Gemini 0.63.0 auth loop fix for headless keyring: Sume key from env
Gemini CLI 0.63.0 fixed an infinite auth loop from a headless keyring. In CI, keep Sume's key in an environment variable and one header, not a keyring.

Use an API key from an environment variable for Sume in headless Gemini runs, because an OAuth sign-in needs a browser and a credential store. The v0.63.0 release notes list the fix "prevent infinite auth loop from file contention, headless keyring, and supervisor state drops", and the same release lists "enable autonomous plan execution in non-interactive mode". A non-interactive run with a key in a header has no interactive step to loop on.
What the release says
The Gemini facts come from the v0.63.0 release notes (read 2026-10-07). The Sume facts come from the OAuth page and Authentication.
Which one for CI
The table compares the two ways to authenticate with Sume's hosted MCP.
| Question | OAuth | API key |
|---|---|---|
| Needs a browser consent | Yes | No |
| Needs stored tokens between runs | Yes | No; read the key from the environment |
| Tools visible | mcp:read shows read-only tools; Write is opt-in | Full hosted tool set |
| Spend control | Wallet and admission | Wallet and admission |
| Header format | Bearer token from the client | Authorization: Bearer or x-api-key, one only |
Guard the unattended run
An API key puts spend in the hands of a script, so give a non-interactive run a short list of allowed steps. Have it call generation_admission_preview or send dry_run=true, set max_spend_usd, and send an idempotency_key built from your own job id.
Where the key lives
Keep the key in the secret store of your CI system and map it to an environment variable. Do not commit it to a settings file. If the key shows up in logs or chat history, rotate it in the dashboard.
Sources
Related posts
More in Integrations
- GitHub Actions weekly Sume bulk queue that fails on counts.failed
A scheduled workflow that creates a Sume bulk queue, polls it through transient 429 and 503, and turns a completed queue with failed items into a red job.
- Sume hosted MCP: API key or OAuth for an overnight agent job?
OAuth fits a person at a keyboard; an API key fits an unattended agent. How Sume hosted MCP treats each, plus the guardrails to set before you leave it running.
- Let an agent pick talking video, Fabric or H3 Max over MCP
Rules for an agent on hosted MCP: avatar-videos_create for scripts, avatar-image-to-video_create for audio, and dry_run plus max_spend_usd before any paid call.
- LinkedIn video ad needs an uploaded file, not a link: use the Sume MP4
LinkedIn's video ad spec says to upload the file, not link YouTube or Vimeo. How to take the MP4 from a Sume job, check it, and upload it.
Written by Sume