claude -p loads project .mcp.json with no approval: Sume paid tools

In claude -p, Agent SDK and cloud sessions, Claude Code loads .mcp.json servers without asking. What that means for a committed Sume entry, and how to block it.

5 min readSume
All posts

A Sume server committed in .mcp.json loads without any approval prompt when someone runs claude -p, uses the Agent SDK, or starts a cloud session in that repository. Claude Code's MCP page says it cannot show the approval prompt in those modes, so it loads project-scoped servers without asking. If the environment also has a Sume API key, the paid tools are then reachable, so decide on purpose whether that is what you want.

Claude Code facts are from Connect Claude Code to tools via MCP; Sume facts from MCP tools and gates and OAuth and API keys, read 2026-10-02.

When does Claude Code skip the approval prompt?

In interactive sessions Claude Code asks before using project-scoped servers from .mcp.json, and claude mcp reset-project-choices clears those answers. The page lists the cases with no prompt: claude -p runs, Agent SDK sessions and cloud sessions, plus a session started in bypassPermissions mode with skipDangerousModePermissionPrompt set in user or managed settings.

Controls from Claude Code's MCP page for a project-scoped server, read 2026-10-02.
ControlWhat the page saysEffect on a Sume entry
disabledMcpjsonServersBlocks the server in every permission modeSume never loads from that file
--setting-sources / settingSourcesExcludes project settings entirelyProject-level settings are ignored
--strict-mcp-configUses only servers passed with --mcp-configYou name Sume yourself, or not at all
Interactive promptAsks before using .mcp.json serversOnly in interactive sessions

What does a loaded Sume entry give a headless run?

That depends on the credential. A key in the header gives a session the full hosted tool set, including generate_image, generate_video and tts_create, each needing an idempotency_key. A project entry without a key and no way to complete OAuth gives you a server that needs authentication. Sume's max_spend_usd caps a call only when the model sends it, so it is not a policy.

How do I keep paid Sume tools out of a CI run?

Pick the narrowest control that fits. For a pipeline that must never generate, add the server to disabledMcpjsonServers. For a pipeline that should use only servers you name, use --strict-mcp-config with an explicit --mcp-config. The page says skipping the approval prompt for project servers a strict session is not loading needs Claude Code v2.1.246 or later.

Keep the key out of the committed file by referencing an environment variable in headers, and set that variable only in jobs that should have Sume. Claude Code --bare and MCP shows a related setup.

claude -p "summarize last week's jobs" \
  --strict-mcp-config \
  --mcp-config ./sume-readonly.json

What should I check before merging the entry?

Confirm the behavior in a clean checkout rather than assuming it.

  • Run claude mcp get sume; a Pending approval status means the interactive prompt applies, and claude -p will not wait for it.
  • Confirm what the credential can do with mcp_health and tools_list in a throwaway session.
  • Add a permission ask rule for paid tool names if people run interactive sessions in the repo.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume