One Sume MCP URL in Claude Code, Cursor and VS Code: keys compared
One https://mcp.sume.com/mcp URL, three shapes: claude mcp add --transport http, Cursor's mcpServers url, and VS Code's servers with type http.

The Sume endpoint is the same everywhere, https://mcp.sume.com/mcp. What changes is the config shape. Claude Code uses a command, claude mcp add --transport http sume https://mcp.sume.com/mcp. Cursor uses mcpServers with a url. VS Code uses servers with type: "http" and a url. The three vendor pages (read 2026-10-08) differ in how they keep a secret out of the file, so the table below lines up the parts that matter for a Sume key.
Side by side
Fields come from each vendor's current docs page, and the Sume values from its MCP quickstart.
| Part | Claude Code | Cursor | VS Code |
|---|---|---|---|
| Where | claude mcp add or .mcp.json | .cursor/mcp.json or ~/.cursor/mcp.json | mcp.json |
| Top-level key | mcpServers in .mcp.json | mcpServers | servers |
| Remote entry | --transport http plus URL | url | type: http plus url |
| Header for a key | --header flag | headers | headers |
| Keep the secret out | Env var in your shell | ${env:NAME} | inputs with ${input:id} |
| OAuth sign-in | /mcp or claude mcp login sume | Prompts when connecting | Browser window on first connection, when configured |
What stays the same
Sume does not care which client you use. It sees an HTTP request to the MCP endpoint with either an OAuth bearer token or an API key. For interactive use, Sume's docs prefer OAuth: Read is on, Write is off by default, and the consent page is on mcp.sume.com. For automation, send Authorization: Bearer or x-api-key, never both, because the API rejects a request with both. Writes and paid calls need an idempotency_key either way.
- Confirm with
tools_listafter connecting. - Use
mcp_healthto see the auth source. - Never put a workspace id in the config.
What differs in practice
Timeouts are a client setting. Claude Code's page lists MCP_TOOL_TIMEOUT for per-server tool execution and a per-server timeout field in .mcp.json, and an idle timeout variable that defaults to 5 minutes for HTTP. Sume's jobs_wait holds for at most 55 seconds, so a client timeout above that never cuts a wait short, and the right pattern is to repeat the call, not to raise the timeout.
Config scope also differs. Cursor documents project and global files, so a team can commit a project entry that holds only the URL and the ${env:NAME} reference. Check each client's page for where its config lives before you commit a file.
Which entry to write first
Start with the OAuth form in the client you use, since it needs no secret and starts read-only. Add a second, key-based entry only for scripts and shared automation. If a model cannot see generate_video, check scope before you check syntax: the tool is hidden until Write is granted or a key is used.
Checking each client
After you add the entry, the check is the same in all three: ask the model to list the Sume tools, or call mcp_health. A read-only OAuth session should show the read tools and hide generate_video. An API key entry should show the full set. If the list is empty, look at the client's own server status view first, since a transport or auth failure shows up there before it reaches Sume.
Sources
Related posts
More in Integrations
- One Sume webhook endpoint for job and run events: route on event
Job and run webhooks share one HMAC scheme but not one payload. A 27-line TypeScript handler verifies once, routes on event, and answers 204 to the rest.
- Stdlib Python Sume webhook receiver: http.server, 204 for webhook.test
A 29-line http.server receiver that refuses an empty secret, checks sume-v1 in a 300-second window, takes the two-signature header, and 204s webhook.test.
- Roo Code alwaysAllow for Sume MCP: which tools to auto-approve
Roo Code alwaysAllow skips the approval click. Auto-approve Sume read tools only, and keep paid ones manual or behind dry_run and a spend cap.
- Roo Code MCP timeout 60 s default: add Sume as streamable-http
Roo Code defaults MCP requests to 60 seconds and allows 1 to 3600. Here is the streamable-http entry for Sume with a timeout that fits jobs_wait.
Written by Sume