Devin Desktop ${file:} interpolation for the Sume API key
Devin Desktop expands ${file:/path} and ${env:NAME} in mcp_config.json. Put the Sume API key in a file outside the config; the 100-tool cap still applies.

Use ${file:} when you want the Sume API key to live in a file with its own permissions rather than in mcp_config.json. The Devin Desktop page says the config supports ${env:VAR_NAME} and ${file:/path/to/file} so that secrets are not hardcoded. A Sume entry then needs only the URL and one header, and the key is read from the path you name each time the config loads.
The entry
| Item | Devin Desktop page | Sume value |
|---|---|---|
| Config file | ~/.config/devin/mcp_config.json (or $XDG_CONFIG_HOME/devin/mcp_config.json); %APPDATA%\devin\mcp_config.json | Same file |
| Remote URL key | serverUrl or url, plus headers | https://mcp.sume.com/mcp |
| Interpolation | ${env:VAR_NAME} and ${file:/path/to/file} | Use for the API key |
| Tool cap | Cascade has a limit of 100 total tools | Sume's list varies with credential |
| Auth header | Any header | Authorization: Bearer or x-api-key |
{
"mcpServers": {
"sume": {
"serverUrl": "https://mcp.sume.com/mcp",
"headers": {
"Authorization": "Bearer ${file:/Users/me/.secrets/sume-key}"
}
}
}
}Details that bite
The key file should hold only the key. A trailing newline is a common cause of a 401 with a valid key, so write it with printf rather than echo, and check whether Devin Desktop trims whitespace before you assume it does; the page does not say.
Restrict the file to your user (mode 600 on macOS and Linux). Devin Desktop reads it as you, so tight permissions cost nothing, and they stop other local users and most backup tools from picking it up by accident.
Choose ${env:} instead when the key already comes from a secret manager that exports an environment variable. Choose ${file:} when the manager writes a file, as many container secret mounts do.
Tool count and credential
Cascade stops at 100 total tools across all your servers. Sume does not publish a fixed tool count, and the list depends on the credential: an API key sees the full set, while an OAuth session with only mcp:read hides write tools. If you hit the cap, switching Sume to a read-only OAuth session removes write tools from the list, which also lowers the number Cascade has to hold. Then call mcp_health to confirm which credential is live.
Write and paid calls need an idempotency_key whichever way the key is stored. Storing it in a file changes who can read it, not what it can spend.
Rotating the key
The practical benefit shows up at rotation. Create a new key in the dashboard, write it to the same file, and restart the MCP connection. The mcp_config.json file does not change, so it can be shared, backed up or committed as a template without a diff that contains a secret. Delete the old key in the dashboard once the new one works.
If more than one machine uses Sume, give each its own key. A single leaked laptop then costs one revocation instead of a team-wide rotation,.
Sources
Related posts
More in Integrations
- Gemini CLI authProviderType: connect Sume with dynamic_discovery
Gemini CLI defaults authProviderType to dynamic_discovery. For Sume that means OAuth discovery, not Google credentials. What each of the three values does.
- Does Copilot's MCP policy apply to Pro+ or Max? Sume hosted MCP
GitHub's MCP servers in Copilot policy covers Business and Enterprise, off by default. Free, Pro, Pro+ and Max users can add Sume's hosted MCP server directly.
- MCP spec: token in the header on every request, never the URL
The 2025-11-25 MCP spec forbids access tokens in the URL query string and wants a Bearer header on every request. Keep the Sume key in headers, not the URL.
- MCP spec: tool annotations are untrusted. What that means for Sume
The MCP spec says clients must treat tool annotations as untrusted unless they come from a trusted server. Treat Sume as trusted only for your own workspace.
Written by Sume