Claude Code cloud sessions: where Sume hosted MCP comes from

In Claude Code cloud sessions the host passes in MCP servers from your claude.ai organization settings. Add Sume as a connector there, not in a local file.

5 min readSume
All posts

For a Claude Code cloud session, Sume has to arrive through your claude.ai organization settings, not through a claude mcp add you ran on your own machine. Claude Code's MCP page says cloud sessions get their servers from the cloud host, which draws on your organization's claude.ai settings plus any allowlist, denylist and managed configuration that reach the session.

What does the Claude Code page say about cloud sessions?

The MCP page (read 2026-10-03) has a section on how connectors reach Claude Code. For cloud sessions it says the cloud host passes them in, from "your claude.ai organization settings, plus the allowlist and denylist settings that reach the session and any managed-mcp.json on the host that runs it". It adds that a call to a plugin server that is not connected yet, such as right after an idle session wakes, starts the server on demand and waits for it to connect.

Where do local installs store their servers?

The same page tables three scopes. They matter here because none of them is what a cloud session reads.

Claude Code MCP scopes (Claude Code docs, read 2026-10-03)
ScopeLoads inShared with teamStored in
Local (default)Current project onlyNo~/.claude.json
ProjectCurrent project onlyYes, via version control.mcp.json in project root
UserAll your projectsNo~/.claude.json

How do I get Sume into a cloud session?

Add it as a custom connector in your claude.ai organization with the URL https://mcp.sume.com/mcp, the production endpoint in the MCP overview. Sume's docs describe the OAuth flow the connector follows, with consent on the MCP host. A project .mcp.json you committed is a separate path, and the page does not say that a cloud session reads it, so do not depend on it without testing.

# Local machine only; a cloud session does not read this:
claude mcp add --transport http sume https://mcp.sume.com/mcp
claude mcp login sume

Who can block or limit it?

Your administrators can. The page says organizations can set per-tool controls on claude.ai connectors, which Claude Code reads at startup and enforces locally, and that a server provided through the managedMcpServers setting ranks above the other scopes. If Sume's tools are missing in a cloud session, compare the connector's per-tool settings and the allowlist before suspecting Sume.

On Sume's side the visible tools depend on the grant. A Read-only OAuth session sees read-only tools, and paid calls return insufficient_scope until the connector is authorized with Write.

What should I do for unattended cloud runs?

Decide the spend rules before the session starts. Paid calls need an idempotency_key, and max_spend_usd bounds a call only when passed, so put both in the task instructions. The changelog (read 2026-10-03) also records that 2.1.287 made MCP calls in a resumed session wait up to 10 seconds for a server that is still connecting, which is relevant after an idle wake.

How do I verify Sume inside a cloud session?

Ask the agent, as the first step of the task, to call mcp_health and tools_list and report what it sees. Both are read-only and free. If the tools are listed, continue. If the server is missing, the cause is on the connector side: it was not added to the organization, it was blocked by an allowlist or denylist, or it needs authorizing.

Keep the first paid call small. Pass dry_run=true and a max_spend_usd cap so the preview shows cost before a job exists, and give every create its own idempotency_key.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume