Codex bearer_token_env_var: connect Sume MCP with an API key, no OAuth

Set url and bearer_token_env_var in Codex's config.toml so a Sume API key from the environment authenticates hosted MCP, with enabled_tools to shorten the list.

4 min readSume
All posts

To connect Codex to Sume's hosted MCP server with an API key, add a server entry in Codex's config.toml with url set to https://mcp.sume.com/mcp and bearer_token_env_var set to the name of an environment variable that holds the key. Codex then sends the key as a Bearer token; the key itself never sits in the file.

The config keys come from Codex's MCP documentation, read 2026-09-29; the auth behavior comes from Sume's MCP OAuth and API keys page, which lists Authorization: Bearer and x-api-key as the two ways to send a key.

What does the config look like?

Codex's page lists url, bearer_token_env_var, http_headers, tool_timeout_sec and enabled_tools as options for a server. This entry uses three of them.

[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
bearer_token_env_var = "SUME_API_KEY"
enabled_tools = ["mcp_health", "generate_video", "jobs_wait", "jobs_result"]

When should I pick a key over OAuth?

OAuth suits a person at a keyboard. A key suits a script, a CI job or a machine with no browser. The two are not interchangeable credentials: an OAuth token is not an API key.

From Sume's MCP OAuth and API keys docs, read 2026-09-29.
ModeHow it connectsTools
OAuthcodex mcp login, consent on the MCP hostmcp:read by default; mcp:write if Write is on
API keyBearer token from an environment variableFull hosted tool set

What does a key change about spend?

With a key the paid tools are available without a consent step, so the controls matter more. Paid calls need an idempotency_key, dry_run=true previews admission and cost, and max_spend_usd is enforced when the call provides it.

Keep the key in your shell profile or secret store, rotate it if it appears in logs or chat, and do not paste it into a prompt.

Why list enabled_tools?

Sume's full tool set is long. Listing only the tools a task needs keeps the model's choice small; the four above cover a health check, one paid call, and collecting the result. A remote jobs_wait call holds at most 55 seconds, so set tool_timeout_sec above that if Codex cuts tool calls off sooner.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume