LM Studio mcp.json: add Sume's hosted MCP server with an API key

LM Studio 0.3.17 and later accept remote MCP servers in mcp.json. The exact entry for https://mcp.sume.com/mcp with a Bearer header, plus the gates to know.

5 min readSume
All posts

Short answer

Open LM Studio's Program tab, choose Install, then Edit mcp.json, and add a sume entry with url set to https://mcp.sume.com/mcp and an Authorization: Bearer header. LM Studio's MCP docs say that starting with 0.3.17 (b10) the app supports both local and remote MCP servers, and show the url plus headers shape this entry uses.

Sume's hosted MCP accepts either an OAuth token or an API key sent as Authorization: Bearer or x-api-key, per the MCP OAuth and API keys page. LM Studio's documented remote form carries headers, so the API-key path is the one that maps onto it.

The mcp.json entry

Replace the placeholder with a key from the dashboard's API keys page. Keep the key out of screenshots and shared config files; Sume's docs say to rotate a key that shows up in logs or chat history.

{
  "mcpServers": {
    "sume": {
      "url": "https://mcp.sume.com/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_SUME_API_KEY>"
      }
    }
  }
}

What an API-key session can reach

An OAuth session is read-only by default and has no paid scope. An API-key session sees the full hosted tool set, including write and paid tools, and a local model with tool access can call them. Treat the key like a spending credential.

Hosted Sume MCP by credential (as of 2026-10-03)
CredentialReachPaid tools
OAuth, mcp:readread tools such as jobs_list, catalog_listinsufficient_scope
OAuth, mcp:read + mcp:writeadds write toolsthere is no mcp:paid scope
API key (Bearer or x-api-key)full hosted tool setvisible; idempotency_key required on writes and paid calls

Verify before you generate

Start a chat with a tool-capable model and ask it to call mcp_health, then tools_list. The first confirms the endpoint, auth source and safety posture; the second lists what the session can see. Live tool ids use underscores, such as tools_list and generate_image.

Before the first paid call, ask for dry_run=true or a generation_admission_preview, and pass max_spend_usd to cap spend. For a job that outlasts a single wait, jobs_wait holds at most 55 seconds per call; on wait_slice_expired call it again with the same ids rather than resubmitting the paid create.

What Sume does and does not do

Sume requires an idempotency_key on mutating and paid MCP calls, so a model that retries a tool call does not bill twice. It also lets you wait on up to 20 job ids in one jobs_wait call.

Sume does not offer a paid OAuth scope, and does not treat an OAuth token as an API key. LM Studio's own approval behavior for tool calls is outside Sume's docs; check its settings before connecting a key that can spend.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume