Cline cline_mcp_settings.json for Sume: streamableHttp and cline mcp

Where Cline keeps remote MCP config, the streamableHttp entry for Sume's hosted server, and the cline mcp wizard that reruns browser authorization.

5 min readSume
All posts

For Cline CLI, remote MCP servers live in ~/.cline/data/settings/cline_mcp_settings.json. A Sume entry sets type to streamableHttp, url to https://mcp.sume.com/mcp, and an Authorization header if you use an API key. In the IDE extensions you reach the same file from the MCP Servers panel, Configure tab. The Cline CLI also has a cline mcp wizard that can run or rerun browser authorization for a remote server.

What does the Sume entry look like?

Cline's page shows the fields type, url, headers, disabled and autoApprove. For an API key session against Sume:

  • Leave autoApprove empty so every paid call asks first.
  • Replace the placeholder yourself; never commit a real key.
  • Sume also accepts an x-api-key header, per its OAuth and API keys page.
{
  "mcpServers": {
    "sume": {
      "type": "streamableHttp",
      "url": "https://mcp.sume.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_SUME_API_KEY"
      },
      "disabled": false,
      "autoApprove": []
    }
  }
}

When should you use OAuth instead of a header?

With OAuth, the client discovers Sume's protected-resource metadata and sends you to the consent page on the MCP host. The default grant is mcp:read, which lists and reads but cannot create. Turn Write on at consent when you want generation. A key skips consent and sees the full tool set, so treat it like a wallet credential.

Cline's page says the wizard can rerun browser authorization but gives no further OAuth configuration detail, so confirm the exact steps in your installed version.

What should you check after saving?

Ask the agent to call mcp_health and check the auth source, then call tools_list. A read-only session lists fewer tools than a key session, which is expected.

Cline remote entry fields (Cline docs read 2026-10-11)
FieldValue for Sume
typestreamableHttp
urlhttps://mcp.sume.com/mcp
headersAuthorization: Bearer key, or omit for OAuth
disabledfalse
autoApprove[] until you trust specific read tools

How do you keep the key out of the repository?

The settings file for Cline CLI lives in your home directory, not inside a project, so a key placed there is not committed with your code by default. If you use the IDE extension and its Configure tab, confirm where the file is stored before you paste a key, and never copy the file into a repository.

If you rotate the key, edit the headers value and restart the server entry from the MCP Servers panel. Sume treats the key and an OAuth token as different credentials, so rotating one has no effect on the other.

For long renders, Sume's jobs_wait returns after at most 55 seconds, so an agent may call it several times for a single video. That is normal; the job keeps running between calls, and a status read with jobs_status is free.

Before you rely on any of this in a team setting, test it once end to end with a throwaway prompt. Call mcp_health, call tools_list, and run one dry_run against a paid tool. Compare the tool count with what you expected for your credential. If a read-only OAuth session lists more than you expected, or a key session lists fewer, stop and recheck which credential the client is actually sending. Sume's mcp_health response reports the auth source, which settles the question quickly without guessing.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume