Sume hosted MCP: API key or OAuth for an overnight agent job?

OAuth fits a person at a keyboard; an API key fits an unattended agent. How Sume hosted MCP treats each, plus the guardrails to set before you leave it running.

4 min readSume
All posts

Use OAuth when a person is present to sign in and approve, and use an API key when an agent runs unattended. Sume's hosted MCP accepts both, and the Sume docs call OAuth the preferred path for interactive clients and API-key MCP the path for current automation. Whichever you choose, the guardrails for an overnight run are the same.

What each credential gives you

The two are not interchangeable: an OAuth token is not a Sume API key, and you cannot use one in place of the other.

Hosted MCP credentials (Sume docs, read 2026-10-07)
CredentialTools visibleFits
OAuth, mcp:read onlyRead-only toolsDiscovery and status checks
OAuth, read plus writeFull set, after you toggle Write on the consent pageA person-supervised session
API keyFull hosted tool setUnattended automation and CI

How to attach a key in Claude Code

Claude Code's docs show an authenticated HTTP server added with the --header flag, for example a Bearer header, and a --scope flag of local, project or user (read 2026-10-07). Sume accepts Authorization: Bearer <key> or x-api-key. Do not use project scope with a literal key in a committed file; keep the key in an environment variable your shell or CI provides. The hosted MCP endpoint is https://mcp.sume.com/mcp.

claude mcp add --transport http sume https://mcp.sume.com/mcp \
  --header "Authorization: Bearer $SUME_API_KEY"

Guardrails for an unattended run

  • Give every paid call a stable idempotency_key so a restart does not duplicate a render.
  • Preview with dry_run=true or generation_admission_preview before an expensive burst.
  • Set max_spend_usd on paid calls. Sume enforces it only when you provide it.
  • Use a key from a workspace with a funded but limited wallet, not your main one.
  • Prefer script_run for fan-out, with max_calls and max_paid_calls set.

Long jobs and the 55 second hold

A remote MCP call holds for at most 55 seconds. Video jobs take longer, so have the agent call jobs_wait, which accepts one job id or up to 20 and can wait for all or any. Treat a job that is still processing as normal. Do not submit the original paid request again just because a wait timed out (Jobs and results).

If the key leaks

Rotate it right away; the Sume docs say to rotate keys that appear in logs or chat history, which is one reason to keep them out of prompts. Create the replacement in the API keys page of the dashboard and give the new value to the agent.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume