Cursor remote MCP has no envFile: where the Sume key goes

Cursor's envFile works for stdio servers only. For Sume's remote MCP, read the key from your shell with a headers entry, or skip keys and use OAuth.

4 min readSume
All posts

If you connect Cursor to Sume's remote MCP server with an API key, put the key in your shell environment and reference it as ${env:SUME_API_KEY} in the headers field, because Cursor's envFile option is for stdio servers only. If you do not need a key, connect with OAuth and leave mcp.json with just the URL.

Cursor's MCP page (read 2026-10-10) says it directly: envFile is only available for STDIO servers, and remote servers cannot use environment files, so variables go in your shell profile. Sume's hosted endpoint is a remote HTTP server, so that rule applies to it.

What Cursor reads for a remote server

The page lists three fields for remote servers: url, headers (which supports variable interpolation) and auth, a static OAuth credentials object. For interpolation it names ${env:NAME}, ${userHome}, ${workspaceFolder} and ${workspaceFolderBasename}.

Sume accepts an API key as Authorization: Bearer <SUME_API_KEY> or as x-api-key. Combine the two and the header block has one line that holds no secret.

{
  "mcpServers": {
    "sume": {
      "url": "https://mcp.sume.com/mcp",
      "headers": {
        "Authorization": "Bearer ${env:SUME_API_KEY}"
      }
    }
  }
}

Three ways to authenticate, compared

Pick by how the session will be used, not by habit. An interactive coding session is best served by OAuth, and a scheduled or headless run by a key. The static auth object in Cursor is meant for providers that require you to register a redirect first, and the Cursor page gives Figma and Linear as examples. Sume's own quickstart config has only a url, so you do not need a static client to use Sume.

Cursor MCP docs and Sume MCP docs, read 2026-10-10
MethodWhere the secret livesSume tools visible
OAuth, URL onlyCursor stores the grant after sign-inRead-only by default; Write is a toggle on the consent page
headers with ${env:SUME_API_KEY}Your shell profileFull hosted tool set
Literal key in mcp.jsonThe file, and maybe gitFull set, with the key exposed: avoid
envFileNot available for remote serversNot applicable

Shell profile gotchas

Because the value comes from your shell, the app must be started from an environment that has it. A desktop app launched from the dock may not inherit variables you export in a terminal profile, so a header can resolve to an empty string and Sume will answer 401. Restart Cursor from a shell that has the variable, or set it where your OS exposes it to GUI apps.

Check the result with a read-only call. Ask the agent to run mcp_health and read authenticated.auth_source, then account_me. If both work, the key reached Sume. After that, tools_list should show write and paid tools, because Sume's docs say an API-key session sees the full hosted set.

Keep approvals on for paid tools

Cursor prompts before MCP tool calls by default, and the page says that in Auto-review mode allowlisted tools run immediately. Do not allowlist Sume's paid tools. Sume's docs state that idempotency_key is transport and dedup, not human approval, so the approval prompt in the editor is the only human gate you have.

Before an expensive burst, ask for dry_run=true or generation_admission_preview, which preview cost and admission without submitting. A call that sets max_spend_usd has it enforced, and a call that omits it has no cap from that field.

  • Use one key per machine so a leak is a one-key revoke.
  • Never allowlist generate_video or other paid tools.
  • Rotate any key that appears in chat history or logs.
  • Use OAuth read-only for exploration.

When to choose OAuth instead

OAuth removes the whole variable problem. Cursor stores the grant, the file holds only the URL, and the consent page on the MCP host has a Write toggle that is off by default. That is the right shape for a person exploring Sume from an editor. The Cursor page lists two redirect URLs for providers that need them registered: a web one on cursor.com and a desktop one at http://localhost:8787/callback. Sume's quickstart does not ask you to register either, so use them only if a sign-in fails on a redirect and you were told to.

Choose a key when nobody will be at the keyboard to click a consent page, for example a scheduled agent run. Then the key must be present in the environment that runs it, and the headers line above does the work.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume