Theia AI remote MCP server: serverUrl and serverAuthToken for Sume

Theia AI's remote MCP config takes serverUrl, serverAuthToken and an optional serverAuthTokenHeader. The entry for Sume's hosted MCP with a Bearer API key.

5 min readSume
All posts

The answer

In Theia AI, add an entry under the MCP Servers Configuration preference with serverUrl set to https://mcp.sume.com/mcp and serverAuthToken set to a Sume API key. Theia's documentation says that when serverAuthTokenHeader is not provided, it sends the token as Authorization with the Bearer scheme, and that is the header Sume accepts for API keys.

Keep the key out of shared settings. Theia's page shows the token written directly in the entry, so put it only in user-level preferences, never in a workspace file that lives in version control.

The entry

Theia's remote server options are serverUrl, serverAuthToken, serverAuthTokenHeader, oauth and autostart, which defaults to true. The entry key becomes part of the tool name used in prompts, so choose a short one.

{
  "sume": {
    "serverUrl": "https://mcp.sume.com/mcp",
    "serverAuthToken": "sume_live_REPLACE_ME",
    "autostart": true
  }
}

Fields and what Sume does with them

The table pairs each documented Theia option with the Sume behaviour it meets.

Theia remote MCP options against Sume's hosted MCP (read 2026-10-03)
Theia optionDocumented behaviourWith Sume
serverUrlURL of the remote MCP serverhttps://mcp.sume.com/mcp
serverAuthTokenAuthentication token, if requiredA Sume API key
serverAuthTokenHeaderHeader name; default is Authorization with BearerLeave unset
autostartConnect when the IDE starts; default trueFine for a read-mostly workflow

What you get after it connects

With an API key the full hosted tool set is available, and Sume's gates apply: write and paid tools need an idempotency_key, dry_run previews admission without submitting, and max_spend_usd is enforced when provided. Theia notes that a server must be started in the current session with the MCP: Start MCP Server command if autostart only takes effect on the next restart.

Because a wait is capped, ask the agent to repeat jobs_wait rather than request a longer one. Sume's docs say remote waits default to 50 seconds and are capped at 55, and that a ten-minute render is waited for by repeating the wait.

If you would rather not store a key

Theia also documents an oauth block for remote servers that use OAuth 2.1, with Theia acting as a public client using PKCE. Sume's hosted MCP supports OAuth with mcp:read and an opt-in mcp:write, so the token-free option exists; the next step is to try the sign-in and read what the consent screen grants.

A check after the first start

Start the server with the MCP: Start MCP Server command and read the notification Theia shows. It confirms the operation and lists the functions the server made available. If you expected submitting tools such as generate_image and only read tools appear, the credential is not the API key you meant to use, or you are on an OAuth session without write.

Call tools_list first from a chat and look at the names. Sume's own docs recommend asking tools_schema for a tool before using it, for example to learn how idempotency_key works on a paid tool, so a quick schema read is a normal first step rather than an extra.

For a paid submit, include dry_run once to preview admission, then run it for real with a stable idempotency_key. The key is for transport and deduplication, not human approval, so choose one per intent and reuse it only on a genuine retry.

Browser deployments

Theia's page notes that in a browser deployment MCP servers are scoped per connection, so if you start one manually you need to start it once per browser tab. Autostart removes that chore. If several people share one Theia deployment, remember that a token typed into a shared preference is shared too; give each person their own key through user-level settings so usage and revocation stay per person.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume