Claude Code MCP error showed a Bearer token: rotate the Sume key
If an MCP error or log exposed a Sume Bearer value, rotate the API key. An OAuth token is not an API key. Report issues with the request id, not the key.

If an MCP error message or log showed your Sume Bearer value, treat that key as exposed and rotate it. Sume's docs say to rotate API keys if they appear in logs or chat history.
The Claude Code changelog, read 2026-09-30, lists 2.1.286 fixes: MCP error messages showing a credential's value when "Bearer" or "Basic" came before its key name, and percent-encoded Bearer tokens being only partly masked. Updating Claude Code stops new leaks of that kind; it does not un-leak a value already in a log.
What do I rotate?
It depends on which credential was shown. Per MCP OAuth and API keys, an MCP OAuth token is not a Sume API key.
| Credential in the log | What the docs say |
|---|---|
| Sume API key | Rotate if it appears in logs or chat history; create keys in the dashboard |
| MCP OAuth token | Not an API key; do not store in CLI config, paste into prompts, or forward |
How do I rotate and clean up?
Create a replacement key in the dashboard, switch your Claude Code MCP header or secret to it, then revoke the old one. Search the places the error could have landed, such as CI logs, terminal scrollback and pasted chat, and redact them. Step-by-step help is in exposed API key: what to do.
What do I send when I report the error?
Send the Sume request id, which is in the response body and headers. The errors docs say not to include API keys, signed URLs, raw media URLs, or private workspace and user ids.
Sources
Related posts
More in Developers
- Claude Code list_changed and reconnect: refresh Sume tools
Claude Code refreshes an MCP server's tools on list_changed and lets you reconnect from /mcp. After changing Sume's Write consent, verify with tools_list.
- Claude Code reserved MCP server name: widgets, and Sume's name
Claude Code 2.1.285 reserves the MCP server name widgets in cloud sessions and on self-hosted runners. Sume's documented name is sume, so nothing to rename.
- claude -p --permission-prompt-tool with Sume paid jobs
Headless claude -p can route permission prompts to an MCP tool. For Sume paid jobs, keep idempotency_key stable and wait with jobs_wait in 55s slices.
- claude plugin validate and an insecure URL in .mcp.json
Claude Code 2.1.283 added MCP checks to claude plugin validate, including insecure URLs. Sume's hosted endpoint is https, so a plain entry has nothing to flag.
Written by Sume