How to add MCP to Devin: connect Sume's hosted server

Add a custom MCP server to Devin in Customize > MCPs: HTTP transport, Sume's hosted MCP URL, an Authorization header or OAuth, then Test tools.

5 min readSume
All posts

To add an MCP server to Devin, go to Customize > MCPs, open Add MCP, choose Add custom MCP, name the server, select the HTTP transport, enter the Server URL and an authentication method, and click Save. Then click Test tools on the server's page. Adding a custom server needs the Manage MCP Servers permission. For Sume's hosted MCP server, the URL is https://mcp.sume.com/mcp, and the authentication is an Authorization header with Bearer and a Sume API key, or OAuth.

Devin's side comes from Devin MCP servers and marketplace; Sume's side comes from MCP OAuth and API keys, MCP quickstart, MCP tools and gates, and Jobs and results, all read on 2026-09-28. Sume has no official Devin integration or marketplace plugin: Devin connects to Sume's remote MCP server as a custom MCP, and Sume's basics page says hosted MCP still works but is not part of the primary path today. This post covers Devin's web app; for the desktop IDE, see Windsurf MCP server: add Sume's hosted MCP in Devin Desktop.

How do I add a custom MCP server in Devin?

MCP servers live on the Customize > MCPs tab at the personal, organization, or enterprise scope; the older Settings > Connections > MCP servers page redirects there. If you don't see Add custom MCP, contact your organization admin or use Suggest MCP Integration. Devin also takes stdio and SSE servers, but its docs recommend HTTP, which is Streamable HTTP, for new integrations and call SSE legacy.

From Devin's Devin MCP servers and marketplace and Sume's MCP OAuth and API keys, read 2026-09-28.
FieldWhat Devin's docs sayFor Sume
Server Name, Short DescriptionA descriptive name and a brief summary; an icon is optional.Sume, image and video tools
TransportSTDIO, SSE, or HTTP (Streamable HTTP).HTTP
Server URLRequired: the endpoint URL of the MCP server.https://mcp.sume.com/mcp
Authentication methodNone, Auth Header, or OAuth.Auth Header, or OAuth
Auth HeaderHeader key defaults to Authorization; value such as Bearer your-token.Authorization: Bearer <your Sume API key>
Access (OAuth only)Organization: every member shares one connection. Personal: each member signs in.Personal, or Organization with a service account

Should Devin use an API key or OAuth for Sume?

An API key is the simpler fit, with one catch: every session that uses the server calls Sume with that key. A key session sees Sume's full hosted tool set, paid tools included, and spend resolves to the key's workspace, so one Sume workspace pays for everyone's calls. Rotate the key if it appears in logs or chat history.

For OAuth, save the server, then choose Connect in Customize > MCPs and complete the sign-in in your browser. Devin's fields for your own client ID and secret are for providers without dynamic client registration; Sume's current server advertises registration and accepts only public clients, so there is no client secret to enter. Consent happens on Sume's MCP host with Read locked on and Write off by default, and a read-only session gets insufficient_scope from paid tools such as generate_image. In Sume's current code the token lasts one hour with no refresh token, so expect to reconnect about hourly.

With Organization access, Devin recommends connecting a service account rather than your personal account, since every member's sessions use it. With Personal access, Devin notes that other users can still interact with your sessions, so it is not a security boundary.

How do I keep Devin from spending on paid tools?

Devin's MCP page describes no per-tool approval step, so put the rules in the session instructions and rely on Sume's gates. Each paid call needs an idempotency_key, dry_run=true previews admission and cost without submitting the job, and max_spend_usd caps a call only when it is sent. For read-only work, such as checking jobs or the catalog, an OAuth connection with Write off can't start paid jobs at all. Sume MCP tools list groups the hosted tools by read, write, and paid.

Renders are waited out in slices: jobs_wait holds one call for at most 55 seconds, and on wait_slice_expired Devin should call it again with the same ids and never resubmit the paid create.

What if Test tools fails?

Read the message: Devin says it tells you whether the problem is connectivity, authentication, or a timeout.

  • Verify server URL and network connectivity: the URL is unreachable. Check it is exactly https://mcp.sume.com/mcp.
  • Check authentication credentials and permissions: invalid or missing credentials. Check the header value starts with Bearer and the key hasn't been revoked.
  • Server took too long to respond - check server status: no answer within the timeout.
  • MCP server validation failed: the server returned an error while listing tools.
  • Once it passes, start a session and ask Devin to call mcp_health, which confirms the endpoint, auth source, and safety posture.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume