fastmcp-remote: connect a stdio-only MCP host to Sume's hosted MCP
FastMCP 3.4.0 added fastmcp-remote, a bridge from stdio-only hosts to HTTP servers with OAuth for HTTPS. Point it at mcp.sume.com/mcp, verify with mcp_health.

If your MCP host can only start local stdio servers, use a bridge such as fastmcp-remote to reach Sume's hosted server at https://mcp.sume.com/mcp. FastMCP's updates page describes it as a standalone bridge that connects stdio-only MCP hosts to servers hosted over HTTP, with OAuth enabled automatically for HTTPS, and lists it under FastMCP 3.4.0 "Remote Control" dated June 2, 2026. Check the FastMCP page for the exact command; this post does not guess flags.
What FastMCP says
The same page lists FastMCP 4.0.11 "Fort Knocks" on October 4, 2026, as a release with important security and bug fixes that all users are encouraged to upgrade to (FastMCP updates, read 2026-10-07).
What Sume expects from the other side
Sume documents the hosted endpoint as the supported remote MCP connector. It speaks streamable HTTP, uses OAuth with PKCE for interactive clients, and also accepts an API key. A stdio-only host cannot do that on its own, which is the gap a bridge fills.
| Item | Sume's value |
|---|---|
| Endpoint | https://mcp.sume.com/mcp |
| OAuth metadata | https://mcp.sume.com/.well-known/oauth-protected-resource/mcp |
| Authorization page | https://mcp.sume.com/oauth/authorize, then consent on the MCP host |
| Scopes | mcp:read required, mcp:write opt-in, no mcp:paid |
| API-key headers | Authorization: Bearer or x-api-key, one of them |
OAuth or API key
Choose one path and keep it:
- OAuth through the bridge: sign in once in the browser, leave Write off until you need renders.
- API key: set it as one header only. Sending both
Authorizationandx-api-keyis a conflict on Sume's REST API, so do not stack headers from the bridge and the host.
Verify the bridge
After the bridge connects, ask the agent to call mcp_health, then tools_list. The first confirms the endpoint and the auth source; the second shows the tools your credential can see. A read-only OAuth session lists only read-only tools. Paid calls still need an idempotency_key, and dry_run plus max_spend_usd apply the same way through a bridge.
Timeouts through a bridge
Bridges add a hop, and a long jobs_wait is one HTTP request that stays open for up to 55 seconds. Keep the host's tool timeout above that, and wait again instead of asking for longer. The Jobs and results page explains why.
Sources
Related posts
More in Integrations
- Forward a finished Sume run to team chat with a signed webhook
A standard-library Python receiver that verifies the sume-v1 signature, rejects an empty secret, and forwards primary_output_url when a Format run ends.
- Gemini 0.63.0 auth loop fix for headless keyring: Sume key from env
Gemini CLI 0.63.0 fixed an infinite auth loop from a headless keyring. In CI, keep Sume's key in an environment variable and one header, not a keyring.
- GitHub Actions weekly Sume bulk queue that fails on counts.failed
A scheduled workflow that creates a Sume bulk queue, polls it through transient 429 and 503, and turns a completed queue with failed items into a red job.
- Sume hosted MCP: API key or OAuth for an overnight agent job?
OAuth fits a person at a keyboard; an API key fits an unattended agent. How Sume hosted MCP treats each, plus the guardrails to set before you leave it running.
Written by Sume