OpenAI remote MCP does not store authorization: resend a Sume key

OpenAI does not store the MCP authorization value, so resend it on every request. Sume accepts a bearer API key or OAuth; keep either one server-side only.

4 min readSume
All posts

OpenAI's remote MCP tool does not keep your authorization value between requests, so your code has to send it again on every request. With Sume's hosted MCP at https://mcp.sume.com/mcp, the value you would send is an OAuth access token or a Sume API key, and both stay on your server. The Sume docs have no OpenAI-specific guide, so the steps below combine the OpenAI page with Sume's auth matrix.

What each page says

MCP auth facts, read 2026-10-05
ItemOpenAISume
Credential storageauthorization value is not stored; resend every requestNot applicable; your server holds the key
Connector styleLegacy connectors for older models; new work uses server_url or tunnel_idOne URL: https://mcp.sume.com/mcp
Accepted credentialsYour server passes what the MCP server expectsOAuth access token, or API key as Authorization: Bearer or x-api-key
Default capabilityApproval controlled by require_approvalOAuth mcp:read sees read-only tools; mcp:write is a consent toggle; API key sees the full set

What this means for your build

Because the value is not stored, every request your backend builds for the Responses API must include the credential. That puts a long-lived Sume API key in your request builder, which is fine on a server and wrong in a browser or mobile bundle. The Sume docs say an API key spends credits and there is no browser-safe variant.

An API key gives the full hosted tool set. Paid and write calls still need an idempotency_key, and spend is governed by wallet and admission. OAuth is the preferred path for interactive clients, and it starts read-only, so paid tools such as generate_image return insufficient_scope until the user grants mcp:write. There is no mcp:paid scope.

Checklist

  • Keep the key in a secret store and build the MCP tool entry per request.
  • Do not paste keys into chat or logs. The Sume docs list API keys and signed URLs as unsafe to log.
  • Start with a read-only discovery call, tools_list or mcp_health, before any paid tool.
  • Rotate the key if it ever appears in a log line or error message.

Request flow

A single user turn can involve several requests: one to list tools, one per tool call, and a final answer. If each is a separate Responses API request, each needs the credential. Build the tool entry in one function that reads the key from your secret store, so the key is not copied into prompts, templates or logs. Sume's docs list API keys and signed URLs as unsafe in logs, and they ask you to share request ids instead.

For a multi-tenant product, resolve the credential per customer at request time. Because Sume's key selects the workspace, the right key means the right workspace and the right wallet, with no workspace argument to get wrong.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume