Claude Code allowedMcpServers: the serverUrl rule for mcp.sume.com
Allow only Sume's hosted MCP endpoint in Claude Code managed settings with an allowedMcpServers serverUrl entry, and what the rule does not control.

To allow Sume in a managed Claude Code setup, add an allowedMcpServers entry whose serverUrl matches https://mcp.sume.com/mcp. The Claude Code docs show the pattern form https://mcp.example.com/*, so a Sume rule is https://mcp.sume.com/*. The rule only decides which servers users may connect to. It does not change what a Sume session can do once connected.
Check your own precedence and deny rules on the vendor page before you roll it out. I only read the allowlist example, not every edge case.
The rule
Put this in the managed MCP configuration, the same place you keep other organization-wide server rules:
{
"allowedMcpServers": [
{ "serverUrl": "https://mcp.sume.com/*" }
]
}What the allowlist does not decide
The allowlist answers one question: may this client connect to this URL. Sume answers a different one: what may this session do. OAuth sessions get mcp:read by default and mcp:write only if the person turns the Write toggle on at consent. API-key sessions see every hosted tool. Paid and write calls still need an idempotency_key.
So an allowlisted Sume entry is not a read-only entry. If you want agents on read-only, say so in your onboarding: connect with OAuth and leave Write off.
Host coverage
A serverUrl pattern is host-specific. The production endpoint is mcp.sume.com; development uses mcp.dev.sume.com, which this rule does not cover. If your team tests against the development host, add it deliberately instead of widening the pattern.
Verify after rollout
On a managed machine, add the server and sign in, then ask the agent to call mcp_health and tools_list. The first confirms the endpoint and auth source, the second shows the tools that session can see.
claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume| Control | Where it lives | What it decides |
|---|---|---|
| allowedMcpServers serverUrl | Claude Code managed settings | Which MCP URLs may be added |
| mcp:read / mcp:write | Sume OAuth consent | Which Sume tools the session sees |
| idempotency_key | Each write or paid call | Retry safety, not approval |
| max_spend_usd | Optional per call | Spend limit, only if you send it |
Sources
Related posts
More in Developers
- claude mcp add --header Bearer: a Sume API key for CI runs
For unattended Claude Code runs, pass a Sume API key as a Bearer header. That session sees every tool, so cap spend and send idempotency keys.
- Claude Code MCP scope: local, project or user for the Sume server
Use project scope for a shared .mcp.json with the Sume URL only, user scope for your own machine, and keep API keys out of shared files.
- Codex 0.160.0 MCP status for one server: confirm Sume with mcp_health
Codex 0.160.0 adds single-server MCP status discovery with thread connection reuse. Confirm the Sume session itself with mcp_health and tools_list.
- Codex 0.160.1 remote stdio MCP fix: does it affect Sume?
Codex 0.160.1 preserves SYSTEMROOT, TEMP and TMP for remote stdio MCP launches on Windows hosts. Sume's hosted MCP is HTTP, so no process is launched.
Written by Sume