Claude allowedPluginMcpServers and denied list for Sume URL

Claude admins can allow or deny plugin MCP servers by URL pattern. How to allow mcp.sume.com/mcp and what a deny match does even when allowed.

5 min readSume
All posts

To let installed plugins reach Sume while keeping control, add https://mcp.sume.com/mcp to allowedPluginMcpServers and review deniedPluginMcpServers for any pattern that would also match it. Claude Desktop added the allow list in v2.2553.0 and v1.40609.0 and the deny list in v2.16120.0 (2026-09-29), and a deny match stays blocked even if the same server is allowed.

That precedence is the part most likely to surprise an admin who writes a broad deny pattern first.

Allow, deny and precedence

allowedPluginMcpServers limits which MCP servers bundled in plugins may run. deniedPluginMcpServers takes URL patterns and blocks any match. The changelog is explicit that deny wins.

At a glance

Plugin MCP admin lists, read 2026-10-03.
SettingIntroducedEffect
allowedPluginMcpServersv2.2553.0 and v1.40609.0Allow list for plugin servers
deniedPluginMcpServersv2.16120.0 (2026-09-29)URL patterns, deny beats allow
Sume endpoint to allown/ahttps://mcp.sume.com/mcp

Writing a pattern that does not catch Sume by accident

If you block a whole domain family for data-loss reasons, check that the pattern does not match mcp.sume.com. Sume's hosted server is one fixed host and one path, so an allow entry for the exact URL is short and easy to audit.

Sume's read-only OAuth scope exposes only read tools, so an allowed server is not automatically a write-capable one. Users opt in to mcp:write on the consent page.

  • Allow the exact URL https://mcp.sume.com/mcp.
  • Search your deny patterns for wildcard hosts before rollout.
  • Remember that plugin MCP rules are separate from the connector the user adds by hand.

Limits and what is not verified

The exact pattern syntax for deniedPluginMcpServers is defined by Anthropic's admin documentation, which I did not reproduce here. Test any wildcard pattern in a pilot group first.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume