Cursor remote MCP has no envFile: where the Sume key goes
Cursor's envFile works for stdio servers only. For Sume's remote MCP, read the key from your shell with a headers entry, or skip keys and use OAuth.

If you connect Cursor to Sume's remote MCP server with an API key, put the key in your shell environment and reference it as ${env:SUME_API_KEY} in the headers field, because Cursor's envFile option is for stdio servers only. If you do not need a key, connect with OAuth and leave mcp.json with just the URL.
Cursor's MCP page (read 2026-10-10) says it directly: envFile is only available for STDIO servers, and remote servers cannot use environment files, so variables go in your shell profile. Sume's hosted endpoint is a remote HTTP server, so that rule applies to it.
What Cursor reads for a remote server
The page lists three fields for remote servers: url, headers (which supports variable interpolation) and auth, a static OAuth credentials object. For interpolation it names ${env:NAME}, ${userHome}, ${workspaceFolder} and ${workspaceFolderBasename}.
Sume accepts an API key as Authorization: Bearer <SUME_API_KEY> or as x-api-key. Combine the two and the header block has one line that holds no secret.
{
"mcpServers": {
"sume": {
"url": "https://mcp.sume.com/mcp",
"headers": {
"Authorization": "Bearer ${env:SUME_API_KEY}"
}
}
}
}Three ways to authenticate, compared
Pick by how the session will be used, not by habit. An interactive coding session is best served by OAuth, and a scheduled or headless run by a key. The static auth object in Cursor is meant for providers that require you to register a redirect first, and the Cursor page gives Figma and Linear as examples. Sume's own quickstart config has only a url, so you do not need a static client to use Sume.
| Method | Where the secret lives | Sume tools visible |
|---|---|---|
| OAuth, URL only | Cursor stores the grant after sign-in | Read-only by default; Write is a toggle on the consent page |
headers with ${env:SUME_API_KEY} | Your shell profile | Full hosted tool set |
Literal key in mcp.json | The file, and maybe git | Full set, with the key exposed: avoid |
envFile | Not available for remote servers | Not applicable |
Shell profile gotchas
Because the value comes from your shell, the app must be started from an environment that has it. A desktop app launched from the dock may not inherit variables you export in a terminal profile, so a header can resolve to an empty string and Sume will answer 401. Restart Cursor from a shell that has the variable, or set it where your OS exposes it to GUI apps.
Check the result with a read-only call. Ask the agent to run mcp_health and read authenticated.auth_source, then account_me. If both work, the key reached Sume. After that, tools_list should show write and paid tools, because Sume's docs say an API-key session sees the full hosted set.
Keep approvals on for paid tools
Cursor prompts before MCP tool calls by default, and the page says that in Auto-review mode allowlisted tools run immediately. Do not allowlist Sume's paid tools. Sume's docs state that idempotency_key is transport and dedup, not human approval, so the approval prompt in the editor is the only human gate you have.
Before an expensive burst, ask for dry_run=true or generation_admission_preview, which preview cost and admission without submitting. A call that sets max_spend_usd has it enforced, and a call that omits it has no cap from that field.
- Use one key per machine so a leak is a one-key revoke.
- Never allowlist
generate_videoor other paid tools. - Rotate any key that appears in chat history or logs.
- Use OAuth read-only for exploration.
When to choose OAuth instead
OAuth removes the whole variable problem. Cursor stores the grant, the file holds only the URL, and the consent page on the MCP host has a Write toggle that is off by default. That is the right shape for a person exploring Sume from an editor. The Cursor page lists two redirect URLs for providers that need them registered: a web one on cursor.com and a desktop one at http://localhost:8787/callback. Sume's quickstart does not ask you to register either, so use them only if a sign-in fails on a redirect and you were told to.
Choose a key when nobody will be at the keyboard to click a consent page, for example a scheduled agent run. Then the key must be present in the environment that runs it, and the headers line above does the work.
Sources
Related posts
More in Integrations
- Docker Agent YAML: add Sume as a remote MCP toolset
Docker Agent takes a remote MCP URL, headers and a tools allowlist. Here is the Sume entry with a Bearer key from the environment and a read-only tool list.
- Framer looping video: keep it under 5 MB, Framer won't compress
Framer says keep looping videos under 5 MB, uses H.264 MP4, and serves a 4K upload at full size. Render and trim a Sume clip small before you upload.
- Freshdesk Trigger Webhook: 1000 calls an hour and Sume bulk runs
Freshdesk automations cap webhook calls at 1000 an hour and retry failures every 30 minutes. Here is how a relay maps ticket bursts onto Sume bulk runs.
- Gemini CLI 63-character tool names: Sume's longest is 45
Gemini CLI truncates MCP tool names over 63 characters. Checked against Sume's tool list, the longest becomes 45, so nothing is cut.
Written by Sume