OpenAI Agents SDK 0.20 httpx2 MCP headers: Sume API key

With a custom MCP HTTP client in Agents SDK 0.20, send the Sume key as an Authorization Bearer or x-api-key header. httpx2 only matters if you built the client.

4 min readSume
All posts

Put the Sume key in a request header, either Authorization: Bearer $SUME_API_KEY or x-api-key: $SUME_API_KEY, whichever HTTP client you use. Agents SDK 0.20 changes nothing about that for ordinary connections; it only matters if you supply your own httpx.Auth object or httpx.AsyncClient factory and MCP Python SDK v2 gets installed, in which case those must move to httpx2.

SDK behavior from its release notes; header forms from OAuth and API keys, read 2026-10-01.

What changed in Agents SDK 0.20?

Local MCP HTTP customization follows the installed MCP package: MCP Python SDK v1 uses legacy httpx, v2 uses httpx2. The SDK adapts ordinary stdio, SSE and Streamable HTTP connections automatically and does not convert arbitrary legacy httpx objects. If resolution picks MCP v2, custom httpx.Auth objects and httpx.AsyncClient factories must be migrated to httpx2, or you pin mcp<2.

Which header does Sume accept?

Sume key header forms on the hosted endpoint, read 2026-10-01.
HeaderValue
AuthorizationBearer $SUME_API_KEY
x-api-key$SUME_API_KEY

What is the simplest setup?

A plain headers dict avoids a custom client altogether, so the httpx or httpx2 question never comes up.

import asyncio
import os
from agents.mcp import MCPServerStreamableHttp


async def main():
    key = os.environ["SUME_API_KEY"]
    async with MCPServerStreamableHttp(
        name="sume",
        params={
            "url": "https://mcp.sume.com/mcp",
            "headers": {"Authorization": "Bearer " + key},
        },
    ) as server:
        tools = await server.list_tools()
        print([t.name for t in tools])


asyncio.run(main())

What if I do need a custom client?

Set the same header on whichever client your installed MCP package expects, and keep the key in an environment variable rather than in code. API-key sessions can see write and paid tools, and paid calls still need an idempotency_key. For a second server alongside Sume, see McpServerManager with a second server.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume