n8n MCP Client Tool with Sume: Bearer auth and tool selection
n8n's MCP Client Tool offers Bearer, header and OAuth2 auth and a Selected tools mode. Set it up against Sume's mcp.sume.com/mcp, and know the endpoint caveat.

In n8n, add the MCP Client Tool node under an AI Agent, enter https://mcp.sume.com/mcp as the endpoint, choose Bearer authentication, and paste a Sume API key. Then set tools to Selected and pick read tools first. The node's endpoint field is labeled SSE Endpoint in the n8n docs, while Sume's server is streamable HTTP, so confirm a first call works before you build on it.
| Setting | Options |
|---|---|
| Endpoint | Labeled SSE Endpoint |
| Authentication | Bearer, generic header, multiple headers, OAuth2, none |
| Tools to include | All, Selected, All Except |
Credential choice
Sume accepts Authorization: Bearer or x-api-key. In n8n, Bearer maps to the first. A generic header credential covers x-api-key. Either path gives the full hosted tool set, so scope the node with Selected.
| n8n option | Sends | Sume result |
|---|---|---|
| Bearer | Authorization: Bearer <key> | Full tool set |
| Generic header | x-api-key: <key> | Full tool set |
| OAuth2 | Token from n8n's flow | Needs Sume's MCP-host consent, read-only by default |
| None | Nothing | OAuth challenge from the server |
Selected tools
List only what the workflow needs. A workflow that reports on jobs needs jobs_list, jobs_wait and jobs_result. A workflow that creates images adds generate_image, and with it the duty to send a stable idempotency_key so a retried execution does not double-submit.
- Start with
tools_list,jobs_status,jobs_result. - Use All Except to drop
jobs_canceland other writes. - Add paid tools only with a dry run in the prompt.
- Rotate the key if an execution log shows it.
First call
Ask the agent to call mcp_health. If n8n cannot connect, test the key with a curl POST to the endpoint first; the Sume docs describe the transport as streamable HTTP, and the n8n docs describe the field as SSE, so the gap is the likely cause.
Testing outside n8n
Before wiring the node, post a JSON-RPC tools/list to the endpoint with your key using curl. If that returns tools, the key and URL are right and any remaining problem is in the node's transport handling. Keep the n8n credential name descriptive, such as the workspace and purpose, so you can find which workflows use a key when you rotate it.
Workflow design
An agent node can call tools in a loop, so cap its iterations. For paid creation, pass a stable idempotency_key built from the workflow's input, such as a row id, so a re-run of the same execution does not create a second job. For long renders, have the workflow call jobs_wait again on wait_slice_expired, rather than creating again.
Since the n8n page labels the field as an SSE endpoint, its docs do not confirm that the node negotiates streamable HTTP, and this setup was not run against Sume, so treat compatibility as something to test. If the node cannot connect, an HTTP Request node posting JSON-RPC to the same URL with the same header gives you the same tools without the MCP client node.
Keep in mind that Sume's hosted endpoint is the same for every client in this series: https://mcp.sume.com/mcp, with OAuth consent on the MCP host or an API key in a header. What differs is each client's config keys, its timeout defaults and its approval prompts. When a connection misbehaves, first separate those two layers: test the endpoint with curl and your credential, and only then look at the client's settings.
Sources
More in Integrations
- n8n test URL or production URL: which goes in a Sume webhook_url
Put the n8n Production URL in Sume's webhook_url. The Test URL only works while the editor is listening, so a holiday batch would burn retries against it.
- Unattended agent on Sume MCP: API key or OAuth consent?
A cron or CI agent cannot click a consent page. Sume's docs give OAuth to interactive clients and API-key remote MCP to automation, with caps set per call.
- One Sume MCP URL in Claude Code, Cursor and VS Code: keys compared
One https://mcp.sume.com/mcp URL, three shapes: claude mcp add --transport http, Cursor's mcpServers url, and VS Code's servers with type http.
- One Sume webhook endpoint for job and run events: route on event
Job and run webhooks share one HMAC scheme but not one payload. A 27-line TypeScript handler verifies once, routes on event, and answers 204 to the rest.
Written by Sume