Which coding clients can authenticate to Sume: key or OAuth?
Five coding clients (JetBrains, Jan, Kimi Code CLI, Tabnine, Augment) and the credential route each vendor page documents for Sume's endpoint.

Of five clients checked on 2026-10-02, Jan and Kimi Code CLI document an OAuth sign-in that fits Sume, Kimi and Tabnine document header-based API keys, and the JetBrains AI Assistant and Augment extension pages document a URL but not a credential. Sume needs one or the other.
Sume's hosted endpoint accepts an OAuth access token or an API key (bearer or x-api-key). A client that can do neither cannot connect, however well it handles the URL.
What does Sume require from a client?
From the OAuth and API keys page: for OAuth the client follows the protected-resource metadata, sends the user to the consent page on the MCP host, and exchanges the code with PKCE. For an API key, it sends Authorization: Bearer <key> or x-api-key. OAuth defaults to mcp:read; Write is an opt-in at consent. A key sees the full tool set.
What does each vendor page document?
Only what each page says, nothing inferred:
| Client | OAuth sign-in | Static header | Fits Sume as documented |
|---|---|---|---|
| Jan | Yes: metadata discovery, dynamic registration, PKCE | Not documented | OAuth route |
| Kimi Code CLI | Yes: --auth oauth, kimi mcp auth | Yes: --header "KEY: value" | Either route |
| Tabnine | Described for SSE servers only | Yes: requestInit.headers | Key route |
| Augment extension | Not documented | Not documented | Unconfirmed |
| Augment CLI | Not documented | Yes: headers in add-json | Key route |
| JetBrains AI Assistant | Not documented | Not documented | Unconfirmed |
How do you test an unconfirmed client?
Add the entry with only the URL, Apply, and look at the connection state. A client that supports OAuth will usually start a sign-in on its own; one that does not will show an authorization error and no tools. If it shows no sign-in, try the header route if one exists, and if neither works, run the same job from a client in the table that does document a route.
A successful connection is proven by mcp_health (check the auth source) and tools_list, as the Sume quickstart suggests.
Which route should you prefer?
OAuth for interactive use: it is the preferred path in the Sume docs, defaults to read-only, and keeps keys out of config files. API keys for automation, in a file that is not committed, rotated if exposed. Do not mint an API key just to work around a client that lacks OAuth for a person to use; the docs call that out as a workaround to avoid for hosted OAuth clients.
What does this table not tell you?
It reflects the pages as read on 2026-10-02, not the software itself. A client can support more than its documentation says, and documentation can lag a release. Treat a not documented cell as a prompt to test, not as a no.
It also says nothing about tool counts, approval prompts or timeouts, which differ by client and decide how safe a paid call is. Check the client's tool timeout against Sume's 55 second wait cap, and its approval mode against how much you trust the session, before the first real generation.
Sources
- JetBrains AI Assistant: Model Context Protocol (MCP) (read 2026-10-02)
- Jan: MCP Servers (read 2026-10-02)
- Kimi Code CLI docs: Model Context Protocol (read 2026-10-02)
- Tabnine docs: Understanding MCP Servers (read 2026-10-02)
- Augment docs: MCP setup (read 2026-10-02)
- Augment docs: CLI integrations (read 2026-10-02)
- MCP OAuth and API keys
- MCP quickstart
Related posts
More in Comparisons
- Best Sume image model for text in images: five catalog ids compared
Vendors pitch text rendering: Ideogram typography, FLUX.2 flex, Qwen-Image 2.0 Pro, Seedream. Which of those ids does Sume list, and how to test them yourself.
- Wistia Localize translates the transcript: same order on Sume
Wistia lists $2 per minute per language and translates the editable transcript, not the audio. Here is that transcript-first order built from Sume steps.
- YouTube Edit with AI limits: Shorts app vs Create app
Edit with AI takes up to 3 minutes of assets in the Shorts camera and 5-second to 5-minute clips in YouTube Create. Limits side by side, plus Sume Timeline.
- YouTube Studio clips and Shorts tool vs Sume trim and captions
YouTube's clips tool cuts Shorts from your long videos inside Studio. Sume does the same file work by API, with trim, captions and Timeline. When to use which.
Written by Sume