OpenAI remote MCP does not store authorization: resend your Sume key

OpenAI's remote MCP tool does not keep the authorization value, so every Responses call must carry it. What that means for a Sume key and how to rotate it.

5 min readSume
All posts

Yes, send the credential on every request. OpenAI's remote MCP guide says the authorization value, typically an OAuth access token, is not stored by the API and does not appear in response objects, so you must resend it each time (read 2026-10-05). For Sume's hosted MCP at https://mcp.sume.com/mcp, that means your code holds the key and attaches it to each Responses call.

What the guide specifies

The tool entry names the server with server_url, passes credentials in authorization, narrows tools with allowed_tools, and sets approvals with require_approval (read 2026-10-05). Sume's side accepts either an OAuth token or an API key on the same endpoint, and the docs say one cannot stand in for the other.

Remote MCP fields against Sume's auth rules, read 2026-10-05
Field or ruleBehaviorSource
authorizationNot stored; not echoed in responses; resend each requestOpenAI guide
server_urlPublic MCP endpoint, here https://mcp.sume.com/mcpOpenAI guide, Sume docs
allowed_toolsLimits which tools the model can importOpenAI guide
API key on SumeAuthorization: Bearer or x-api-key; full tool setSume docs
OAuth token on SumeNot an API key; mcp:read by default, mcp:write opt-inSume docs

What this means for rotation

Because OpenAI does not keep the value, there is no stored copy to update when you rotate a Sume key. The new key only has to reach the process that builds the request. That is a point in favor of this design: a leaked key that appears in neither the response nor the stored objects is easier to contain.

If a key appears in logs or chat history, Sume's docs say to rotate it. Create the new key in the dashboard, deploy it to the secret store your request builder reads, and revoke the old one.

Build the tool entry without leaking

The helper refuses an empty key and prints the entry with the credential masked. It runs offline.

import json, os

def sume_mcp_tool(key: str) -> dict:
    if not key:
        raise ValueError("SUME_API_KEY is empty")
    return {
        "type": "mcp",
        "server_label": "sume",
        "server_url": "https://mcp.sume.com/mcp",
        "authorization": key,
        "require_approval": "always",
    }

def main() -> None:
    tool = sume_mcp_tool(os.environ.get("SUME_API_KEY", ""))
    print(json.dumps({**tool, "authorization": "***"}, indent=2))

if __name__ == "__main__":
    main()

Keep the key out of the prompt

The credential belongs in the tool entry, never in the instructions. The Sume docs list API keys and signed URLs among the things that must not reach logs or chat. A model that sees the key in its context can repeat it in a reply.

Pair the entry with require_approval so that a person or a policy sees each paid call before it runs. The approval flow is covered in Responses API approvals before Sume agent runs.

Checklist

Check these before you ship an agent that uses the tool entry above.

  • The key is read from a secret store at request time, not baked into a prompt template.
  • Logs record the Sume request_id, not the entry or its headers.
  • A rotation drill updates one secret and nothing else.
  • The key's scopes match the job; Agent Completions need the agent_completions:* scopes on a newer key.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume