Perplexity MCP authorization field with Sume: one-hour token
Perplexity passes the authorization value to the MCP server as an access token. A Sume OAuth token lasts one hour with no refresh, so use an API key unattended.

If you pass a Sume OAuth access token in Perplexity's authorization field, expect it to stop working after one hour. The Perplexity page describes authorization as the access token passed to the remote server. Sume's access tokens live for 3,600 seconds and Sume does not implement refresh, so a stored token cannot be renewed by the client. For anything that runs unattended, send a Sume API key instead.
Token or key
Perplexity also lets you pass extra headers as string values, so x-api-key works there if you would rather not use the authorization field.
| Option | Where it goes in Perplexity | Lifetime on Sume | Tools visible |
|---|---|---|---|
| OAuth access token | authorization | 1 hour, no refresh | mcp:read only, plus write tools if Write was ticked |
| API key | authorization or headers (x-api-key) | Until revoked | Full set |
What a mid-run expiry looks like
A Sume call made after the hour should be refused as unauthorized, not answered with a tool result about your task. Sume's 401 response carries a WWW-Authenticate challenge that points to the resource metadata, which a full OAuth client uses to start a new sign-in. A server-side agent has no browser, so the run simply fails at that point.
If a job was submitted before the token expired, it keeps running and billing. After you have a new credential, call jobs_wait or jobs_result with the job id to collect it.
Recommended setup
Use OAuth only for short interactive sessions, where a person can sign in again. Sume reports the credential in use through mcp_health, which is a cheap first call in any new agent run.
- Use an API key for scheduled or server-side Perplexity agents.
- Store it in your own secret manager and rotate it from the dashboard.
- Set allowed_tools to the tools the agent needs.
- Keep require_approval on for paid tools; its default is never.
Checking the token before a long run
If you must use OAuth for a one-off agent, start the run within a few minutes of signing in and keep it short. A jobs_wait slice is at most 55 seconds, so an hour allows many slices, but a queue of long video jobs may outlast the token. Plan to collect results with a fresh credential rather than hoping the old one lasts.
Never paste the token into a prompt or a shared document. The Sume safe-automation guidance lists API keys among the things that should not be logged, and a bearer token is just as sensitive while it is valid.
Sources
Related posts
More in Integrations
- Sume MCP read_busy 503: four concurrent reads per owner
read_busy is a retryable 503 from Sume's MCP host. Reads inside tools, including jobs_wait polls, are capped at 4 at once per owner, 512 across the host.
- Voice files from Gemini or ElevenLabs in a Sume timeline: 31 cents
Make the voice elsewhere, import the files into Sume media, join up to 20 parts for $0.01, render 3 minutes for $0.30. Total $0.31 plus your clips.
- VS Code MCP: Reset Trust after you grant Sume the Write scope
Write on Sume's consent page changes the server's abilities, not VS Code's trust decision. MCP: Reset Trust makes VS Code ask again; mcp_health shows scopes.
- VS Code Settings Sync and MCP servers: keep the Sume key out
VS Code can sync MCP config when the MCP Servers sync option is on. Keep the Sume API key out of the file with an input variable, or use OAuth instead.
Written by Sume