Egress firewall for a Claude agent in CI: Sume hosts to allow
Claude Agent SDK v0.2.164 hardens CI egress firewalls. Which Sume hosts a render job needs: api.sume.com, mcp.sume.com and media.sume.com, and what each is for.

If your CI locks outbound traffic, a Sume video agent needs three hosts: mcp.sume.com for the hosted MCP server, api.sume.com for the REST API, and media.sume.com for the finished files. The Claude Agent SDK for Python v0.2.164 (Oct 6) lists CI egress-firewall hardening, so this is a good week to write the allow list down.
What does the SDK release say?
The releases page lists v0.2.164 as bundling CLI 2.1.292 with CI egress-firewall hardening. It gives no host list, so allow-list your own model provider and anything else the SDK needs from its docs.
| Version | Date | Item |
|---|---|---|
| v0.2.164 | Oct 6 | Bundled CLI 2.1.292; CI egress-firewall hardening |
Which Sume hosts, and why?
Each host has one job.
| Host | Used for |
|---|---|
| mcp.sume.com | Hosted MCP at /mcp, plus OAuth metadata under /.well-known |
| api.sume.com | REST API, job status, Agent Completions |
| media.sume.com | Durable URLs for generated and imported media |
Which do you actually need?
It depends on the run:
- MCP only with an API key:
mcp.sume.com, andmedia.sume.comif the job downloads files. - OAuth sign-in in CI: also allow the metadata paths on
mcp.sume.com. A key is simpler for unattended jobs. - Agent Completions or the CLI:
api.sume.com. - A webhook for terminal events goes the other way: Sume calls your public HTTPS URL.
What fails when a host is blocked?
A blocked mcp.sume.com looks like an MCP server that never connects. A blocked media.sume.com means jobs finish but downloads fail, and you pay for the render either way. Test with mcp_health first and a free read like balance_get. See MCP quickstart.
Sources
Related posts
More in Developers
- Claude Code 2.1.295 MCP changes: a checklist for Sume
Three MCP changes in Claude Code 2.1.295 (Oct 8) and what each means for a connection to Sume's hosted server. A short table to run through after upgrading.
- Claude Code hooks on Sume tool calls: check the top-level guards
A Claude Code hook that gates paid Sume MCP calls should read the top-level idempotency_key, dry_run and max_spend_usd, and deny when input is unreadable.
- claude -p --max-budget-usd does not cap Sume renders
Claude Code's --max-budget-usd is a client-side estimate of API spend in print mode. Pair it with max_spend_usd on every paid Sume call and leave headroom.
- claude -p --max-turns exits with an error: Sume job in flight
When --max-turns ends a CI run, a Sume job may still be rendering. Keep the job id in the output, resume with jobs_wait, and never repeat the paid create.
Written by Sume