LibreChat MCP server: add Sume in librechat.yaml

Add Sume's hosted MCP server to LibreChat under mcpServers in librechat.yaml: streamable-http, a Bearer key header, and requiresOAuth set to false.

5 min readSume
All posts

To add an MCP server to LibreChat, list it under mcpServers in librechat.yaml and restart LibreChat, or create it in the MCP Settings panel, where it takes effect without a restart. For Sume's hosted MCP server, use type: streamable-http, the URL https://mcp.sume.com/mcp, and a Sume API key in an Authorization: Bearer header, with requiresOAuth: false so LibreChat doesn't treat the key-protected server as an OAuth one.

LibreChat's side comes from its MCP page and MCP Servers object structure reference; Sume's side comes from MCP OAuth and API keys, MCP tools and gates, and Jobs and results, all read on 2026-09-28. Sume has no official LibreChat connector: LibreChat connects to Sume's remote MCP server like any other, and Sume's basics page says hosted MCP still works but is not part of the primary path today. Open WebUI MCP server covers another self-hosted chat UI.

How do I add Sume to librechat.yaml?

Add an entry under mcpServers. Its key, sume here, is the server's unique name. ${SUME_API_KEY} reads a server-side environment variable, so the key stays out of the file.

  • requiresOAuth: false: LibreChat's auto-detection probes a server without your configured headers, and a server that answers 401 with a WWW-Authenticate: Bearer challenge can be misclassified as OAuth-protected. Sume returns an OAuth challenge to a client that connects without a token, so set the flag whenever you use a key.
  • timeout: 60000: LibreChat's default for MCP server requests is 30000 ms, and one Sume jobs_wait call holds for up to 55 seconds. LibreChat's own long-operation example uses 60000 for tool operations.
mcpServers:
  sume:
    type: streamable-http
    url: https://mcp.sume.com/mcp
    headers:
      Authorization: 'Bearer ${SUME_API_KEY}'
    requiresOAuth: false
    timeout: 60000

Can each LibreChat user have a separate Sume key?

Yes, and it decides who pays. Sume API keys and spend resolve to a workspace, so one shared ${SUME_API_KEY} bills every LibreChat user's generations to a single Sume workspace. With customUserVars, each user enters their own key in the MCP Settings panel or from the settings icon in the tool selection dropdown; LibreChat stores the value per user and server and substitutes it at runtime, so each person's calls bill the workspace of the key they entered.

Servers created in the MCP Settings panel can do the same: choose API Key, check User provides key, and pick the Bearer header format, and LibreChat creates a customUserVars entry named MCP_API_KEY with a header such as Authorization: Bearer {{MCP_API_KEY}}. Panel-created servers can't read server-side environment variables, so a shared key kept in an environment variable has to be configured in librechat.yaml. Can multiple people use the same API key? covers the trade-off.

mcpServers:
  sume:
    type: streamable-http
    url: https://mcp.sume.com/mcp
    headers:
      Authorization: 'Bearer {{SUME_API_KEY}}'
    customUserVars:
      SUME_API_KEY:
        title: 'Sume API key'
    requiresOAuth: false
    timeout: 60000

Can LibreChat connect to Sume with OAuth instead?

Possibly, but neither side's docs cover the pairing, so test one sign-in first. LibreChat supports OAuth 2.0 for MCP servers with the authorization code flow and PKCE, automatic client registration when the provider supports it, and a callback at ${DOMAIN_SERVER}/api/mcp/sume/oauth/callback for a server named sume. Each user signs in with their own login. Sume's hosted MCP accepts OAuth access tokens too, and they behave differently from a key. MCP server OAuth flow on Sume walks through the steps.

  • Sume's consent page shows Read locked on and Write off by default. With Read only, paid tools such as generate_image return insufficient_scope, so turn Write on to generate.
  • In current code, Sume's access tokens last one hour and it issues no refresh token. LibreChat's own advice is to plan for re-authentication with providers that don't support refresh tokens.
  • Sume's current OAuth server registers public clients only, refusing a registration that asks for a client-secret token method, and accepts a plain http redirect only at localhost or 127.0.0.1. LibreChat says local Docker installs usually use http://localhost:3080; serve any other address over HTTPS.

Which librechat.yaml fields matter for Sume?

Fields from LibreChat's MCP Servers object structure; Sume values from MCP OAuth and API keys and Jobs and results, read 2026-09-28.
FieldWhat LibreChat's docs sayFor Sume
typestdio, websocket, streamable-http, or ssestreamable-http
headersCustom headers; ${ENV_VAR} and {{VARIABLE}} placeholdersAuthorization: 'Bearer …'
requiresOAuthAuto-detected when not setfalse with an API key
timeoutRequest timeout in ms; default 3000060000
chatMenufalse keeps the server out of regular chatfalse to reach Sume only through agents

What should I know before relying on it?

  • An API-key session sees Sume's full hosted tool set, paid tools included. In LibreChat's Agent Builder, expand the Sume server and enable only the tools an agent needs. In regular chat, selecting a server makes all of its tools available to the model, which is why chatMenu: false suits Sume.
  • Paid tools need an idempotency_key; dry_run=true previews cost without submitting; max_spend_usd caps a call only when it is sent.
  • If long calls still end early, LibreChat points at proxies such as nginx or traefik cutting connections on their own default timeouts.
  • On wait_slice_expired, the agent should call jobs_wait again with the same ids and never resubmit the paid create. MCP tool call timeouts on long-running video jobs covers the pattern.
  • Keep type: streamable-http. Without it, LibreChat treats an https:// URL as sse, and Sume's current server answers a GET on its MCP URL with 405 and Remote MCP uses POST JSON-RPC requests.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume