Claude Managed Agents vault static_bearer for Sume tools
For Sume's hosted MCP in a Claude Managed Agents vault, use a static_bearer credential keyed to https://mcp.sume.com/mcp; OAuth tokens last an hour.

Use a static_bearer credential holding a Sume API key, keyed to https://mcp.sume.com/mcp. Sume's OAuth access tokens expire after one hour and the vault's mcp_oauth type is built around refreshing, so an API key is the simpler fit for an unattended agent.
Vendor facts are from the Managed Agents vaults page; Sume facts from MCP OAuth and API keys and tools and gates, read 2026-10-01.
How do vault credentials find the MCP server?
The vaults page says MCP credentials (mcp_oauth, static_bearer) are each keyed by an mcp_server_url, and that the token is injected automatically when the agent connects to a server at that URL at session runtime. For Sume that URL is the documented hosted endpoint, character for character.
Which credential type fits Sume?
| Option | Sume side | Consequence |
|---|---|---|
static_bearer with an API key | Client sends Authorization: Bearer <SUME_API_KEY> or x-api-key | Full hosted tool set; paid calls still need idempotency_key |
mcp_oauth | Access token TTL is one hour | Session needs a working refresh path; read-only unless mcp:write was granted |
Does the key remove the spend gates?
No. The API-key row in the tools-and-gates auth table says the same idempotency_key and admission rules apply. Treat the key as access, and keep dry_run and max_spend_usd in the agent's instructions. See API key vs OAuth for the longer comparison.
How should I store the key?
The vaults page treats credential values such as token as sensitive, write-only fields that are never returned in API responses. Put the Sume key there, not in the agent's prompt, and rotate it if it appears in logs, as the Sume docs advise.
Sources
Related posts
More in Integrations
- Sonnet 5.5 and a 10-minute render: about 12 jobs_wait calls
A Sume job that takes ten minutes needs roughly 11 to 12 jobs_wait calls at the 55 and 50 second slices. How to keep a Sonnet 5.5 tool loop that short.
- Code by Zapier 225 requests per 10 seconds and Sume 429s
Zapier lists 225 requests per 10 seconds for Code by Zapier on Pro and Team. Sume has its own 429 rate_limited: honor retry-after and send an Idempotency-Key.
- Code by Zapier 10-minute runtime vs Sume's 30-second sync wait
Code by Zapier can run 10 minutes on action steps, but Sume's sync wait caps at 30 seconds. Submit async, keep the job id, and poll instead of holding the step.
- Codex network policy now follows redirects: allow Sume's hosts
Codex 0.157.0 enforces network restrictions across redirects and cancels traffic when a policy change revokes access. Which Sume hosts to allow.
Written by Sume