Devin Desktop ACP session/new mcp_servers with Sume's remote URL

Devin Desktop 3.10.35 uses MCP servers an ACP client passes in session/new. Pass Sume's streamable HTTP URL and an API-key header, not editor config.

4 min readSume
All posts

If your ACP client lists MCP servers in session/new, give it Sume as a streamable HTTP server at https://mcp.sume.com/mcp with an Authorization: Bearer <SUME_API_KEY> header. Devin Desktop 3.10.35 says such servers are usable by the agent and listed in /mcp, so no editor-side config file is needed.

Vendor behavior is from the Devin Desktop changelog (read 2026-10-01); Sume behavior from the MCP quickstart and OAuth and API keys.

What does the Devin Desktop changelog say?

Version 3.10.35 (September 24, 2026): "MCP servers passed by an ACP client in session/new / session/load are now usable by the agent and listed in /mcp, including for HTTP and SSE MCP servers." The changelog excerpt does not describe the field shape, so use your ACP client's own schema for the server entry.

What should the Sume entry contain?

Sume's quickstart says to point a streamable HTTP MCP server at the production URL. For a headless or embedded ACP client there is rarely a browser to finish OAuth, so the API-key path fits: the client sends Authorization: Bearer <SUME_API_KEY> or x-api-key.

Values for a Sume entry, from the docs read 2026-10-01.
FieldValue
TransportStreamable HTTP
URLhttps://mcp.sume.com/mcp
HeaderAuthorization: Bearer <SUME_API_KEY> or x-api-key
Visible toolsFull hosted set for an API key
Writes and paid callsNeed idempotency_key

How do I check the server loaded?

Open /mcp in Devin Desktop and look for the server, then ask the agent to call tools_list or mcp_health. The quickstart lists mcp_health as the call that confirms endpoint, auth source and safety posture. Before a first paid call, the docs suggest asking the agent to call tools_schema with name generate_image and explain idempotency_key and dry_run.

Should the key sit in the ACP payload?

Treat it as a secret: the docs say to rotate API keys if they appear in logs or chat history, and not to paste keys into chat. Inject it from the environment when your client builds the session/new request rather than writing it into a saved file. For the editor-config route see Devin MCP setup.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume