Gemini Enterprise per-user MCP credentials vs Sume OAuth and key
Gemini Enterprise's Oct 2 federated query uses MCP with each user's own credentials. Sume offers per-user OAuth with mcp:read or mcp:write, or a shared API key.

Google's Gemini Enterprise release notes for October 2, 2026 describe a federated query mode for Data Cloud connectors (AlloyDB, BigQuery, Cloud SQL and Spanner). It queries data in place using the Model Context Protocol and each user's own credentials. Sume's hosted MCP can follow the same per-user pattern through OAuth, or a shared API key if you prefer one identity.
The Google facts are from its release notes. The notes cover Data Cloud connectors, not Sume, so treat this as a design comparison.
Per-user versus shared
| Model | Who the server sees | Sume option |
|---|---|---|
| Federated query (Gemini Enterprise) | Each user's own credentials | OAuth: each user consents to mcp:read and optionally mcp:write |
| Shared service identity | One account for everyone | API key sent as Bearer or x-api-key |
| Read-only default | Cannot change data | mcp:read hides write and paid tools |
| Token lifetime | Set by the vendor | Sume access tokens last one hour, no refresh token |
Which identity should pay?
With OAuth, each user's own Sume account is the one that is charged, so spend follows the person. With a shared API key, one balance pays for everyone and you must meter use yourself. The OAuth docs describe consent and scopes, and authentication covers the key headers.
Pick OAuth when you want an audit trail by person. Pick a key when a backend job runs without anyone present.
Checklist
- Decide per workflow: per-user OAuth or a shared key.
- Start every user on
mcp:read. - Plan for token expiry; a one-hour token does not suit a long unattended job.
- Do not mix identities in one thread; the account that holds the token pays.
Sources
Related posts
More in Integrations
- GitHub Actions: generate a release-note image with the Sume Images API
A workflow that fires when a release is published, calls Sume's image endpoint with curl and jq, downloads the result and uploads it as a build artifact.
- Sheets 20 million cells: how many Sume jobs can a ledger hold?
Google Sheets doubled its cell limit to 20 million. Work out how many Sume job rows fit by column count, and why GET /v1/jobs stays the system of record.
- Sheets manual calculation: keep paid Sume calls out of formulas
Google Sheets can now pause automatic recalculation. Keep Sume job submits in a menu-driven Apps Script, not formulas, so a recalc never buys a render.
- GPT-6.1 Sol is in ChatGPT Work and Codex, not chat: attach Sume's MCP
OpenAI put GPT-6.1 Sol in ChatGPT Work and Codex rather than regular chat. Which of those surfaces can take Sume's hosted MCP server.
Written by Sume