Which Sume MCP URL? mcp.sume.com/mcp, not the dev host or Studio

Add https://mcp.sume.com/mcp as the connector. The dev host is internal, and Studio Agent is a separate product, not the hosted MCP connector.

3 min readSume
All posts

The URL

The hosted MCP connector for Sume is https://mcp.sume.com/mcp. Add exactly that URL to your MCP client. You sign in with OAuth, or you send an API key as a Bearer token or an x-api-key header.

Two nearby names cause confusion. A host with dev in its name, such as mcp.dev.sume.com, is internal and is not for customers. Studio Agent is the agent inside the Sume app, and it is not the MCP connector, so configuring it will not give your own client any tools.

Names that are not the connector

The table lists what to use and what not to, as of 2026-10-08.

Sume MCP names and what they are, as of 2026-10-08
NameWhat it isUse it as the connector?
https://mcp.sume.com/mcpHosted MCP for customersYes
mcp.dev.sume.comInternal development hostNo
Studio AgentAgent inside the Sume appNo
REST API at api.sume.comHTTP API for Formats, Images, VideosNot MCP

Confirm the connection

After you add the URL, call mcp_health and check that authenticated.auth_source is mcp_oauth. Then call tools_list. If the connector cannot be added at all, check the OAuth metadata URLs with curl before you retry, since a client that cannot read them will fail with an unhelpful message.

curl -sS https://mcp.sume.com/.well-known/oauth-protected-resource/mcp | jq .

Scopes and keys

OAuth grants mcp:read and an optional mcp:write toggle. There is no mcp:paid scope. An API key gives the full tool set. Choose OAuth for people and short sessions, and a key for unattended agents that must write.

Remember that Image 1.0 and Video 1.0 creation is REST-only, so you will not find images_create or videos_create in the tool list, whichever URL you use.

  • One URL for production: https://mcp.sume.com/mcp.
  • Write toggle off means a read-only session.
  • Keys go in headers, never in the URL.

Why the distinction exists

The connector is a public, supported surface with documented scopes and gates. The dev host and the in-app agent have different auth and different change cadence, and the docs say not to build on them. Copying a URL from a screenshot or an old thread is how most people end up there.

If you manage connectors for a team, publish the one URL in your internal docs and check it in a review.

  • Check the URL in your client config today.
  • Re-run mcp_health after changing it.
  • Treat these as working notes you can adapt: the figures are from the Sume docs read on 2026-10-08, and the arithmetic is yours to rerun with your own numbers.

Make it routine

Add this check to your runbook and run it on a schedule, not only after an incident. The cost is a few read requests, and the rate limits are far above what it needs: even the Free plan allows 120 writes and 4,800 reads per minute. Keep the output with the date, so you can show later what the system looked like when a question came up.

Check the authentication path before the URL. OAuth shows a consent page that asks for read, with write as a toggle. An API key goes in a Bearer header or in x-api-key. If you send both, the one the server picks will decide what mcp_health reports, so use one at a time while you debug.

  • Remove old keys from the client config.
  • Reconnect after changing scopes.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume