OpenAI connector_id deprecation: use server_url for Sume
OpenAI marks connector_id deprecated for models released after Sept 1, 2026. Sume is not a built-in connector: point server_url at https://mcp.sume.com/mcp.

Use server_url with https://mcp.sume.com/mcp. You do not need a connector_id for Sume, and OpenAI's MCP guide says connector_id is deprecated for models released after September 1, 2026.
That makes the remote-server form the safer default for any new integration. It is also the only form that fits a server OpenAI does not host: Sume's hosted MCP is reached over HTTPS at one endpoint, authenticated with an OAuth access token or an API key (hosted MCP docs).
Field by field
| Field | What OpenAI says | What you pass for Sume |
|---|---|---|
server_url | Points the tool at a remote MCP server | https://mcp.sume.com/mcp |
connector_id | Deprecated for models released after Sept 1, 2026 | Leave it out |
authorization | An OAuth token that OpenAI does not store; resend it on every request | A Sume OAuth access token |
allowed_tools | Limits which tools the model may see | Names from tools_list |
require_approval | always, never, or an object with tool names | Keep approval on for paid tools |
Where does the OAuth token come from?
Sume's protected-resource metadata lives at /.well-known/oauth-protected-resource/mcp, and the authorize step redirects to a consent page where the user picks mcp:read or adds mcp:write (OAuth docs). Because OpenAI does not store the token, your backend must keep it and put it in every request. Access tokens last an hour, so plan for re-login or switch long jobs to an API key.
Migration checklist
- Search your code for
connector_idand list which tools use it. - Replace each Sume use with
server_urland anauthorizationvalue. - Pin
allowed_toolsto the tools the task needs. - Re-run one read-only call such as
account_mebefore enabling anything paid. - Re-check the OpenAI page; the deprecation applies by model release date, not by calendar date.
Sources
Related posts
More in Integrations
- OpenClaw cron tool allowlists for unattended jobs that call Sume
OpenClaw v2026.8.35 keeps explicit cron tool allowlists. Name the Sume tools a job may call, and pair them with a read-only OAuth grant or a capped key.
- Retool agent can create a REST resource: set it up for Sume
Retool's app builder agent can now create REST API resources from a prompt. Tell it the Sume base URL, one auth header and a free GET /v1/me test.
- Runway MCP bills credits, no API key; Sume's hosted MCP uses scopes
Runway's MCP signs in with your Runway account and spends credits. Sume's hosted MCP defaults to read-only OAuth with write opt-in and dry runs.
- Runway MCP is Streamable HTTP only: connecting Sume the same way
Runway's MCP supports Streamable HTTP, not SSE or stdio. Sume's hosted MCP is one HTTPS URL too. Exact URLs, Cursor and Claude Code lines, and a 405.
Written by Sume