FastMCP client auth: pass the Sume API key as a string
In FastMCP, pass your Sume API key as a plain string to auth, with no Bearer prefix. The client adds the header; send only one credential.

To authenticate a FastMCP client against Sume, pass your Sume API key as a plain string to auth and leave off the word Bearer. FastMCP adds the Bearer scheme for you, and Sume's hosted MCP endpoint accepts Authorization: Bearer <SUME_API_KEY>.
FastMCP facts are from its Bearer token page; Sume facts are from MCP OAuth and API keys and Authentication, read 2026-10-01.
How does the FastMCP client send a string token?
The FastMCP page says the most straightforward way to use an existing Bearer token is to give it as a string to the auth parameter of fastmcp.Client or a transport. It formats the value for the Authorization header and Bearer scheme, and it warns: if you use a string token, do not include the Bearer prefix.
Pointed at Sume, the key goes in as-is. mcp_health is a read tool that reports endpoint readiness and auth source, so it makes a cheap first call.
import asyncio
import os
from fastmcp import Client
async def main():
async with Client(
"https://mcp.sume.com/mcp",
auth=os.environ["SUME_API_KEY"],
) as client:
tools = await client.list_tools()
print(len(tools), "tools visible")
print(await client.call_tool("mcp_health", {}))
asyncio.run(main())What does Sume accept on the MCP endpoint?
The canonical endpoint is https://mcp.sume.com/mcp. Sume lists two ways to authenticate, and the string form maps to the API key row.
| Mode | How the client connects | What it can call |
|---|---|---|
| API key | Authorization: Bearer <SUME_API_KEY> or x-api-key | Full hosted tool set |
| OAuth | Client follows protected-resource metadata and first-party consent | mcp:read is read-only; Write on consent adds mcp:write |
Why must I send only one credential?
Sume rejects a request that carries both Authorization: Bearer and x-api-key with 401 unauthorized and the message Send only one API key credential. Neither header wins. If a gateway or fetch wrapper adds its own Authorization header on top of a client that already sends x-api-key, strip one of them.
How do I call a paid tool once the client is connected?
Paid and write tools require idempotency_key in the tool arguments. The docs describe it as a stable key for transport and dedup, not human approval. dry_run=true previews cost without submitting, and max_spend_usd is enforced only when you provide it. Fetch a tool's contract with tools_schema before you call it, then pass the same idempotency_key if you retry. For long renders, see MCP jobs_wait for long video jobs.
Sources
Related posts
More in Developers
- FFmpeg 8.1 AV1 and ProRes encoding: Sume has no codec field
FFmpeg 8.1 adds D3D12 H.264/AV1 and Vulkan ProRes encoding. Sume compiles ffmpeg server-side and rejects codec and crf fields, so you cannot pick an encoder.
- FFmpeg 8.1 drawvg and vpp_amf: not on Sume's allowlist
FFmpeg 8.1 lists new drawvg and vpp_amf filters. Sume video-filter only runs allowlisted filters and refuses unknown names with unknown_filter.
- Firefly Custom Models API vs Sume: references, no training
Firefly Custom Models trains subject or style models you call by asset ID. Sume offers no image model training; use up to 16 input references.
- Firefly Upscale API vs Sume's image_upscale_create tool
Firefly's Upscale API enhances resolution at 2x, 4x or 6x. Sume exposes upscaling as the image_upscale_create MCP tool: a paid job you poll.
Written by Sume