Kimi Code CLI MCP: kimi mcp add --transport http for Sume

Add Sume's hosted MCP to Kimi Code CLI with kimi mcp add --transport http, finish OAuth with kimi mcp auth, and verify with kimi mcp test.

5 min readSume
All posts

To add Sume to Kimi Code CLI, run kimi mcp add --transport http --auth oauth sume https://mcp.sume.com/mcp, then kimi mcp auth sume to finish the browser sign-in, and kimi mcp test sume to check it.

These commands come from the Kimi Code CLI MCP page. The Sume side is the standard hosted endpoint and OAuth flow from the Sume docs.

What are the exact commands?

Add the server, authorize it, then confirm it:

kimi mcp add --transport http --auth oauth sume https://mcp.sume.com/mcp
kimi mcp auth sume
kimi mcp test sume
kimi mcp list

What does each command do?

The Kimi page describes kimi mcp list as showing configured servers, kimi mcp auth <name> as completing OAuth authorization in the browser, kimi mcp test <name> as verifying connectivity, and kimi mcp remove <name> as deleting the entry. Servers are stored in ~/.kimi/mcp.json, and you can point at another file with --mcp-config-file or pass inline JSON with --mcp-config.

Kimi MCP commands, read 2026-10-02
CommandPurposeSume step it covers
kimi mcp add --transport httpRegister a remote serverEndpoint https://mcp.sume.com/mcp
kimi mcp auth sumeBrowser OAuthConsent on the MCP host
kimi mcp test sumeConnectivity checkServer reachable and authorized
kimi mcp listShow serversConfirm the sume entry

Can you use an API key instead of OAuth?

The Kimi page documents a --header option for HTTP servers with the format KEY: value, with a space after the colon. Sume accepts x-api-key or a bearer Authorization header, so an automation setup can look like this:

kimi mcp add --transport http sume https://mcp.sume.com/mcp \
  --header "x-api-key: $SUME_API_KEY"

What should you check after connecting?

Ask Kimi to call mcp_health; with OAuth the auth source is mcp_oauth. Then tools_list. A default OAuth grant is mcp:read, so paid tools stay hidden and answer insufficient_scope if called. Grant Write at consent, or use a key, to generate.

A header added on the command line ends up in a config file, and the shell expands the variable before Kimi sees it, so the key is written out as its value. Treat ~/.kimi/mcp.json as a secret file, and rotate the key if it ever lands in a log or chat, as the Sume OAuth and API keys page advises.

What can you ask Kimi to do first?

Start with discovery, since it spends nothing. Ask Kimi to call tools_list and summarize it, account_me to confirm the workspace, and catalog_list to see public capabilities. The catalog is broader than the MCP tools, so a model listed there may have no matching MCP tool; tools_list is the authority for what you can call.

For a first generation, have Kimi call tools_schema with the tool name, then run the call with dry_run=true. A real submit needs a session with write access and an idempotency_key, and then jobs_wait reads the result.

Why not use a local command instead of the remote entry?

Sume's docs say the local command surface is not launched yet, and that hosted MCP is the supported remote connector today. So for Kimi the remote entry above is the route to use.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume