Devin Desktop ACP session/new mcp_servers with Sume's remote URL
Devin Desktop 3.10.35 uses MCP servers an ACP client passes in session/new. Pass Sume's streamable HTTP URL and an API-key header, not editor config.

If your ACP client lists MCP servers in session/new, give it Sume as a streamable HTTP server at https://mcp.sume.com/mcp with an Authorization: Bearer <SUME_API_KEY> header. Devin Desktop 3.10.35 says such servers are usable by the agent and listed in /mcp, so no editor-side config file is needed.
Vendor behavior is from the Devin Desktop changelog (read 2026-10-01); Sume behavior from the MCP quickstart and OAuth and API keys.
What does the Devin Desktop changelog say?
Version 3.10.35 (September 24, 2026): "MCP servers passed by an ACP client in session/new / session/load are now usable by the agent and listed in /mcp, including for HTTP and SSE MCP servers." The changelog excerpt does not describe the field shape, so use your ACP client's own schema for the server entry.
What should the Sume entry contain?
Sume's quickstart says to point a streamable HTTP MCP server at the production URL. For a headless or embedded ACP client there is rarely a browser to finish OAuth, so the API-key path fits: the client sends Authorization: Bearer <SUME_API_KEY> or x-api-key.
| Field | Value |
|---|---|
| Transport | Streamable HTTP |
| URL | https://mcp.sume.com/mcp |
| Header | Authorization: Bearer <SUME_API_KEY> or x-api-key |
| Visible tools | Full hosted set for an API key |
| Writes and paid calls | Need idempotency_key |
How do I check the server loaded?
Open /mcp in Devin Desktop and look for the server, then ask the agent to call tools_list or mcp_health. The quickstart lists mcp_health as the call that confirms endpoint, auth source and safety posture. Before a first paid call, the docs suggest asking the agent to call tools_schema with name generate_image and explain idempotency_key and dry_run.
Should the key sit in the ACP payload?
Treat it as a secret: the docs say to rotate API keys if they appear in logs or chat history, and not to paste keys into chat. Inject it from the environment when your client builds the session/new request rather than writing it into a saved file. For the editor-config route see Devin MCP setup.
Sources
Related posts
More in Developers
- ElevenLabs API timeout: cascade_timeout_seconds vs Sume waits
ElevenLabs added cascade_timeout_seconds (2-15 s) for Speech Engine retries. Sume's wait_timeout_seconds is a different knob: a 0-30 s HTTP wait on a job.
- ElevenLabs API cursor pagination, and how Sume pages lists
ElevenLabs added a cursor-paginated phone number endpoint. Sume list routes use keyset pages: pass next_cursor back as cursor until has_more is false.
- ElevenLabs Flows webhook: what changed, and Sume's per-job webhook
ElevenLabs Flows template runs can send a terminal result to a webhook, and webhook targets now need type all or ids. Sume sets the callback per job.
- is_final_audio_for_turn vs Sume TTS sentence boundaries: wav or mp3
ElevenLabs now emits is_final_audio_for_turn after every byte, even for MP3. Sume marks boundaries differently: sentence segments, sliced only for wav or raw.
Written by Sume