FastMCP client auth: pass the Sume API key as a string

In FastMCP, pass your Sume API key as a plain string to auth, with no Bearer prefix. The client adds the header; send only one credential.

4 min readSume
All posts

To authenticate a FastMCP client against Sume, pass your Sume API key as a plain string to auth and leave off the word Bearer. FastMCP adds the Bearer scheme for you, and Sume's hosted MCP endpoint accepts Authorization: Bearer <SUME_API_KEY>.

FastMCP facts are from its Bearer token page; Sume facts are from MCP OAuth and API keys and Authentication, read 2026-10-01.

How does the FastMCP client send a string token?

The FastMCP page says the most straightforward way to use an existing Bearer token is to give it as a string to the auth parameter of fastmcp.Client or a transport. It formats the value for the Authorization header and Bearer scheme, and it warns: if you use a string token, do not include the Bearer prefix.

Pointed at Sume, the key goes in as-is. mcp_health is a read tool that reports endpoint readiness and auth source, so it makes a cheap first call.

import asyncio
import os

from fastmcp import Client


async def main():
    async with Client(
        "https://mcp.sume.com/mcp",
        auth=os.environ["SUME_API_KEY"],
    ) as client:
        tools = await client.list_tools()
        print(len(tools), "tools visible")
        print(await client.call_tool("mcp_health", {}))


asyncio.run(main())

What does Sume accept on the MCP endpoint?

The canonical endpoint is https://mcp.sume.com/mcp. Sume lists two ways to authenticate, and the string form maps to the API key row.

Hosted MCP auth modes from the Sume docs, read 2026-10-01: https://docs.sume.com/mcp/oauth
ModeHow the client connectsWhat it can call
API keyAuthorization: Bearer <SUME_API_KEY> or x-api-keyFull hosted tool set
OAuthClient follows protected-resource metadata and first-party consentmcp:read is read-only; Write on consent adds mcp:write

Why must I send only one credential?

Sume rejects a request that carries both Authorization: Bearer and x-api-key with 401 unauthorized and the message Send only one API key credential. Neither header wins. If a gateway or fetch wrapper adds its own Authorization header on top of a client that already sends x-api-key, strip one of them.

How do I call a paid tool once the client is connected?

Paid and write tools require idempotency_key in the tool arguments. The docs describe it as a stable key for transport and dedup, not human approval. dry_run=true previews cost without submitting, and max_spend_usd is enforced only when you provide it. Fetch a tool's contract with tools_schema before you call it, then pass the same idempotency_key if you retry. For long renders, see MCP jobs_wait for long video jobs.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume