One Sume MCP URL in Claude Code, Cursor and VS Code: keys compared

One https://mcp.sume.com/mcp URL, three shapes: claude mcp add --transport http, Cursor's mcpServers url, and VS Code's servers with type http.

4 min readSume
All posts

The Sume endpoint is the same everywhere, https://mcp.sume.com/mcp. What changes is the config shape. Claude Code uses a command, claude mcp add --transport http sume https://mcp.sume.com/mcp. Cursor uses mcpServers with a url. VS Code uses servers with type: "http" and a url. The three vendor pages (read 2026-10-08) differ in how they keep a secret out of the file, so the table below lines up the parts that matter for a Sume key.

Side by side

Fields come from each vendor's current docs page, and the Sume values from its MCP quickstart.

Config shapes for one remote MCP server, vendor pages read 2026-10-08
PartClaude CodeCursorVS Code
Whereclaude mcp add or .mcp.json.cursor/mcp.json or ~/.cursor/mcp.jsonmcp.json
Top-level keymcpServers in .mcp.jsonmcpServersservers
Remote entry--transport http plus URLurltype: http plus url
Header for a key--header flagheadersheaders
Keep the secret outEnv var in your shell${env:NAME}inputs with ${input:id}
OAuth sign-in/mcp or claude mcp login sumePrompts when connectingBrowser window on first connection, when configured

What stays the same

Sume does not care which client you use. It sees an HTTP request to the MCP endpoint with either an OAuth bearer token or an API key. For interactive use, Sume's docs prefer OAuth: Read is on, Write is off by default, and the consent page is on mcp.sume.com. For automation, send Authorization: Bearer or x-api-key, never both, because the API rejects a request with both. Writes and paid calls need an idempotency_key either way.

  • Confirm with tools_list after connecting.
  • Use mcp_health to see the auth source.
  • Never put a workspace id in the config.

What differs in practice

Timeouts are a client setting. Claude Code's page lists MCP_TOOL_TIMEOUT for per-server tool execution and a per-server timeout field in .mcp.json, and an idle timeout variable that defaults to 5 minutes for HTTP. Sume's jobs_wait holds for at most 55 seconds, so a client timeout above that never cuts a wait short, and the right pattern is to repeat the call, not to raise the timeout.

Config scope also differs. Cursor documents project and global files, so a team can commit a project entry that holds only the URL and the ${env:NAME} reference. Check each client's page for where its config lives before you commit a file.

Which entry to write first

Start with the OAuth form in the client you use, since it needs no secret and starts read-only. Add a second, key-based entry only for scripts and shared automation. If a model cannot see generate_video, check scope before you check syntax: the tool is hidden until Write is granted or a key is used.

Checking each client

After you add the entry, the check is the same in all three: ask the model to list the Sume tools, or call mcp_health. A read-only OAuth session should show the read tools and hide generate_video. An API key entry should show the full set. If the list is empty, look at the client's own server status view first, since a transport or auth failure shows up there before it reaches Sume.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume