n8n 2.42 MCP Registry: add Sume's hosted MCP endpoint

n8n 2.42.0 (pre-release) drops the feature flag for its MCP Registry. The Sume side is one URL: OAuth read-only by default, or an API key for paid tools.

4 min readSume
All posts

To use Sume from an MCP client such as an n8n agent, point it at the hosted endpoint https://mcp.sume.com/mcp and choose OAuth or an API key. OAuth sessions are read-only unless Write is granted at consent; API-key sessions see the paid tools.

What n8n 2.42 says

The n8n releases page lists n8n@2.42.0, dated Sep 29, 2026 and marked pre-release, with the bug-fix entry "Remove feature flag for MCP Registry in AI Assistant". The release notes do not describe the registry screens, so this post does not either. Check the n8n documentation for where an MCP server entry is added in your version.

The Sume side

Whatever the client UI looks like, it needs the same three things from Sume.

Sume hosted MCP connection facts (read 2026-10-03)
ItemValue
Endpointhttps://mcp.sume.com/mcp
OAuth scopesmcp:read (required) and mcp:write (opt-in at consent)
API key headerAuthorization: Bearer <SUME_API_KEY> or x-api-key
Paid or write callsidempotency_key required
First read-only callsmcp_health, tools_list, account_me

Pick the auth mode on purpose

Default hosted OAuth grants read-only access. With mcp:read only, tools such as generate_image or avatars_create return insufficient_scope. There is no mcp:paid scope; paid submits go through wallet admission.

An unattended workflow usually cannot complete an interactive consent screen, so automation tends to use an API key. API-key sessions can see write and paid tools, which means the key can spend. Give the agent dry_run or generation_admission_preview before its first paid call, and cap spend with max_spend_usd when you pass it.

Verify before you build on it

After the client connects, ask it to call tools_list and summarize what it sees. Then call mcp_health, which confirms the endpoint, auth source and safety posture. Only then wire a generation tool into the workflow.

Never paste an API key into chat or a prompt, and do not reuse an OAuth token as an API key. The two are separate credentials. Details are in MCP OAuth and API keys.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume