LiteLLM mcp_servers config for Sume: static_headers and one credential
Register Sume's hosted MCP server in LiteLLM with auth_type and static_headers. Send one credential header, and keep write tools off a read-only team key.

LiteLLM's proxy can front remote MCP servers, so teams can register Sume's hosted MCP server once and let several apps use it. The LiteLLM MCP page lists mcp_servers keys including url, transport (default http, also sse and stdio), server_id, auth_type, auth_value, static_headers and extra_headers, read 2026-10-03. The question for a Sume setup is which of those carries the credential.
The keys you need
LiteLLM also lists api_key, basic, authorization, token, oauth2 and aws_sigv4 as auth_type values, and oauth2_flow, token_url, client_id, client_secret and scopes for the OAuth path. For Sume, a key sent as a bearer token is the simplest route; the Sume OAuth page covers the interactive alternative.
| Key | Value for Sume | Note |
|---|---|---|
url | https://mcp.sume.com/mcp | Streamable HTTP endpoint from the Sume docs |
transport | http | The LiteLLM default |
auth_type | bearer_token | One of the types LiteLLM lists |
auth_value | Your Sume key, from an env reference | Do not commit it |
server_id | A stable name | Used for selection |
mcp_servers:
sume:
url: https://mcp.sume.com/mcp
transport: http
auth_type: bearer_token
auth_value: os.environ/SUME_API_KEYOne credential, not two
Sume's SDK docs say the REST API rejects a request carrying both Authorization and x-api-key with a 401 "Send only one API key credential." If you use auth_type and also add the same key in static_headers, the proxy may send both. Pick one place for the credential. This post does not state how LiteLLM merges them; test the outgoing headers.
Scope the key to the job
Sume's gates are enforced on the Sume side: idempotency_key is required on paid and write tools, and max_spend_usd is enforced when you provide it. LiteLLM lists MCP cost tracking and guardrails as features, without detail on the page, so do not assume they replace Sume's own limits.
For a shared proxy, give each team a Sume key with only the access it needs. Under OAuth, mcp:read exposes read-only tools and a paid tool returns insufficient_scope; that is a useful default for a team that only needs to look at assets.
- Reference the key from an environment variable.
- Check the outgoing headers once.
- Require
idempotency_keyin any client that creates jobs. - Use LiteLLM's
x-mcp-serversheader to choose which servers a request may use.
Sources
Related posts
More in Integrations
- Make MCP scenario tool times out at 25 seconds: Sume job pattern
Make's MCP scenario tool call times out at 25s on OAuth while the run continues. Return a Sume job id and poll it; never resubmit the paid call.
- Make MCP token in URL, header or OAuth: which one for Sume workflows
Make's MCP server has three connection styles with different timeouts. Compare them for a Sume workflow and keep the Sume key out of URLs and prompts.
- Mastodon GIF under 1 megapixel, no sound: send a trimmed MP4 instead
Mastodon limits GIFs to 16 MB and under 1 megapixel (1280x720) and turns them into soundless MP4s. For sound, upload a trimmed video made with Sume instead.
- MCP server has a url but no type in Claude Code: fix the entry
Claude Code skips an MCP entry that has a url and no type. Add type http to the Sume entry you copied from Cursor, then sign in and check the connection.
Written by Sume