Jan app MCP server: connect Sume over Streamable HTTP and OAuth
Jan can connect to a remote MCP server over Streamable HTTP and sign in with OAuth and PKCE. How that maps onto Sume's hosted MCP endpoint and its scopes.

Jan supports remote MCP servers over Streamable HTTP or SSE, and its Sign in action runs OAuth against the server with PKCE. That maps directly onto Sume: add https://mcp.sume.com/mcp as an HTTP server in Jan, sign in, and approve read access on the Sume consent page.
The details that matter are the order of operations and the scope you grant, because Sume's default OAuth grant is read-only.
How does Jan connect to a remote MCP server?
Per Jan's MCP Servers page, the connection types are local STDIO, HTTP (Streamable HTTP) and SSE. Choose HTTP for Sume and give it the URL:
https://mcp.sume.com/mcpWhat happens when you click Sign in?
Jan's page describes the flow: Jan discovers the server's OAuth metadata, registers itself dynamically, and completes an authorization-code flow with PKCE, opening your browser. Sume publishes protected-resource metadata from the MCP endpoint, and its authorization metadata lists a registration endpoint on the MCP host, so a dynamically registering client has what it needs. The Sume OAuth page lists the metadata URLs:
https://mcp.sume.com/.well-known/oauth-protected-resource/mcp
https://mcp.sume.com/.well-known/oauth-authorization-serverWhich scope should you grant?
The consent page lives on the MCP host, not on app.sume.com. It shows Read locked on and a Write toggle that is off by default. There is no mcp:paid scope: paid calls are governed by your wallet and by the idempotency_key each paid call requires.
Start with Read only. Ask Jan's assistant to call tools_list and account_me. If you later want it to generate, sign in again with Write on, or use an API key session, which sees the full tool set.
| Grant | Visible tools | Paid call result |
|---|---|---|
OAuth mcp:read | Read-only tools | insufficient_scope |
OAuth mcp:read + mcp:write | Mutating and paid tools | Runs with idempotency_key |
| API key | Full hosted set | Runs with idempotency_key |
What does Jan not give you?
Jan's page does not say how to send a static header to a remote server in the interface, so the OAuth path is the documented one for Sume. If you need an API key session, confirm in your Jan version whether a header field exists before relying on it.
Sume also does not read files from your machine over hosted MCP. To use a local image or clip, the assistant has to create an upload URL, your client PUTs the bytes, and assets_complete finishes the upload, as the tools page describes.
What is a good first check?
Ask for mcp_health and look for authenticated.auth_source equal to mcp_oauth. Then run catalog_list, which shows public API capabilities (broader than the MCP tool list). If a read tool works and a paid tool says insufficient_scope, the connection is healthy and simply read-only.
What if sign-in does not complete?
Work through the browser steps rather than retrying the connection blindly. The consent page is on mcp.sume.com, and it needs a Sume sign-in. If you are already signed in to the app, you still land on the MCP host's own consent page. A second sign-in attempt replaces the first, so closing a stale tab and starting over is safe.
Sume accepts redirect addresses over https and loopback http (localhost or 127.0.0.1), which is how desktop apps typically receive the code. If a client sends some other scheme, the authorization request is rejected as an invalid redirect. That is a client-side issue, not an account one.
Does OAuth expire?
Access tokens are short-lived. When one lapses, Jan has to refresh or you sign in again, and until then tool calls fail with an authentication error rather than a scope error. Jobs you already submitted are unaffected, because they run on Sume's side and are read back by id with jobs_status once you reconnect.
Sources
Related posts
More in Integrations
- JetBrains AI Assistant MCP server: add Sume with a url entry
Add Sume's hosted MCP server to JetBrains AI Assistant: the Settings path, the url JSON, global or project scope, and what the page leaves unsaid about auth.
- Kimi Code CLI MCP: kimi mcp add --transport http for Sume
Add Sume's hosted MCP to Kimi Code CLI with kimi mcp add --transport http, finish OAuth with kimi mcp auth, and verify with kimi mcp test.
- Lambda 1,000 concurrency and Sume webhook bursts finishing together
Jobs from one bulk queue often finish together. Lambda starts at 1,000 concurrent executions, lower on new accounts. Here is how Sume's retries absorb a burst.
- Lambda async 1 MB limit vs Sume's 1 MiB run webhook overflow
Lambda takes 1 MB for async events and 6 MB sync. Sume sends a run webhook inline up to 1 MiB, then payload null. Forward the id, not the receipt.
Written by Sume