Roo Code .roo/mcp.json overrides the global Sume MCP entry

In Roo Code a project .roo/mcp.json wins over global mcp_settings.json when both name the same server. Use one name for Sume and keep the key in one file.

4 min readSume
All posts

Roo Code reads MCP servers from a global mcp_settings.json and from a project-level .roo/mcp.json, and when the same server name appears in both, the project entry takes precedence. If you register Sume under one name in both files, the project file replaces the global one rather than adding to it, so a project entry that lacks your header or alwaysAllow list can change what Roo sends.

What Roo's docs say

Roo's page describes the two files and the precedence rule. For a remote server, the type must be streamable-http, the url is required, headers are optional, alwaysAllow is an array of tool names, and disabled is a boolean.

Roo Code server entry keys (Roo docs, read 2026-10-10) with Sume values
KeyRequiredSume value
typeYesstreamable-http
urlYeshttps://mcp.sume.com/mcp
headersNox-api-key with your Sume key, or leave out and use OAuth
alwaysAllowNoRead tools only, if any
disabledNotrue to pause the server

Choose where the key lives

Sume accepts an API key as an Authorization Bearer header or an x-api-key header, and its docs say an API-key session sees the full hosted tool set. Putting that key in a project .roo/mcp.json risks committing it with the repository. Sume's credential-safety notes say to rotate keys that appear in logs or chat history.

A safe split follows from the precedence rule. Keep the key and the Sume entry only in the global file, and do not add a Sume entry to the project file. If the project needs to disable Sume, a same-name project entry with disabled set to true would take precedence, though check that behavior in your Roo version before relying on it.

{
  "mcpServers": {
    "sume": {
      "type": "streamable-http",
      "url": "https://mcp.sume.com/mcp",
      "headers": { "x-api-key": "<SUME_API_KEY>" },
      "alwaysAllow": ["tools_list", "mcp_health"]
    }
  }
}

Quick diagnostic

If Sume behaves differently in one repository than everywhere else, look for a .roo/mcp.json with a server of the same name. Then run mcp_health to see the auth source Sume recorded and tools_list to see which tools that session can see.

Roo's per-server network timeout defaults to 60 seconds and ranges from 1 to 3600 seconds; the project entry is the one that applies when it overrides the name. Sume's gates, including idempotency_key on paid calls, are in Tools and gates.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume