Raycast MCP: add Sume's hosted server with Dynamic OAuth

Add Sume to Raycast as an HTTP MCP server: URL, Dynamic OAuth sign-in, read-only by default, and when to switch to an API-key header for paid tools.

5 min readSume
All posts

To add Sume to Raycast, open the Install MCP Server command, choose the HTTP transport, set the URL to https://mcp.sume.com/mcp, pick Dynamic as the OAuth type and press Sign In. That connects Raycast AI to Sume's hosted MCP server with a read-only grant, which is enough for catalog and job lookups. Writes and paid generation need a second step, covered below.

Raycast's side comes from its Model Context Protocol manual and Sume's from MCP OAuth and API keys and the MCP quickstart, all read on 2026-10-01. Raycast is also shipping quickly: its changelog lists v2.5 on 28 September and v2.6 on 30 September 2026, so menu names may differ slightly on your build.

The fields, side by side

Raycast HTTP-server fields (Raycast manual) mapped to Sume values, read 2026-10-01.
Raycast fieldWhat Raycast saysValue for Sume
URLThe server's MCP endpointhttps://mcp.sume.com/mcp
HTTP HeadersKey/value pairs sent on every requestLeave empty for OAuth; for a key use Authorization: Bearer plus your key
OAuth TypeDynamic (Dynamic Client Registration with PKCE) or StaticDynamic
Static credentialsClient ID, secret and scopesNot needed for Sume

Why Dynamic fits

Raycast says Dynamic OAuth uses Dynamic Client Registration with PKCE: you press Sign In and Raycast registers itself as a client. Sume's MCP host exposes an /oauth/register endpoint and a PKCE code exchange, so a client that registers itself can complete the flow without you pasting a client id. Consent happens on the MCP host, not app.sume.com, and shows a Permissions step where Read is locked on and Write defaults to off.

Raycast stores tokens encrypted, per server, and its Logout Server action clears them without deleting the entry. That is the move if you grant Write once and later want to go back to read-only.

What the read-only grant can do

With only mcp:read, Sume's hosted server shows read tools such as tools_list, jobs_list, catalog_list and assets_get. Paid tools such as generate_image return insufficient_scope. Raycast's manual says it approves read-only tools on its own and asks you about the rest, which lines up neatly: the safe calls run silently and anything that spends money stops for a confirmation.

Verify the connection by asking Raycast AI to call tools_list and summarize the result. If the list is empty or the sign-in loops, remove the server and re-add it rather than editing tokens.

Letting it spend

To generate, you have two options from the Sume docs. Toggle Write on at consent to get mcp:write, or use an API key in a header, which exposes the full hosted tool set. Either way, paid submits need an idempotency_key, and dry_run=true previews cost without submitting. There is no mcp:paid scope, so the money guard is your wallet balance plus whatever you ask the assistant to pass as max_spend_usd.

A long video job will outlast one tool call. jobs_wait holds for up to 55 seconds per call, so ask the assistant to keep waiting on the job id rather than resubmitting.

Limits

Raycast's manual marks MCP as a Pro-exclusive feature, so check your plan first. This walkthrough follows the two vendors' documentation; it is not a captured session, so treat the verify step as the test. Raycast's tool-call timeout is not stated on the page we read, and we make no claim about it. Sume's hosted MCP is a secondary path next to the HTTP API and Formats, so use it where Raycast is where you work and the REST API where you are scripting.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume