Sume hosted MCP: API key or OAuth for an overnight agent job?
OAuth fits a person at a keyboard; an API key fits an unattended agent. How Sume hosted MCP treats each, plus the guardrails to set before you leave it running.

Use OAuth when a person is present to sign in and approve, and use an API key when an agent runs unattended. Sume's hosted MCP accepts both, and the Sume docs call OAuth the preferred path for interactive clients and API-key MCP the path for current automation. Whichever you choose, the guardrails for an overnight run are the same.
What each credential gives you
The two are not interchangeable: an OAuth token is not a Sume API key, and you cannot use one in place of the other.
| Credential | Tools visible | Fits |
|---|---|---|
| OAuth, mcp:read only | Read-only tools | Discovery and status checks |
| OAuth, read plus write | Full set, after you toggle Write on the consent page | A person-supervised session |
| API key | Full hosted tool set | Unattended automation and CI |
How to attach a key in Claude Code
Claude Code's docs show an authenticated HTTP server added with the --header flag, for example a Bearer header, and a --scope flag of local, project or user (read 2026-10-07). Sume accepts Authorization: Bearer <key> or x-api-key. Do not use project scope with a literal key in a committed file; keep the key in an environment variable your shell or CI provides. The hosted MCP endpoint is https://mcp.sume.com/mcp.
claude mcp add --transport http sume https://mcp.sume.com/mcp \
--header "Authorization: Bearer $SUME_API_KEY"Guardrails for an unattended run
- Give every paid call a stable
idempotency_keyso a restart does not duplicate a render. - Preview with
dry_run=trueorgeneration_admission_previewbefore an expensive burst. - Set
max_spend_usdon paid calls. Sume enforces it only when you provide it. - Use a key from a workspace with a funded but limited wallet, not your main one.
- Prefer
script_runfor fan-out, withmax_callsandmax_paid_callsset.
Long jobs and the 55 second hold
A remote MCP call holds for at most 55 seconds. Video jobs take longer, so have the agent call jobs_wait, which accepts one job id or up to 20 and can wait for all or any. Treat a job that is still processing as normal. Do not submit the original paid request again just because a wait timed out (Jobs and results).
If the key leaks
Rotate it right away; the Sume docs say to rotate keys that appear in logs or chat history, which is one reason to keep them out of prompts. Create the replacement in the API keys page of the dashboard and give the new value to the agent.
Sources
Related posts
More in Integrations
- Let an agent pick talking video, Fabric or H3 Max over MCP
Rules for an agent on hosted MCP: avatar-videos_create for scripts, avatar-image-to-video_create for audio, and dry_run plus max_spend_usd before any paid call.
- n8n 2.43.0: resume agents after waiting workflows, with Sume runs
n8n 2.43.0 (pre-release, Oct 6) resumes Preview agents after waiting workflows finish. Pair a long Sume run with one webhook, deduped on request_id.
- OpenClaw still lists sora-2 as a configured video provider: fix it
OpenClaw issue 158876: the bundled OpenAI video provider still defaults to sora-2, though /v1/videos returns 404. What to do now, and a Sume video call.
- Plan in Claude Code over MCP, then hand the batch to bulk runs
Use Claude Code with Sume's hosted MCP to prototype one video and read costs, then run the real batch from your backend with Format bulk runs and a spend cap.
Written by Sume