MCP Inspector custom headers: send one Sume API key
In MCP Inspector's custom headers, send either x-api-key or Authorization: Bearer with your Sume key, never both. Sume rejects a request carrying both.

In MCP Inspector, set the transport to Streamable HTTP with URL https://mcp.sume.com/mcp and add one custom header: x-api-key with your Sume key, or Authorization with Bearer <key>. Use only one. Sume rejects a request that carries both with 401 and "Send only one API key credential."
Inspector facts are from its GitHub releases page and Sume facts from the authentication docs, the MCP OAuth docs and the MCP server source, read 2026-10-01.
Which headers does Sume accept?
| Header form | Result |
|---|---|
x-api-key: <SUME_API_KEY> | Accepted; full hosted tool set |
Authorization: Bearer <SUME_API_KEY> | Accepted; full hosted tool set |
| Both together | Rejected with 401: "Send only one API key credential." |
Why not send both?
The authentication docs say neither header wins, and the second does not silently shadow the first. It bites gateways that add their own Authorization header on top of a client that already sends x-api-key. If Inspector or a proxy in front of it adds one, strip it. The MCP health body lists both header forms as accepted.
What do the recent Inspector releases change?
The 2.8.0 notes (published 2026-09-23) include a fix so only DANGEROUSLY_OMIT_AUTH=true or 1 disables Inspector's own /api auth. That is Inspector's local proxy auth, separate from the credential you send to Sume. The 2.9.0 notes (2026-09-30) include a prompt to reconnect when custom headers change on a live connection, so change the header, then reconnect before testing.
Should I use OAuth instead?
You can. The OAuth route gives mcp:read sessions read-only tools and mcp:write sessions the full set, as the MCP OAuth docs describe. An API key is simpler for a quick check but exposes every tool, including paid ones that need an idempotency_key. Keep the key out of screenshots and shared Inspector config files.
Sources
Related posts
More in Developers
- MCP JSON-RPC batch 400: one message per request, Sume max 4
MCP 2026-07-28 requires one JSON-RPC message per POST. Sume still takes legacy batches of 1 to 4 on the 2025-03-26 shape and returns 400 -32600 otherwise.
- MCP OAuth .localhost redirect URI: Sume allows localhost and 127.0.0.1
MCP TypeScript SDK 2.2.0 treats .localhost hosts as loopback for token endpoints. Sume's redirect check allows http only on localhost and 127.0.0.1.
- MCP 403 forbidden_origin: why a browser client is refused
Sume remote MCP answers a disallowed Origin header with 403 forbidden_origin. A request with no Origin, like curl or a server SDK, is not checked this way.
- MCP ping method removed in 2026-07-28: Sume still replies {}
The MCP 2026-07-28 revision removes ping. Sume's hosted server still answers a ping request with an empty result on the versions it speaks.
Written by Sume