Factory Droid MCP server: droid mcp add --type http for Sume
Add Sume's hosted MCP to Factory's droid CLI with droid mcp add --type http and an x-api-key header, why --no-oauth is needed, and where it is stored.

With Factory's droid CLI, add Sume using droid mcp add sume https://mcp.sume.com/mcp --type http --header "x-api-key: $SUME_API_KEY" --no-oauth. Factory's docs say OAuth is on by default for HTTP servers and that --no-oauth is the switch for header or API-key authentication (read 2026-10-02).
What Factory's page says
The Factory page's own x-api-key example is a different vendor's MCP server, but the header name is one Sume accepts too. Sume documents Authorization: Bearer <key> and x-api-key for API-key sessions (OAuth and API keys).
| Item | What Factory's docs say | For Sume |
|---|---|---|
| Command | droid mcp add <name> <url> --type http [--header ...] [--no-oauth] | sume and the hosted URL |
| OAuth | On by default; --no-oauth for header or API-key auth | --no-oauth with a key |
| CLI-added servers | Always go to the user config at ~/.factory/mcp.json | User config, not the repo |
| OAuth tokens | Stored in the system keyring, not per project | Applies only to the OAuth route |
Project .factory/mcp.json | Do not commit secrets there | Keep the key out of it |
droid mcp add sume https://mcp.sume.com/mcp --type http \
--header "x-api-key: $SUME_API_KEY" \
--no-oauthWhy --no-oauth matters for Sume
Sume's hosted OAuth is read-only by default: mcp:read is required, and the Write toggle on the consent page, which is off by default, adds mcp:write (MCP OAuth and API keys). Sume's docs describe that flow for Cursor, Claude Code and Codex, and they do not cover droid. If droid tried OAuth against a key setup, it would be a different credential path from the one you meant to test.
With --no-oauth and a key header the session is an API-key session, which sees the full tool set. That includes paid tools, so decide whether you want that before you add the server.
Checking the connection and keeping it safe
Factory says the /mcp command completes browser OAuth flows; with a key you do not need that step. Ask droid to call mcp_health and confirm the auth source is an API key, then tools_list.
For paid calls, tell the agent to run dry_run=true first and to pass max_spend_usd. Sume requires an idempotency_key on paid and write tools, and says it is for transport and deduplication, not human approval (MCP tools and gates). So the approval has to come from you or from droid's own prompts.
When to use OAuth instead
If you want read-only discovery without a stored key, omit --no-oauth and check whether droid completes Sume's sign-in. I have not verified that flow, and Sume's docs do not list it, so confirm that mcp_health shows an OAuth auth source before relying on it. If sign-in does not complete, return to the key route and keep the file at ~/.factory/mcp.json.
Sources
Related posts
More in Integrations
- Fastify 5 raw body for a Sume webhook: parseAs string
Fastify parses JSON before your handler, which breaks HMAC checks. Use parseAs string, then verify sume-v1 and dedupe. Tested on Fastify 5.12.5.
- Flowise Custom MCP: connect Sume over Streamable HTTP
Add Sume to a Flowise Agent node as a Custom MCP tool: a url, an Authorization header from a $vars variable, then refresh Available Actions.
- Gemini CLI excludeTools: hide paid Sume tools from the agent
Use includeTools and excludeTools in Gemini CLI settings.json to give an API-key Sume session only read tools, since excludeTools wins over includeTools.
- Gemini CLI headless: ask_user acts as deny, so paid Sume calls skip
In Gemini CLI non-interactive mode a policy of ask_user is treated as deny. A paid Sume call then never runs, so allow it narrowly or use an API-key script.
Written by Sume