Perplexity MCP authorization field with Sume: one-hour token

Perplexity passes the authorization value to the MCP server as an access token. A Sume OAuth token lasts one hour with no refresh, so use an API key unattended.

5 min readSume
All posts

If you pass a Sume OAuth access token in Perplexity's authorization field, expect it to stop working after one hour. The Perplexity page describes authorization as the access token passed to the remote server. Sume's access tokens live for 3,600 seconds and Sume does not implement refresh, so a stored token cannot be renewed by the client. For anything that runs unattended, send a Sume API key instead.

Token or key

Perplexity also lets you pass extra headers as string values, so x-api-key works there if you would rather not use the authorization field.

Perplexity MCP credential fields (read 2026-10-09) and Sume credential behaviour (docs and repo as of 2026-10-09)
OptionWhere it goes in PerplexityLifetime on SumeTools visible
OAuth access tokenauthorization1 hour, no refreshmcp:read only, plus write tools if Write was ticked
API keyauthorization or headers (x-api-key)Until revokedFull set

What a mid-run expiry looks like

A Sume call made after the hour should be refused as unauthorized, not answered with a tool result about your task. Sume's 401 response carries a WWW-Authenticate challenge that points to the resource metadata, which a full OAuth client uses to start a new sign-in. A server-side agent has no browser, so the run simply fails at that point.

If a job was submitted before the token expired, it keeps running and billing. After you have a new credential, call jobs_wait or jobs_result with the job id to collect it.

Recommended setup

Use OAuth only for short interactive sessions, where a person can sign in again. Sume reports the credential in use through mcp_health, which is a cheap first call in any new agent run.

  • Use an API key for scheduled or server-side Perplexity agents.
  • Store it in your own secret manager and rotate it from the dashboard.
  • Set allowed_tools to the tools the agent needs.
  • Keep require_approval on for paid tools; its default is never.

Checking the token before a long run

If you must use OAuth for a one-off agent, start the run within a few minutes of signing in and keep it short. A jobs_wait slice is at most 55 seconds, so an hour allows many slices, but a queue of long video jobs may outlast the token. Plan to collect results with a fresh credential rather than hoping the old one lasts.

Never paste the token into a prompt or a shared document. The Sume safe-automation guidance lists API keys among the things that should not be logged, and a bearer token is just as sensitive while it is valid.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume