Can an MCP OAuth token double as a Sume API key? No

Sume says hosted MCP takes an OAuth token or an API key, never one for the other. Do not paste a token into x-api-key or mint a key as a workaround.

4 min readSume
All posts

No. Sume's MCP OAuth page (read 2026-10-08) says hosted Sume MCP accepts OAuth access tokens or Sume API keys, and that you cannot use one of these credentials in place of the other. An OAuth token is not an API key. Pasting a token into an x-api-key header, or minting an API key to feed a client that wants OAuth, are both listed as things not to do.

The two credentials side by side

They come from different places and carry different power. The table lists what the docs say about each.

Hosted MCP credentials, from Sume's OAuth and API keys page, read 2026-10-08
QuestionOAuth access tokenSume API key
Obtained howClient runs the OAuth flow on mcp.sume.com and you consentCreated in the dashboard under API keys
Sent howBearer token after the client completes PKCE exchangeAuthorization: Bearer or x-api-key, one only
Default capabilitymcp:read, read-only toolsFull hosted tool set
Write and paid toolsNeed Write at consent (mcp:write)Visible; need idempotency_key
Spend gateWallet and admission; no mcp:paid scopeWallet and admission

Three tempting shortcuts that the docs rule out

Each shortcut looks harmless when a client will not finish sign-in. Sume's credential-safety list names them directly:

  • Do not store OAuth tokens in CLI config.
  • Do not paste OAuth tokens into prompts, and do not forward them to third-party providers.
  • Do not mint API keys for hosted OAuth clients as a workaround.
  • sume login does not broker hosted MCP OAuth tokens, so signing in to the CLI will not sign in Cursor or Claude.

What to do when OAuth will not complete

Pick the matching credential on purpose instead of converting one into the other. For an interactive client, fix the flow: the client connects to https://mcp.sume.com/mcp, receives the OAuth challenge and protected-resource metadata, and goes to https://mcp.sume.com/oauth/authorize, which redirects to the consent page on the MCP host. Do not send it to app.sume.com. The metadata is public at https://mcp.sume.com/.well-known/oauth-protected-resource/mcp, so you can check it with curl.

For automation with no browser, choose API-key remote MCP on purpose and configure the client with a header. Keep the key in a secret store, send only one credential header, and expect to include an idempotency_key on writes and paid calls.

If a token or key leaks

If an API key appears in logs or chat history, rotate it: create a replacement, deploy it, check it with GET /v1/me, then revoke the old one. Prefer sharing request ids and job ids when you debug, not credentials or signed URLs. Safe logs per Sume's safe-automation page are request ids, job ids, high-level status and sanitized media metadata.

A quick decision rule

Ask who will be present when the connection starts. If a person is at the keyboard, use OAuth and let the client do the exchange; you never see the token, and you can keep Write off until you need it. If nobody is present, use an API key from the dashboard and treat it like any server secret.

Mixing the two is where trouble starts. A key pasted into a field meant for a token will not work, and the reverse is also true. Pick one mode per server entry, and name the entry so it is obvious which mode it is, for example one entry for the read-only OAuth session and a separate one for the automation key.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume