

For runs nobody watches, the Sume docs recommend keeping read-only exploration separate from paid actions and logging only request ids, job ids, high-level status and sanitized media metadata. Pausing the server is a clean way to stop an unattended agent from reaching Sume at all, and re-enabling it later restores the same configuration without retyping the URL.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume