Claude Code managed-mcp.json exclusive: allow the Sume server
An exclusive managed-mcp.json fixes the MCP servers Claude Code may use. What to put in it for Sume's hosted server, and what Claude Code 2.1.282 added.

To let Claude Code use Sume when an administrator has made managed-mcp.json exclusive, the managed file needs an entry for Sume's hosted endpoint, https://mcp.sume.com/mcp; check Anthropic's Claude Code documentation for how an exclusive file treats other servers. Claude Code 2.1.282 also added one managed setting, allowClaudeInChromeWithManagedMcp, for a different case: running claude --chrome next to an exclusive file.
What did Claude Code 2.1.282 add?
The changelog says it added the allowClaudeInChromeWithManagedMcp managed setting to let claude --chrome run alongside an exclusive managed-mcp.json, and that the error shown when Chrome is blocked now names it. That is the only exclusive-file change in the entry; it concerns Chrome, not other servers.
What does the Sume entry need?
One URL. The Sume MCP overview gives https://mcp.sume.com/mcp as the production endpoint for Cursor, Claude Code, Codex and other remote MCP clients, and the quickstart connects Claude Code with claude mcp add --transport http sume https://mcp.sume.com/mcp. I did not find the managed file's exact schema in Sume's docs, so take the entry shape from Anthropic's Claude Code documentation and paste the Sume URL into it verbatim.
| Decision | Sume docs say |
|---|---|
| Endpoint to list | https://mcp.sume.com/mcp (dev hosts are for Sume development) |
| Interactive sign-in | OAuth connector flow, read-only by default |
| Automation | API key sent as Bearer or x-api-key, full hosted tool set |
OAuth or an API key for a managed fleet?
The quickstart says not to paste API keys into chat and to prefer the OAuth connector flow for interactive clients. OAuth grants mcp:read by default, and each person turns Write on at consent if they need it. An API key session sees write and paid tools. The OAuth and API keys page says the two credentials are not interchangeable and that you should not mint API keys for OAuth clients as a workaround.
How do I check it worked?
Run the login, then ask Claude to call tools_list or mcp_health. If the server is missing from Claude Code's MCP status UI, the managed file is the first place to look.
What breaks if Sume is left out?
The likely symptom is a Sume server that never shows up after the quickstart commands succeed. If that happens under an exclusive managed file, the entry is missing, and the fix is on the administrator's side, not in the user's own config.
Give the administrator three facts: the endpoint URL, that interactive sign-in is OAuth with read-only default, and that Write is opt-in at consent. The docs also say there is no mcp:paid scope, so the file does not need a separate entry for paid tools; spend is governed by wallet and admission.
Sources
Related posts
More in Developers
- Claude Code MCP progress notifications on a background call: Sume
Claude Code 2.1.283 fixed MCP progress notifications dropped on background calls. Sume's docs describe bounded jobs_wait slices instead of a progress stream.
- Claude Code mcp_tool hook on PreToolUse for a spend check
Claude Code 2.1.282 makes mcp_tool hooks on blocking events wait for their MCP server. With Sume, the check to run there is a dry_run cost preview.
- Claude Code "No such tool available" on a resumed MCP session
After resuming a Claude Code session, a first MCP call could fail with No such tool available. Claude Code 2.1.284 waits up to 10 seconds. The Sume side.
- OTEL_LOG_TOOL_CONTENT with MCP tool output: what Sume logs could leak
Claude Code 2.1.283 can put MCP tool output on an OTEL span when OTEL_LOG_TOOL_CONTENT=1. With Sume, check that output for signed URLs and keys first.
Written by Sume