AI SDK 7 createMCPClient: connect a remote HTTP MCP server
In AI SDK 7, createMCPClient takes an http transport with a url and headers. Point it at https://mcp.sume.com/mcp, load client.tools(), and close in finally.

Call createMCPClient with a transport of type: "http", the server url, and any headers. For Sume the URL is https://mcp.sume.com/mcp and the header is Authorization: Bearer $SUME_API_KEY. Then pass await client.tools() to generateText and close the client in a finally block.
The client shape comes from Vercel's AI SDK page (last updated 2026-09-18), which describes AI SDK 7 and Node.js 22 or newer. The Sume side comes from the MCP quickstart.
What does the connection code look like?
This is the whole wiring, with the model left for you to pass in. It asks the model to call tools_list, a read tool that lists everything visible to the session.
import { createMCPClient } from "@ai-sdk/mcp";
import { generateText, isStepCount } from "ai";
type Model = Parameters<typeof generateText>[0]["model"];
export async function sumeTools(model: Model) {
const client = await createMCPClient({
transport: {
type: "http",
url: "https://mcp.sume.com/mcp",
headers: { Authorization: `Bearer ${process.env.SUME_API_KEY}` },
},
});
try {
const { text } = await generateText({
model,
tools: await client.tools(),
stopWhen: isStepCount(5),
prompt: "Call tools_list and name the read-only tools.",
});
return text;
} finally {
await client.close();
}
}Which values are Sume-specific?
Only the URL and the credential. Everything else is the AI SDK's own shape.
| Value | What it is | Source |
|---|---|---|
type: "http" | HTTP transport in createMCPClient | Vercel AI SDK page |
https://mcp.sume.com/mcp | Sume's production MCP endpoint | Sume MCP quickstart |
Authorization: Bearer | API-key session, full hosted tool set | Sume MCP OAuth page |
isStepCount(5) | Stops the loop after five steps | Vercel AI SDK page |
Why an API key here and not OAuth?
The header in the sample is an API key, which suits server code with no person to sign in. Sume's docs list two modes: OAuth, which grants read-only access unless Write is switched on at consent, and an API key, which sees the full hosted tool set. See MCP server API key vs OAuth for the choice.
Because an API-key session can see write and paid tools, client.tools() hands them all to the model. Tool approval for paid video covers gating them.
Why close the client in finally?
Vercel's page closes the client in a finally block, and the sample does the same so a failed model call does not leave the connection open. Do not put the key in browser code; run this on a server.
How do I check it worked?
Sume's quickstart suggests tools_list as the first read-only call, and mcp_health confirms the endpoint, auth source, and safety posture. If the model returns names such as generate_image or jobs_wait, the key was accepted.
What can go wrong on the first connect?
A wrong or missing key is the usual cause. Sume's MCP page says mcp_health confirms the endpoint, auth source, and safety posture, so call it before blaming the SDK. Also remember the header rule: send one credential header only, since a request with both Authorization and x-api-key is rejected with 401 unauthorized.
Node.js 22 or newer is what Vercel's page lists for this setup. If the tool list comes back empty, check that you passed await client.tools() to generateText rather than the client itself, and that the client was still open when the call ran. Each new request should build its own client and close it when the response ends, as in the sample above.
Sources
Related posts
More in Developers
- AI SDK 7 isStepCount stopWhen: cap a paid tool loop
stopWhen: isStepCount(5) limits AI SDK steps, not spend. For paid Sume MCP tools, pair it with max_spend_usd, dry_run and an idempotency_key.
- AI SDK MCP client authorization bearer header: what to send Sume
Set headers.Authorization to Bearer plus your Sume API key on the AI SDK http transport, and send only one credential header. An OAuth token is not an API key.
- AI vendor risk assessment: questions and where to look
An AI vendor risk assessment adds training, model providers and spend to a SaaS review. The questions, and where Sume's public pages answer them.
- API audit log: what you can trace on Sume's media API
Sume's docs describe no audit-log endpoint. Job records, the usage ledger and request ids give a trail, but not which API key made a call.
Written by Sume