Codex bearer_token_env_var for Sume MCP: keep the key out of config

Codex can read a bearer token from an environment variable, so your Sume API key never lands in config.toml. Setup, the OAuth alternative, and what to check.

5 min readSume
All posts

Set bearer_token_env_var = "SUME_API_KEY" on the Sume server entry in Codex and export the key in your shell. Codex sends it as the bearer token to https://mcp.sume.com/mcp, and the secret stays out of config.toml. If you only need read access, skip the key and use the client's OAuth login instead.

Codex HTTP server keys, read 2026-10-08
KeyPurpose
urlServer address (required)
bearer_token_env_varName of the variable that holds the bearer token
http_headersStatic header values written in the file
env_http_headersHeader names mapped to environment variable names

Entry and shell

Put the variable name in the file and the value in your shell profile or a secrets manager.

[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
bearer_token_env_var = "SUME_API_KEY"

# shell, not the file:
# export SUME_API_KEY=your-key-from-the-dashboard

OAuth or key

The Sume docs call OAuth the preferred path for interactive clients. A Codex session is often unattended, which is where a key fits. The tradeoff is scope: an OAuth grant is read-only unless Write is switched on at consent, while a key sees every tool.

Choosing a credential for Codex, read 2026-10-08
SituationCredentialReason
Looking up jobs, assets, catalogOAuth mcp:readWrite and paid tools stay hidden
Scripted runs that create paid jobsAPI keyFull tool set; idempotency_key required
Interactive run with paid callsOAuth with Write onScope is explicit on the consent page

Checks

Two Sume rules apply however the key arrives. Paid and write calls need an idempotency_key. There is no mcp:paid scope, so spend is controlled by wallet admission, and max_spend_usd is enforced only when you pass it.

After the first connection, ask the agent to call mcp_health. The authenticated.auth_source field tells you which credential the session used. If a key was rotated or leaked into a log, create a new one in the dashboard and update the variable.

Where the variable lives

Codex reads the variable from the process environment that starts it. A key exported in one terminal is not visible to the desktop app launched from the dock, so set it where the app can see it, or start Codex from the shell that has it. If the variable is empty, Codex has nothing to send, and the server will answer with an authentication challenge instead of tools.

Rotation and sharing

Give each machine or automation its own key so a leak can be revoked without breaking the rest. After you revoke, update the variable and restart Codex. The Sume docs recommend rotating any key that appears in logs or chat history, and recommend against pasting keys into prompts. A config that names only the variable can be shared in a repository safely, because the secret is not in it.

For teams, a short written rule helps. Say which workspace the key belongs to, who can rotate it, and which agents may use it. Codex shares one configuration across its app, CLI and IDE extension, so a single entry covers all three, and a single leak covers all three too. If you want different reach for different surfaces, use OAuth for the interactive ones and keep the key for the unattended job.

Keep in mind that Sume's hosted endpoint is the same for every client in this series: https://mcp.sume.com/mcp, with OAuth consent on the MCP host or an API key in a header. What differs is each client's config keys, its timeout defaults and its approval prompts. When a connection misbehaves, first separate those two layers: test the endpoint with curl and your credential, and only then look at the client's settings.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume