v0 custom MCP: connect Sume with a Bearer token or OAuth

In v0, open the + menu, choose MCPs, add a custom MCP and pick Bearer Token or OAuth for auth. Which to use for Sume's hosted server, and what each grants.

5 min readSume
All posts

In v0, open the "+" menu in the prompt form, choose MCPs, add a custom MCP, enter https://mcp.sume.com/mcp, and pick an auth type. v0's docs list four: No Auth, Custom Headers, Bearer Token and OAuth. For Sume, choose OAuth when a person is at the keyboard, because the grant starts read-only; choose Bearer Token with an API key for a fixed, unattended setup.

v0's steps come from its MCP docs; Sume's from the MCP quickstart and OAuth and API keys, all read on 2026-10-06. Sume has no official v0 integration.

Which auth type should I pick?

The table below lists each item as documented.

v0 auth options from the v0 MCP docs and Sume behavior from docs.sume.com, read 2026-10-06.
v0 auth typeWorks with SumeWhat the session gets
OAuthYes, preferred for interactive clientsmcp:read always; mcp:write only if you grant it
Bearer TokenYes, with an API keyThe full tool set, including paid tools
Custom HeadersYes, x-api-key or AuthorizationSame as an API key
No AuthNoSume requires credentials

What happens during OAuth?

Sume's consent page lives on the MCP host: /oauth/authorize redirects to /oauth/consent on mcp.sume.com. The scopes are mcp:read (required) and mcp:write (opt-in); there is no paid scope. A write grant always includes read. The protected-resource metadata is published at /.well-known/oauth-protected-resource/mcp, which is how a client finds the authorization server.

Why not an API key by default?

An API key sees paid tools at once and an OAuth token is not a key, so do not mint a key to stand in for a failed OAuth flow. If v0 shows an unauthorized error, retry the OAuth connection; Sume's docs say OAuth is the path for interactive clients, and keys are for headless ones.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume