Can I swap a Sume MCP OAuth token for an API key? Why you should not
A hosted MCP OAuth token is not a Sume API key. Do not mint keys as a workaround for a read-only session; turn Write on at consent, or use a key on purpose.

No, and Sume's docs say not to try. An MCP OAuth token is not a Sume API key, and the OAuth page says not to mint API keys for hosted OAuth clients as a workaround. If your session is read-only and you want write tools, turn Write on at the consent page. If you want an API key, choose that path on purpose and connect with the key.
Two credentials, two jobs
The two rows on hand-offs are the point of the page's credential safety list: do not store OAuth tokens in CLI config, do not paste them into prompts, and do not forward them to third-party providers. The matrix itself is on the OAuth and API keys page.
| OAuth session | API key | |
|---|---|---|
| How the client sends it | MCP OAuth with protected-resource metadata | Authorization: Bearer or x-api-key header |
| Tool set | mcp:read: read-only tools; mcp:write adds write and paid tools | Full hosted tool set |
| Paid and write calls | Need mcp:write plus idempotency_key | Need idempotency_key |
| Best for | Interactive clients such as Cursor and Claude | Automation that does not use OAuth |
| If exposed in logs or chat | Do not paste it anywhere | Rotate the key |
Why not mix them
A mixed setup hides which login an agent is really using, and that decides what it can spend. If a client holds an OAuth token and an agent also has a key in its environment, a read-only session can quietly become a full-access one through the key. mcp_health shows the auth source, so use it to see which one a session is on.
If your goal is a read-only agent, keep it on OAuth with Write off and do not give it a key at all.
- Interactive client: OAuth, Write off unless you need it.
- Unattended automation: an API key, with
max_spend_usdanddry_runhabits. - Never put either credential in a prompt, a chat or a committed config file.
The tradeoff
OAuth tokens are short-lived by design, which limits damage from a leak, but an unattended job cannot sit through a browser sign-in. An API key fits that job and lasts until you rotate it. Picking the credential is picking where the risk sits: short-lived and interactive, or long-lived and automatic.
Sources
Related posts
More in Integrations
- Trae IDE: add Sume as a remote MCP server with Add Manually
In Trae, open Settings > MCP > Add > Add Manually and paste a JSON entry with Sume's hosted URL and an Authorization header. Steps, trade-offs, key handling.
- v0 custom MCP: connect Sume with a Bearer token or OAuth
In v0, open the + menu, choose MCPs, add a custom MCP and pick Bearer Token or OAuth for auth. Which to use for Sume's hosted server, and what each grants.
- Vercel Sandbox static egress IP: do I need to allowlist Sume?
Secure Compute gives Vercel Sandbox static egress IPs. Calling Sume needs only an API key over HTTPS; for webhooks into your app, verify the signature.
- Viber bot video message: 26 MB, 180 s, .mp4 URL, a Sume clip
Viber's bot API wants an MP4 URL ending in .mp4, 26 MB max, 180 s max, and a JPEG thumbnail. A 60 second Sume avatar clip fits. The checks to run first.
Written by Sume