MCP Inspector custom headers: send one Sume API key

In MCP Inspector's custom headers, send either x-api-key or Authorization: Bearer with your Sume key, never both. Sume rejects a request carrying both.

4 min readSume
All posts

In MCP Inspector, set the transport to Streamable HTTP with URL https://mcp.sume.com/mcp and add one custom header: x-api-key with your Sume key, or Authorization with Bearer <key>. Use only one. Sume rejects a request that carries both with 401 and "Send only one API key credential."

Inspector facts are from its GitHub releases page and Sume facts from the authentication docs, the MCP OAuth docs and the MCP server source, read 2026-10-01.

Which headers does Sume accept?

Sume docs and MCP server source, read 2026-10-01.
Header formResult
x-api-key: <SUME_API_KEY>Accepted; full hosted tool set
Authorization: Bearer <SUME_API_KEY>Accepted; full hosted tool set
Both togetherRejected with 401: "Send only one API key credential."

Why not send both?

The authentication docs say neither header wins, and the second does not silently shadow the first. It bites gateways that add their own Authorization header on top of a client that already sends x-api-key. If Inspector or a proxy in front of it adds one, strip it. The MCP health body lists both header forms as accepted.

What do the recent Inspector releases change?

The 2.8.0 notes (published 2026-09-23) include a fix so only DANGEROUSLY_OMIT_AUTH=true or 1 disables Inspector's own /api auth. That is Inspector's local proxy auth, separate from the credential you send to Sume. The 2.9.0 notes (2026-09-30) include a prompt to reconnect when custom headers change on a live connection, so change the header, then reconnect before testing.

Should I use OAuth instead?

You can. The OAuth route gives mcp:read sessions read-only tools and mcp:write sessions the full set, as the MCP OAuth docs describe. An API key is simpler for a quick check but exposes every tool, including paid ones that need an idempotency_key. Keep the key out of screenshots and shared Inspector config files.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume