n8n MCP Client Tool with Sume: Bearer auth and tool selection

n8n's MCP Client Tool offers Bearer, header and OAuth2 auth and a Selected tools mode. Set it up against Sume's mcp.sume.com/mcp, and know the endpoint caveat.

5 min readSume
All posts

In n8n, add the MCP Client Tool node under an AI Agent, enter https://mcp.sume.com/mcp as the endpoint, choose Bearer authentication, and paste a Sume API key. Then set tools to Selected and pick read tools first. The node's endpoint field is labeled SSE Endpoint in the n8n docs, while Sume's server is streamable HTTP, so confirm a first call works before you build on it.

n8n MCP Client Tool options, read 2026-10-08
SettingOptions
EndpointLabeled SSE Endpoint
AuthenticationBearer, generic header, multiple headers, OAuth2, none
Tools to includeAll, Selected, All Except

Credential choice

Sume accepts Authorization: Bearer or x-api-key. In n8n, Bearer maps to the first. A generic header credential covers x-api-key. Either path gives the full hosted tool set, so scope the node with Selected.

Mapping n8n auth to Sume, read 2026-10-08
n8n optionSendsSume result
BearerAuthorization: Bearer <key>Full tool set
Generic headerx-api-key: <key>Full tool set
OAuth2Token from n8n's flowNeeds Sume's MCP-host consent, read-only by default
NoneNothingOAuth challenge from the server

Selected tools

List only what the workflow needs. A workflow that reports on jobs needs jobs_list, jobs_wait and jobs_result. A workflow that creates images adds generate_image, and with it the duty to send a stable idempotency_key so a retried execution does not double-submit.

  • Start with tools_list, jobs_status, jobs_result.
  • Use All Except to drop jobs_cancel and other writes.
  • Add paid tools only with a dry run in the prompt.
  • Rotate the key if an execution log shows it.

First call

Ask the agent to call mcp_health. If n8n cannot connect, test the key with a curl POST to the endpoint first; the Sume docs describe the transport as streamable HTTP, and the n8n docs describe the field as SSE, so the gap is the likely cause.

Testing outside n8n

Before wiring the node, post a JSON-RPC tools/list to the endpoint with your key using curl. If that returns tools, the key and URL are right and any remaining problem is in the node's transport handling. Keep the n8n credential name descriptive, such as the workspace and purpose, so you can find which workflows use a key when you rotate it.

Workflow design

An agent node can call tools in a loop, so cap its iterations. For paid creation, pass a stable idempotency_key built from the workflow's input, such as a row id, so a re-run of the same execution does not create a second job. For long renders, have the workflow call jobs_wait again on wait_slice_expired, rather than creating again.

Since the n8n page labels the field as an SSE endpoint, its docs do not confirm that the node negotiates streamable HTTP, and this setup was not run against Sume, so treat compatibility as something to test. If the node cannot connect, an HTTP Request node posting JSON-RPC to the same URL with the same header gives you the same tools without the MCP client node.

Keep in mind that Sume's hosted endpoint is the same for every client in this series: https://mcp.sume.com/mcp, with OAuth consent on the MCP host or an API key in a header. What differs is each client's config keys, its timeout defaults and its approval prompts. When a connection misbehaves, first separate those two layers: test the endpoint with curl and your credential, and only then look at the client's settings.

Sources

More in Integrations

All Integrations posts

Written by Sume