ant apply agent file: declare the Sume server, keep the key out

In an ant apply agent file, declare the Sume server by name and URL, https://mcp.sume.com/mcp. The API key belongs in a vault, never in the committed file.

4 min readSume
All posts

Put only the server name and URL, https://mcp.sume.com/mcp, in the agent file you commit, and supply the Sume API key through a vault credential. The file is reviewed and locked in your repository, so a key inside it would be committed with it.

Vendor facts are from the ant apply page (CLI 1.30.0 or later); Sume facts from the MCP overview and OAuth and API keys, read 2026-10-01.

What does ant apply do?

It creates and updates Claude API resources from files: agents, environments, skills, memory stores, deployments and vaults. You run it, approve the plan it prints, then commit the claude-lock.json it writes so the next run updates the same resources instead of creating new ones.

What goes in the file and what does not?

Sume values for an agent file, read 2026-10-01
ValueIn the committed file?Source
MCP URL https://mcp.sume.com/mcpYesMCP overview
Header x-api-key: $SUME_API_KEYNo, produced by the vault credentialOAuth and API keys
Write accessNot a file setting: OAuth mcp:write or an API keyThere is no mcp:paid scope
idempotency_keyNot config: passed on every write or paid callRequired on write and paid tools

Does reviewing the plan cover paid calls?

Not by itself. The plan approves resource changes, not each generation. Sume's gate is per call: idempotency_key is transport and dedup, not human approval. Spend is wallet and admission, so add dry_run guidance to the agent's system prompt.

What should I check after applying?

Start a session and have the agent call mcp_health, which reports endpoint, auth source and safety posture. If it reports a read-only session, the credential is the problem, not the agent file.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume