fastmcp-remote: connect a stdio-only MCP host to Sume's hosted MCP

FastMCP 3.4.0 added fastmcp-remote, a bridge from stdio-only hosts to HTTP servers with OAuth for HTTPS. Point it at mcp.sume.com/mcp, verify with mcp_health.

4 min readSume
All posts

If your MCP host can only start local stdio servers, use a bridge such as fastmcp-remote to reach Sume's hosted server at https://mcp.sume.com/mcp. FastMCP's updates page describes it as a standalone bridge that connects stdio-only MCP hosts to servers hosted over HTTP, with OAuth enabled automatically for HTTPS, and lists it under FastMCP 3.4.0 "Remote Control" dated June 2, 2026. Check the FastMCP page for the exact command; this post does not guess flags.

What FastMCP says

The same page lists FastMCP 4.0.11 "Fort Knocks" on October 4, 2026, as a release with important security and bug fixes that all users are encouraged to upgrade to (FastMCP updates, read 2026-10-07).

What Sume expects from the other side

Sume documents the hosted endpoint as the supported remote MCP connector. It speaks streamable HTTP, uses OAuth with PKCE for interactive clients, and also accepts an API key. A stdio-only host cannot do that on its own, which is the gap a bridge fills.

What the bridge has to match on Sume's side (read 2026-10-07)
ItemSume's value
Endpointhttps://mcp.sume.com/mcp
OAuth metadatahttps://mcp.sume.com/.well-known/oauth-protected-resource/mcp
Authorization pagehttps://mcp.sume.com/oauth/authorize, then consent on the MCP host
Scopesmcp:read required, mcp:write opt-in, no mcp:paid
API-key headersAuthorization: Bearer or x-api-key, one of them

OAuth or API key

Choose one path and keep it:

  • OAuth through the bridge: sign in once in the browser, leave Write off until you need renders.
  • API key: set it as one header only. Sending both Authorization and x-api-key is a conflict on Sume's REST API, so do not stack headers from the bridge and the host.

Verify the bridge

After the bridge connects, ask the agent to call mcp_health, then tools_list. The first confirms the endpoint and the auth source; the second shows the tools your credential can see. A read-only OAuth session lists only read-only tools. Paid calls still need an idempotency_key, and dry_run plus max_spend_usd apply the same way through a bridge.

Timeouts through a bridge

Bridges add a hop, and a long jobs_wait is one HTTP request that stays open for up to 55 seconds. Keep the host's tool timeout above that, and wait again instead of asking for longer. The Jobs and results page explains why.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume