Can I swap a Sume MCP OAuth token for an API key? Why you should not

A hosted MCP OAuth token is not a Sume API key. Do not mint keys as a workaround for a read-only session; turn Write on at consent, or use a key on purpose.

4 min readSume
All posts

No, and Sume's docs say not to try. An MCP OAuth token is not a Sume API key, and the OAuth page says not to mint API keys for hosted OAuth clients as a workaround. If your session is read-only and you want write tools, turn Write on at the consent page. If you want an API key, choose that path on purpose and connect with the key.

Two credentials, two jobs

The two rows on hand-offs are the point of the page's credential safety list: do not store OAuth tokens in CLI config, do not paste them into prompts, and do not forward them to third-party providers. The matrix itself is on the OAuth and API keys page.

OAuth token versus API key on hosted MCP (Sume docs, read 2026-10-06)
OAuth sessionAPI key
How the client sends itMCP OAuth with protected-resource metadataAuthorization: Bearer or x-api-key header
Tool setmcp:read: read-only tools; mcp:write adds write and paid toolsFull hosted tool set
Paid and write callsNeed mcp:write plus idempotency_keyNeed idempotency_key
Best forInteractive clients such as Cursor and ClaudeAutomation that does not use OAuth
If exposed in logs or chatDo not paste it anywhereRotate the key

Why not mix them

A mixed setup hides which login an agent is really using, and that decides what it can spend. If a client holds an OAuth token and an agent also has a key in its environment, a read-only session can quietly become a full-access one through the key. mcp_health shows the auth source, so use it to see which one a session is on.

If your goal is a read-only agent, keep it on OAuth with Write off and do not give it a key at all.

  • Interactive client: OAuth, Write off unless you need it.
  • Unattended automation: an API key, with max_spend_usd and dry_run habits.
  • Never put either credential in a prompt, a chat or a committed config file.

The tradeoff

OAuth tokens are short-lived by design, which limits damage from a leak, but an unattended job cannot sit through a browser sign-in. An API key fits that job and lasts until you rotate it. Picking the credential is picking where the risk sits: short-lived and interactive, or long-lived and automatic.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume