Codex MCP enabled = false: pause the Sume server safely
Turn the Sume server off in Codex with enabled = false instead of deleting it, and rotate the API key if it ever showed up in logs or chat.

Set enabled = false on the Sume entry in Codex's config.toml to turn the server off without deleting its settings. Codex's page describes enabled as a toggle for the server that does not require deletion; Sume's docs add that keys exposed in logs or chat should be rotated.
Codex facts are from its MCP page; Sume facts from OAuth and API keys and Safe automation, read 2026-09-30.
What does the toggle look like?
Keep the url and any key variable name in place and flip one line. When you want Sume back, set it to true and ask the agent to call mcp_health, which the docs say confirms endpoint, auth source and safety posture.
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
enabled = falseWhen is pausing not enough?
If a key leaked, disabling the server does not revoke it. The Sume docs say to rotate API keys if they appear in logs or chat history, and to create keys in the dashboard. An OAuth token is not a Sume API key, and the docs say not to store OAuth tokens in CLI config or paste them into prompts.
Which credential does the paused server use?
| Credential | Rule |
|---|---|
| OAuth token | Not a Sume API key; do not paste into prompts |
| API key | Bearer header or x-api-key; rotate if exposed |
| Minted keys for OAuth clients | Do not mint them as a workaround |
| Logs | Safe: request ids, job ids, status. Unsafe: keys, signed URLs |
Is there a read-only alternative to pausing?
Yes. Keep the server on and sign in with OAuth, leaving Write off. Then paid tools are hidden and return insufficient_scope. That preserves discovery calls like tools_list and catalog_list while blocking spend.
What about scheduled or unattended runs?
For runs nobody watches, the Sume docs recommend keeping read-only exploration separate from paid actions and logging only request ids, job ids, high-level status and sanitized media metadata. Pausing the server is a clean way to stop an unattended agent from reaching Sume at all, and re-enabling it later restores the same configuration without retyping the URL.
Sources
Related posts
More in Developers
- Codex mcp_oauth_callback_port and the Sume OAuth login
Pin the Codex OAuth callback port for a remote Sume MCP login, and how the login flows from Codex to the Sume consent page on mcp.sume.com.
- Content Credentials after download: check the file you deliver
C2PA 2.2 defines Content Credentials and a separate Soft Binding API. Sume's docs do not say a downloaded output keeps one, so check the delivered file.
- Can I continue a Sume Agent Completion with thread_id?
Not yet. Every Agent Completion runs in a fresh thread, so a follow-up call cannot reuse thread_id. Pass earlier results back in the next request instead.
- Get the rendered MP4 back from a video editing API job
Descript's API lists no rendered file download without publishing. In Sume, a finished timeline_render job result carries video_url; here is the poll flow.
Written by Sume