Can an MCP OAuth token double as a Sume API key? No
Sume says hosted MCP takes an OAuth token or an API key, never one for the other. Do not paste a token into x-api-key or mint a key as a workaround.

No. Sume's MCP OAuth page (read 2026-10-08) says hosted Sume MCP accepts OAuth access tokens or Sume API keys, and that you cannot use one of these credentials in place of the other. An OAuth token is not an API key. Pasting a token into an x-api-key header, or minting an API key to feed a client that wants OAuth, are both listed as things not to do.
The two credentials side by side
They come from different places and carry different power. The table lists what the docs say about each.
| Question | OAuth access token | Sume API key |
|---|---|---|
| Obtained how | Client runs the OAuth flow on mcp.sume.com and you consent | Created in the dashboard under API keys |
| Sent how | Bearer token after the client completes PKCE exchange | Authorization: Bearer or x-api-key, one only |
| Default capability | mcp:read, read-only tools | Full hosted tool set |
| Write and paid tools | Need Write at consent (mcp:write) | Visible; need idempotency_key |
| Spend gate | Wallet and admission; no mcp:paid scope | Wallet and admission |
Three tempting shortcuts that the docs rule out
Each shortcut looks harmless when a client will not finish sign-in. Sume's credential-safety list names them directly:
- Do not store OAuth tokens in CLI config.
- Do not paste OAuth tokens into prompts, and do not forward them to third-party providers.
- Do not mint API keys for hosted OAuth clients as a workaround.
sume logindoes not broker hosted MCP OAuth tokens, so signing in to the CLI will not sign in Cursor or Claude.
What to do when OAuth will not complete
Pick the matching credential on purpose instead of converting one into the other. For an interactive client, fix the flow: the client connects to https://mcp.sume.com/mcp, receives the OAuth challenge and protected-resource metadata, and goes to https://mcp.sume.com/oauth/authorize, which redirects to the consent page on the MCP host. Do not send it to app.sume.com. The metadata is public at https://mcp.sume.com/.well-known/oauth-protected-resource/mcp, so you can check it with curl.
For automation with no browser, choose API-key remote MCP on purpose and configure the client with a header. Keep the key in a secret store, send only one credential header, and expect to include an idempotency_key on writes and paid calls.
If a token or key leaks
If an API key appears in logs or chat history, rotate it: create a replacement, deploy it, check it with GET /v1/me, then revoke the old one. Prefer sharing request ids and job ids when you debug, not credentials or signed URLs. Safe logs per Sume's safe-automation page are request ids, job ids, high-level status and sanitized media metadata.
A quick decision rule
Ask who will be present when the connection starts. If a person is at the keyboard, use OAuth and let the client do the exchange; you never see the token, and you can keep Write off until you need it. If nobody is present, use an API key from the dashboard and treat it like any server secret.
Mixing the two is where trouble starts. A key pasted into a field meant for a token will not work, and the reverse is also true. Pick one mode per server entry, and name the entry so it is obvious which mode it is, for example one entry for the read-only OAuth session and a separate one for the automation key.
Sources
Related posts
More in Integrations
- n8n MCP Client Tool with Sume: Bearer auth and tool selection
n8n's MCP Client Tool offers Bearer, header and OAuth2 auth and a Selected tools mode. Set it up against Sume's mcp.sume.com/mcp, and know the endpoint caveat.
- n8n test URL or production URL: which goes in a Sume webhook_url
Put the n8n Production URL in Sume's webhook_url. The Test URL only works while the editor is listening, so a holiday batch would burn retries against it.
- Unattended agent on Sume MCP: API key or OAuth consent?
A cron or CI agent cannot click a consent page. Sume's docs give OAuth to interactive clients and API-key remote MCP to automation, with caps set per call.
- One Sume MCP URL in Claude Code, Cursor and VS Code: keys compared
One https://mcp.sume.com/mcp URL, three shapes: claude mcp add --transport http, Cursor's mcpServers url, and VS Code's servers with type http.
Written by Sume