Azure AI Foundry MCP tool: connect an agent to Sume

Add an MCP tool to an Azure AI Foundry agent: a Custom keys connection for Sume's API key, then server_url, allowed_tools, and require_approval.

6 min readSume
All posts

Azure AI Foundry's MCP tool connects a Foundry agent to a remote MCP server: you add an mcp tool with a server_label and a server_url, keep the credentials in a project connection that project_connection_id names, and approve each call unless require_approval says otherwise. For Sume's hosted MCP server, server_url is https://mcp.sume.com/mcp, and the connection is a Custom keys connection with the key Authorization and the value Bearer plus a Sume API key.

Microsoft's side comes from Connect agents to Model Context Protocol servers, which calls the product Microsoft Foundry, and the MCPTool Python reference; Sume's side comes from MCP OAuth and API keys, MCP tools and gates, and Jobs and results, all read on 2026-09-28. Sume has no official Foundry integration: the agent connects to Sume's remote MCP server by URL, and Microsoft says it doesn't test or verify third-party MCP servers. Sume's basics page says hosted MCP still works but is not part of the primary path today. For OpenAI's own MCP tool, see OpenAI Responses API MCP tool.

Where does the Sume API key go?

In a project connection, not in code: Microsoft's page says to keep API keys and bearer tokens in a project connection instead of hard-coding them in your app. In Microsoft Foundry, select Manage in the upper-right navigation, then Project details, then the Connected resources tab; create a connection of Custom keys type and add the key Authorization with the value Bearer <your Sume API key>. Microsoft's page also shows the azd form, run after azd ai project set with your project endpoint. Creating a project connection needs the Foundry Project Manager role.

Use Custom keys rather than OAuth. Foundry's managed OAuth app covers only the servers on Microsoft's list, and your own app registration needs a client ID and client secret; Sume's current server registers only public clients, so it has no client secret to give you.

azd ai connection create sume-mcp \
  --kind remote-tool \
  --target https://mcp.sume.com/mcp \
  --auth-type custom-keys \
  --custom-key "Authorization=Bearer $SUME_API_KEY"

How do I add Sume as an MCP tool on a Foundry agent?

Attach an MCPTool to a prompt agent, as in Microsoft's Python sample, and name the connection in project_connection_id. List only the Sume tools the agent needs in allowed_tools; without it, the agent gets every tool on the server, and a key session sees Sume's full hosted tool set. Run one test call before you build on it: generate_image has a parameter that matches Microsoft's stated cause of the Invalid tool schema error, as the errors section below explains.

From Microsoft's Connect agents to Model Context Protocol servers; Sume values from MCP tools and gates, read 2026-09-28.
FieldWhat Microsoft's page saysFor Sume
server_urlThe URL of the MCP server.https://mcp.sume.com/mcp
server_labelA unique identifier of this MCP server to the agent.sume
allowed_toolsOptional; without it, all of the server's tools.Only the tools the task needs
require_approvalalways (the default), never, or a never or always list of tool names.always for paid tools
project_connection_idThe project connection that stores authentication details.sume-mcp
import os
from azure.identity import DefaultAzureCredential
from azure.ai.projects import AIProjectClient
from azure.ai.projects.models import MCPTool, PromptAgentDefinition

project = AIProjectClient(endpoint=os.environ["FOUNDRY_PROJECT_ENDPOINT"],
                          credential=DefaultAzureCredential())
sume = MCPTool(
    server_label="sume",
    server_url="https://mcp.sume.com/mcp",
    allowed_tools=["mcp_health", "generate_image", "jobs_wait", "jobs_result"],
    require_approval="always",
    project_connection_id="sume-mcp",
)
agent = project.agents.create_version(
    agent_name="sume-agent",
    definition=PromptAgentDefinition(
        model=os.environ["FOUNDRY_MODEL_DEPLOYMENT_NAME"],
        instructions="Use Sume tools only when the user asks for media.",
        tools=[sume],
    ),
)

How do approvals work for Sume's paid tools?

With approval required, the response carries an mcp_approval_request item naming the tool and its arguments. Review them, then send a follow-up request with previous_response_id set to that response and an mcp_approval_response item carrying the request's id as approval_request_id and approve: true; OpenAI Responses API MCP tool walks through the same item types. A {"never": [...]} list names tools that skip approval, which suits Sume's job reads such as jobs_wait; keep generate_image and other paid tools on approval, as Microsoft advises for high-risk operations. Each paid Sume call also needs an idempotency_key, dry_run=true previews admission and cost without submitting the job, and max_spend_usd caps a call only when it is sent.

Will a long Sume job hit Foundry's 100-second timeout?

Not if the agent waits in slices. Non-streaming MCP tool calls in Foundry time out after 100 seconds, and Sume's jobs_wait holds one call for at most 55. On wait_slice_expired, the agent should call jobs_wait again with the same ids and never resubmit the paid create.

Foundry's background mode for longer MCP calls is in preview and needs a server that implements the MCP tasks capability. Sume's server declares only the tools capability in current code, so background mode doesn't change how Sume jobs are waited on.

What errors can Foundry show with Sume?

  • Unauthorized or Forbidden: check the credentials in the project connection, including the Bearer prefix.
  • Invalid tool schema: Microsoft says this usually happens when a server's tool definitions include anyOf or allOf, or a parameter accepts multiple types. In Sume's current code some do: avatars_search uses anyOf for its best_for filter, and generate_image's image_size takes a preset name, a width-and-height object, or a WIDTHxHEIGHT string. You can't change Sume's definitions, and Microsoft doesn't say whether allowed_tools avoids the check.
  • The model never calls the tool: check that server_label, server_url, and allowed_tools match what the server exposes. Sume's tool ids are underscore names such as generate_image.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume