Perplexity Agent API MCP tool: server_label rules for Sume

Perplexity MCP tool: server_label must match ^[a-zA-Z0-9_-]{1,64}$. A Sume entry that passes, with authorization, headers and allowed_tools.

5 min readSume
All posts

To attach Sume to a Perplexity Agent API request, add an MCP tool with a server_label such as sume, a server_url of https://mcp.sume.com/mcp, and the credential in authorization or headers. The label must match ^[a-zA-Z0-9_-]{1,64}$ and must be unique within the request, because Perplexity uses it to namespace the server's tools. "sume" and "sume-prod" both pass; "sume.com" does not, because of the dot.

Fields that matter for Sume

Sume accepts the API key as a Bearer token or in x-api-key, so either field can carry it. An OAuth access token lasts one hour and Sume does not issue refresh tokens, so a long-lived Perplexity integration should use an API key stored in your own secret manager.

Perplexity MCP tool fields (read 2026-10-09) and the Sume value to use (as of 2026-10-09)
FieldPerplexity page saysSume value
server_labelUnique per request; ^[a-zA-Z0-9_-]{1,64}$; namespaces toolssume
server_urlHTTPS URLhttps://mcp.sume.com/mcp
authorizationAccess token passed to the remote serverOAuth access token (valid 1 hour) or API key
headersExtra request headers, string valuesx-api-key: your Sume key
allowed_toolsAllowlist; omitted or empty exposes all toolsNames from the tool list your credential sees

Keep the key out of logs

The request body holds the credential, so do not log whole request bodies. Safe things to log are request ids, job ids and statuses, which is what the Sume safe-automation guidance lists as fine to record. API keys and signed URLs are not.

Under OAuth with only the read scope, write tools are hidden from the tool list. Under an API key you see the full set, so set allowed_tools to the read tools you actually want the model to call. Write and paid calls need an idempotency_key regardless.

Approval for paid tools

Perplexity's require_approval defaults to never, which runs every call without asking. The page also allows always, or a filter that matches tools by name or by the read_only annotation, and it emits an mcp_approval_request that waits for an mcp_approval_response. Because the default is never, a Sume API key behind a Perplexity agent can submit paid jobs without a human step unless you change it.

A practical setting is to require approval for everything except read-only tools. Sume's write and paid tools also demand an idempotency_key, and you can send max_spend_usd and dry_run to bound a call, but those are optional and apply only when the model includes them. Approval on the Perplexity side is the only gate that does not depend on the model remembering a parameter.

Treat tool annotations with care: the MCP specification says clients must consider them untrusted unless they come from a trusted server. Here the server is your own Sume workspace, so a read_only filter is reasonable, but name-based filters survive a change in annotations.

Verify the connection

Ask the model to call mcp_health first. It reports the credential and scopes the session is using, which tells you whether the entry is OAuth or key based before any paid tool is attempted.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume