LM Studio mcp.json: add Sume's hosted MCP server with an API key
LM Studio 0.3.17 and later accept remote MCP servers in mcp.json. The exact entry for https://mcp.sume.com/mcp with a Bearer header, plus the gates to know.

Short answer
Open LM Studio's Program tab, choose Install, then Edit mcp.json, and add a sume entry with url set to https://mcp.sume.com/mcp and an Authorization: Bearer header. LM Studio's MCP docs say that starting with 0.3.17 (b10) the app supports both local and remote MCP servers, and show the url plus headers shape this entry uses.
Sume's hosted MCP accepts either an OAuth token or an API key sent as Authorization: Bearer or x-api-key, per the MCP OAuth and API keys page. LM Studio's documented remote form carries headers, so the API-key path is the one that maps onto it.
The mcp.json entry
Replace the placeholder with a key from the dashboard's API keys page. Keep the key out of screenshots and shared config files; Sume's docs say to rotate a key that shows up in logs or chat history.
{
"mcpServers": {
"sume": {
"url": "https://mcp.sume.com/mcp",
"headers": {
"Authorization": "Bearer <YOUR_SUME_API_KEY>"
}
}
}
}What an API-key session can reach
An OAuth session is read-only by default and has no paid scope. An API-key session sees the full hosted tool set, including write and paid tools, and a local model with tool access can call them. Treat the key like a spending credential.
| Credential | Reach | Paid tools |
|---|---|---|
| OAuth, mcp:read | read tools such as jobs_list, catalog_list | insufficient_scope |
| OAuth, mcp:read + mcp:write | adds write tools | there is no mcp:paid scope |
| API key (Bearer or x-api-key) | full hosted tool set | visible; idempotency_key required on writes and paid calls |
Verify before you generate
Start a chat with a tool-capable model and ask it to call mcp_health, then tools_list. The first confirms the endpoint, auth source and safety posture; the second lists what the session can see. Live tool ids use underscores, such as tools_list and generate_image.
Before the first paid call, ask for dry_run=true or a generation_admission_preview, and pass max_spend_usd to cap spend. For a job that outlasts a single wait, jobs_wait holds at most 55 seconds per call; on wait_slice_expired call it again with the same ids rather than resubmitting the paid create.
What Sume does and does not do
Sume requires an idempotency_key on mutating and paid MCP calls, so a model that retries a tool call does not bill twice. It also lets you wait on up to 20 job ids in one jobs_wait call.
Sume does not offer a paid OAuth scope, and does not treat an OAuth token as an API key. LM Studio's own approval behavior for tool calls is outside Sume's docs; check its settings before connecting a key that can spend.
Sources
Related posts
More in Developers
- Load-test your Sume webhook receiver with a signed burst
Fire 500 correctly signed job.completed requests at your own receiver before a bulk run does it for real. A runnable Python harness and the 10-second budget.
- LRC lyrics file from an AI music track: Sume STT segments in Python
YouTube accepts .lrc lyric files. A short Python script turns STT sentence segments from a generated song into [mm:ss.xx] lines. Check results before upload.
- Luma Agents API polling: 20 s wait, 10-minute video timeout, and Sume
Luma's quickstart says wait 20 seconds, then poll, with a hard 2-minute image and 10-minute video timeout, not backoff. A matching Sume loop that actually runs.
- Luma Ray 2 to Ray 3.2 migration: the field map and what changes
Luma is retiring Ray 3, Ray 2, Ray 2 Flash and more for ray-3.2 on one /v1/generations endpoint. The field map, the poll-only change, and Sume's contrast.
Written by Sume