Tabnine agent MCP: mcp_servers.json with requestInit headers for Sume

Add Sume's hosted MCP to Tabnine with a url entry in mcp_servers.json and an x-api-key header under requestInit. File locations, transport detection, caveats.

5 min readSume
All posts

Tabnine reads MCP servers from .tabnine/mcp_servers.json, either in the project root or your home directory. A remote Sume entry is a url of https://mcp.sume.com/mcp with the API key under requestInit.headers.

This is the header-based route to Sume, so it uses an API key rather than OAuth. Tabnine's page documents headers for remote servers, which is what Sume's API-key mode needs.

Where does the file go?

The Tabnine MCP page names two locations: .tabnine/mcp_servers.json in your project root, and ~/.tabnine/mcp_servers.json in your home directory. It also notes a project folder must be open for the MCP list to update. Use the home directory file so the key never lands inside a repository.

What does the Sume entry look like?

Tabnine detects Streamable HTTP when the entry has a url, and sends headers listed under requestInit. Sume accepts x-api-key or a bearer Authorization header:

{
  "mcpServers": {
    "sume": {
      "url": "https://mcp.sume.com/mcp",
      "requestInit": {
        "headers": {
          "x-api-key": "<your Sume API key>"
        }
      }
    }
  }
}

How does transport detection work?

Per the Tabnine page:

Tabnine transport detection, read 2026-10-02
Entry hasTransportUse for Sume
commandSTDIONo: Sume has no local server
urlStreamable HTTPYes
transport: "sse" set explicitlySSENo

What does the key unlock, and what should you watch?

An API key session sees the full hosted tool set, including paid tools, with idempotency_key required on each paid call and the wallet as the limit, as the OAuth and API keys page explains. Create the key in the Sume dashboard and rotate it if it appears in a log.

The Tabnine page does not describe a sign-in flow for Streamable HTTP entries (its OAuth note concerns SSE servers), so do not expect to use the OAuth route that read-only Sume sessions normally use. If you want a read-only Tabnine connection, there is no scoped key option in the docs read for this post, so keep paid-call instructions explicit: dry run first, max_spend_usd on every paid call.

How do you verify it?

With a project open, check that sume appears in Tabnine's MCP list, then ask the agent to call mcp_health and tools_list. The health answer reports the auth source, which should show an API key rather than OAuth.

What does Sume not do for Tabnine?

Sume has no local server to run, so a command entry is never right. Hosted MCP also does not read local files, and it does not offer Sume Image 1.0 or Video 1.0 tools; those are REST-only. For generation through the agent, use generate_image, generate_video, music_create or tts_create, and let payload.model default to sume/auto unless you want a specific family.

Long jobs are read with jobs_wait, which holds at most 55 seconds per call. If Tabnine's own tool timeout is shorter, the wait gets cut off even though the job continues, so keep waits short and repeat them. Never re-submit a paid create because a wait expired.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume