Factory Droid MCP server: droid mcp add --type http for Sume

Add Sume's hosted MCP to Factory's droid CLI with droid mcp add --type http and an x-api-key header, why --no-oauth is needed, and where it is stored.

5 min readSume
All posts

With Factory's droid CLI, add Sume using droid mcp add sume https://mcp.sume.com/mcp --type http --header "x-api-key: $SUME_API_KEY" --no-oauth. Factory's docs say OAuth is on by default for HTTP servers and that --no-oauth is the switch for header or API-key authentication (read 2026-10-02).

What Factory's page says

The Factory page's own x-api-key example is a different vendor's MCP server, but the header name is one Sume accepts too. Sume documents Authorization: Bearer <key> and x-api-key for API-key sessions (OAuth and API keys).

droid MCP behavior, read 2026-10-02 from Factory's docs; the last column is the Sume value.
ItemWhat Factory's docs sayFor Sume
Commanddroid mcp add <name> <url> --type http [--header ...] [--no-oauth]sume and the hosted URL
OAuthOn by default; --no-oauth for header or API-key auth--no-oauth with a key
CLI-added serversAlways go to the user config at ~/.factory/mcp.jsonUser config, not the repo
OAuth tokensStored in the system keyring, not per projectApplies only to the OAuth route
Project .factory/mcp.jsonDo not commit secrets thereKeep the key out of it
droid mcp add sume https://mcp.sume.com/mcp --type http \
  --header "x-api-key: $SUME_API_KEY" \
  --no-oauth

Why --no-oauth matters for Sume

Sume's hosted OAuth is read-only by default: mcp:read is required, and the Write toggle on the consent page, which is off by default, adds mcp:write (MCP OAuth and API keys). Sume's docs describe that flow for Cursor, Claude Code and Codex, and they do not cover droid. If droid tried OAuth against a key setup, it would be a different credential path from the one you meant to test.

With --no-oauth and a key header the session is an API-key session, which sees the full tool set. That includes paid tools, so decide whether you want that before you add the server.

Checking the connection and keeping it safe

Factory says the /mcp command completes browser OAuth flows; with a key you do not need that step. Ask droid to call mcp_health and confirm the auth source is an API key, then tools_list.

For paid calls, tell the agent to run dry_run=true first and to pass max_spend_usd. Sume requires an idempotency_key on paid and write tools, and says it is for transport and deduplication, not human approval (MCP tools and gates). So the approval has to come from you or from droid's own prompts.

When to use OAuth instead

If you want read-only discovery without a stored key, omit --no-oauth and check whether droid completes Sume's sign-in. I have not verified that flow, and Sume's docs do not list it, so confirm that mcp_health shows an OAuth auth source before relying on it. If sign-in does not complete, return to the key route and keep the file at ~/.factory/mcp.json.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume