Claude Managed Agents vault static_bearer for Sume tools

For Sume's hosted MCP in a Claude Managed Agents vault, use a static_bearer credential keyed to https://mcp.sume.com/mcp; OAuth tokens last an hour.

4 min readSume
All posts

Use a static_bearer credential holding a Sume API key, keyed to https://mcp.sume.com/mcp. Sume's OAuth access tokens expire after one hour and the vault's mcp_oauth type is built around refreshing, so an API key is the simpler fit for an unattended agent.

Vendor facts are from the Managed Agents vaults page; Sume facts from MCP OAuth and API keys and tools and gates, read 2026-10-01.

How do vault credentials find the MCP server?

The vaults page says MCP credentials (mcp_oauth, static_bearer) are each keyed by an mcp_server_url, and that the token is injected automatically when the agent connects to a server at that URL at session runtime. For Sume that URL is the documented hosted endpoint, character for character.

Which credential type fits Sume?

Credential options for Sume hosted MCP, read 2026-10-01
OptionSume sideConsequence
static_bearer with an API keyClient sends Authorization: Bearer <SUME_API_KEY> or x-api-keyFull hosted tool set; paid calls still need idempotency_key
mcp_oauthAccess token TTL is one hourSession needs a working refresh path; read-only unless mcp:write was granted

Does the key remove the spend gates?

No. The API-key row in the tools-and-gates auth table says the same idempotency_key and admission rules apply. Treat the key as access, and keep dry_run and max_spend_usd in the agent's instructions. See API key vs OAuth for the longer comparison.

How should I store the key?

The vaults page treats credential values such as token as sensitive, write-only fields that are never returned in API responses. Put the Sume key there, not in the agent's prompt, and rotate it if it appears in logs, as the Sume docs advise.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume