Le Chat custom MCP connector for Sume: admin-only, three auth modes

Adding Sume to Mistral Le Chat is an admin task: name, server URL, then bearer token or OAuth 2.1. Which mode fits Sume's hosted MCP and what each exposes.

5 min readSume
All posts

Only an administrator of your Mistral workspace can add a custom MCP connector to Le Chat, and Sume's hosted server fits the form with a URL plus either OAuth or a bearer token. Point the connector at https://mcp.sume.com/mcp. The auth choice decides what the connector can do: OAuth with Write left off sees read-only tools, while a Sume API key sees the full tool set including paid generation.

Mistral's side comes from its MCP Connectors page; Sume's side comes from MCP OAuth and API keys and MCP tools and gates. Both were read on 2026-10-03.

Who can add the connector, and what the form asks for

Mistral states that custom connectors are an administrator-only feature, and that on the Free, Pro and Student plans the account owner is the administrator by default. From the Connectors page you choose Add Connector and open the Custom MCP Connector tab. The form takes a connector name with no spaces or special characters, the full server URL, and an optional description.

So the person who holds the Sume decision is the person with admin rights in Mistral. If that is not the person who owns the Sume workspace, settle the credential question before anyone opens the form.

Le Chat connector fields and the value to use for Sume (read 2026-10-03)
FieldWhat Mistral asks forValue for Sume
Connector nameUnique, no spaces or special characterssume
Server URLFull address of the MCP serverhttps://mcp.sume.com/mcp
DescriptionOptionalOne line on what the connector is for
AuthenticationNone, HTTP bearer token / basic auth, or OAuth 2.1OAuth, or a bearer token holding a Sume API key

Pick the auth mode by what you want the connector to do

Mistral lists three modes: no authentication for public servers, an HTTP bearer or basic credential sent in the Authorization header, and OAuth 2.1 with dynamic client registration. Sume's endpoint is not public, so the first is out.

Sume accepts either an OAuth access token or an API key sent as Authorization: Bearer <SUME_API_KEY> or x-api-key. The two are not interchangeable, and they expose different tools.

  • OAuth: the consent page on the MCP host shows Read locked on and a Write toggle that defaults to off. With Write off the session sees read-only tools, and a mutating or paid call returns insufficient_scope.
  • Bearer token: an API key gives the full hosted tool set. Paid and write calls still need an idempotency_key, and spend is governed by wallet and admission, since there is no mcp:paid scope.
  • Either way, max_spend_usd is enforced only when the caller passes it, so it is a request-level cap and not a connector-level one.

A safe first connection

Start with OAuth and leave Write off. Ask Le Chat to call mcp_health, which reports the auth source, then tools_list. If you see mcp_oauth and only read tools, the connector is read-only as intended. Turn Write on only when someone in the workspace needs generation from chat.

If you paste a Sume API key as the bearer credential, treat that connector as a shared spender. Mistral's page does not tell you who in the workspace may invoke a connector, so confirm that before the key goes in, and rotate the key if it ever shows up in a chat transcript. Sume's own guidance is to rotate keys that appear in logs or chat history.

Trust is on your side of the line

Mistral says MCP connectors are not Mistral products and that it cannot guarantee third-party server behavior or data handling. That cuts both ways: Mistral is not vouching for Sume, and you should not expect Le Chat to add spend controls Sume does not already have. The controls that exist live in Sume: scope at consent, idempotency_key on writes, optional dry_run, and optional max_spend_usd. Keep those in the instructions you give the Le Chat agent, and verify with a dry_run=true call before the first paid submit.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume