Msty Studio remote MCP: add Sume over HTTP with a key header

Msty Studio adds remote MCP servers over streamable HTTP with a URL and headers. Use Sume's x-api-key header, then switch paid tools off in the toolbox.

4 min readSume
All posts

To add Sume to Msty Studio, open the Toolbox tools screen, choose HTTP, enter https://mcp.sume.com/mcp as the MCP Server URL, and put your Sume API key in a header. Then use the toolbox's enable and disable controls to keep paid generation tools off until you want them.

Msty's page describes two connection types. HTTP is for remote servers on streamable HTTP, and Msty notes that the SSE protocol has been deprecated in favor of streamable HTTP. STDIO/JSON is for local servers. Sume's hosted endpoint is a remote streamable HTTP server, so HTTP is the choice.

What Msty asks for, and what Sume needs

Msty's HTTP form takes three things: the server URL, any authentication, and any headers. Sume's docs list two ways to send an API key, an Authorization Bearer header or an x-api-key header. Either maps onto Msty's headers field.

Msty's tools page does not describe an OAuth sign-in for remote servers, so this post uses the API-key path. Sume's OAuth path is documented for clients that run the MCP OAuth flow; see MCP OAuth and API keys.

Msty Studio form fields mapped to Sume values (Msty page read 2026-10-10; Sume values from docs.sume.com/mcp/oauth and /mcp/quickstart)
Msty fieldValue for SumeSource
Connection typeHTTP (streamable HTTP, remote)Msty tools page
MCP Server URLhttps://mcp.sume.com/mcpSume MCP quickstart
Header namex-api-key (or Authorization)Sume MCP OAuth and API keys
Header valueyour Sume API key; Bearer prefix only for AuthorizationSume MCP OAuth and API keys

Why the toolbox switches matter more with a key

Sume's docs say an API-key session sees the full hosted tool set, including the tools that change data and the paid ones. A read-only OAuth session would hide those tools; a key does not. Spend is governed by your wallet and admission, and write or paid calls must carry an idempotency_key.

Msty's page says that once a server is added, tools can be enabled or disabled in your toolbox. Use that as your gate. A sensible first pass is to leave on the discovery and read tools, and leave off the paid ones.

  • Leave on: mcp_health, tools_list, tools_schema, account_me, balance_get, catalog_list, jobs_list, jobs_status
  • Leave off until needed: generate_image, generate_video, music_create, tts_create, avatars_create
  • Leave off unless you mean it: jobs_cancel, assets_create, assets_upload_url, assets_complete

Verify the connection

After saving, start a chat with the Sume tools enabled and ask for a read-only call, such as mcp_health or tools_list. Sume's quickstart uses these as the first calls, and mcp_health reports the endpoint, the auth source, and the safety posture.

Before the first paid call, ask the model to run it with dry_run set to true. Sume documents dry_run as a cost preview that does not submit the job, and max_spend_usd as an optional cap that Sume enforces only when you send it.

{
  "idempotency_key": "msty-first-image-001",
  "dry_run": true,
  "max_spend_usd": 1
}

A caveat from Msty itself

Msty's page says these tools are not created or maintained by the Msty team and are used at your own risk. It also says that using Toolbox features with Msty Studio Web requires connecting it to Studio Desktop through Remote Connections or Sidecar, so set the server up where the toolbox runs.

If a key shows up in a chat log or screenshot, rotate it from the API keys page, as Sume's credential-safety notes advise. For the full tool list and gates, read Tools and gates.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume