Egress firewall for a Claude agent in CI: Sume hosts to allow

Claude Agent SDK v0.2.164 hardens CI egress firewalls. Which Sume hosts a render job needs: api.sume.com, mcp.sume.com and media.sume.com, and what each is for.

4 min readSume
All posts

If your CI locks outbound traffic, a Sume video agent needs three hosts: mcp.sume.com for the hosted MCP server, api.sume.com for the REST API, and media.sume.com for the finished files. The Claude Agent SDK for Python v0.2.164 (Oct 6) lists CI egress-firewall hardening, so this is a good week to write the allow list down.

What does the SDK release say?

The releases page lists v0.2.164 as bundling CLI 2.1.292 with CI egress-firewall hardening. It gives no host list, so allow-list your own model provider and anything else the SDK needs from its docs.

Claude Agent SDK for Python releases (read 2026-10-09)
VersionDateItem
v0.2.164Oct 6Bundled CLI 2.1.292; CI egress-firewall hardening

Which Sume hosts, and why?

Each host has one job.

Sume hosts for an agent job
HostUsed for
mcp.sume.comHosted MCP at /mcp, plus OAuth metadata under /.well-known
api.sume.comREST API, job status, Agent Completions
media.sume.comDurable URLs for generated and imported media

Which do you actually need?

It depends on the run:

  • MCP only with an API key: mcp.sume.com, and media.sume.com if the job downloads files.
  • OAuth sign-in in CI: also allow the metadata paths on mcp.sume.com. A key is simpler for unattended jobs.
  • Agent Completions or the CLI: api.sume.com.
  • A webhook for terminal events goes the other way: Sume calls your public HTTPS URL.

What fails when a host is blocked?

A blocked mcp.sume.com looks like an MCP server that never connects. A blocked media.sume.com means jobs finish but downloads fail, and you pay for the render either way. Test with mcp_health first and a free read like balance_get. See MCP quickstart.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume