Cursor project .cursor/mcp.json or global ~/.cursor/mcp.json for Sume?
Put a URL-only Sume entry in .cursor/mcp.json to share it with a repo, and keep any API key in an env variable in the global file, not in git.

Use .cursor/mcp.json in the project root when the whole repo should offer Sume, and ~/.cursor/mcp.json when only you should. Both take the same url entry. Share the OAuth form, which is just the URL, and keep anything secret out of the committed file.
The two files
Cursor's docs list project-level .cursor/mcp.json and global ~/.cursor/mcp.json. A remote entry uses a url and optional headers. Cursor resolves variables in command, args, env, url and headers, including ${env:NAME}.
{
"mcpServers": {
"sume": { "url": "https://mcp.sume.com/mcp" }
}
}OAuth first, key second
With the entry above, Cursor prompts for sign-in and the consent page appears on the MCP host. A new teammate gets mcp:read unless they switch Write on, so committing the entry does not grant anyone write access.
If you need an API-key session, for example for a headless job, the key goes in a header: "Authorization": "Bearer ${env:SUME_API_KEY}". That session sees all tools. Put it in the global file, or keep the env variable set only where it is needed, and never commit the value.
| Need | File | Entry |
|---|---|---|
| Whole repo uses Sume | Project .cursor/mcp.json | URL only, OAuth |
| Only my machine | Global ~/.cursor/mcp.json | URL only, OAuth |
| API-key session | Global file or CI env | Bearer header from ${env:SUME_API_KEY} |
Check it works
Call tools_list once after connecting. If it shows only read tools, that is the default, not a fault.
Sources
Related posts
More in Developers
- Cut hold music from a call recording before STT: one concat job
Drop a hold-music stretch with one Sume timeline audio concat job that reuses the file twice via source_in and duration, then send the result to STT.
- Sume default queue capacity: max(3, 5 x concurrency), checked per plan
Sume's default queue capacity is max(3, concurrency x 5). Checking the rule against Free, Pro, Startup and Scale, plus the org floor and the wave hint.
- Deno: time out a Sume video submit, then retry with the same key
A fetch that times out may still have created a job. A 20-line Deno submit retries only 408, 429, 5xx and timeouts, always with one Idempotency-Key.
- Idempotency-Key from an order id and version, never a fresh uuid
A fresh uuid per request makes Idempotency-Key do nothing. Derive it from the order id plus a version you bump only to re-run. Scope: one Format, 255 chars.
Written by Sume