Claude Code allowedMcpServers: the serverUrl rule for mcp.sume.com

Allow only Sume's hosted MCP endpoint in Claude Code managed settings with an allowedMcpServers serverUrl entry, and what the rule does not control.

4 min readSume
All posts

To allow Sume in a managed Claude Code setup, add an allowedMcpServers entry whose serverUrl matches https://mcp.sume.com/mcp. The Claude Code docs show the pattern form https://mcp.example.com/*, so a Sume rule is https://mcp.sume.com/*. The rule only decides which servers users may connect to. It does not change what a Sume session can do once connected.

Check your own precedence and deny rules on the vendor page before you roll it out. I only read the allowlist example, not every edge case.

The rule

Put this in the managed MCP configuration, the same place you keep other organization-wide server rules:

{
  "allowedMcpServers": [
    { "serverUrl": "https://mcp.sume.com/*" }
  ]
}

What the allowlist does not decide

The allowlist answers one question: may this client connect to this URL. Sume answers a different one: what may this session do. OAuth sessions get mcp:read by default and mcp:write only if the person turns the Write toggle on at consent. API-key sessions see every hosted tool. Paid and write calls still need an idempotency_key.

So an allowlisted Sume entry is not a read-only entry. If you want agents on read-only, say so in your onboarding: connect with OAuth and leave Write off.

Host coverage

A serverUrl pattern is host-specific. The production endpoint is mcp.sume.com; development uses mcp.dev.sume.com, which this rule does not cover. If your team tests against the development host, add it deliberately instead of widening the pattern.

Verify after rollout

On a managed machine, add the server and sign in, then ask the agent to call mcp_health and tools_list. The first confirms the endpoint and auth source, the second shows the tools that session can see.

claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume
Allowlist versus Sume session controls, read 2026-10-07
ControlWhere it livesWhat it decides
allowedMcpServers serverUrlClaude Code managed settingsWhich MCP URLs may be added
mcp:read / mcp:writeSume OAuth consentWhich Sume tools the session sees
idempotency_keyEach write or paid callRetry safety, not approval
max_spend_usdOptional per callSpend limit, only if you send it

Sources

Related posts

More in Developers

All Developers posts

Written by Sume