claude -p loads project .mcp.json with no approval: Sume paid tools
In claude -p, Agent SDK and cloud sessions, Claude Code loads .mcp.json servers without asking. What that means for a committed Sume entry, and how to block it.

A Sume server committed in .mcp.json loads without any approval prompt when someone runs claude -p, uses the Agent SDK, or starts a cloud session in that repository. Claude Code's MCP page says it cannot show the approval prompt in those modes, so it loads project-scoped servers without asking. If the environment also has a Sume API key, the paid tools are then reachable, so decide on purpose whether that is what you want.
Claude Code facts are from Connect Claude Code to tools via MCP; Sume facts from MCP tools and gates and OAuth and API keys, read 2026-10-02.
When does Claude Code skip the approval prompt?
In interactive sessions Claude Code asks before using project-scoped servers from .mcp.json, and claude mcp reset-project-choices clears those answers. The page lists the cases with no prompt: claude -p runs, Agent SDK sessions and cloud sessions, plus a session started in bypassPermissions mode with skipDangerousModePermissionPrompt set in user or managed settings.
| Control | What the page says | Effect on a Sume entry |
|---|---|---|
disabledMcpjsonServers | Blocks the server in every permission mode | Sume never loads from that file |
--setting-sources / settingSources | Excludes project settings entirely | Project-level settings are ignored |
--strict-mcp-config | Uses only servers passed with --mcp-config | You name Sume yourself, or not at all |
| Interactive prompt | Asks before using .mcp.json servers | Only in interactive sessions |
What does a loaded Sume entry give a headless run?
That depends on the credential. A key in the header gives a session the full hosted tool set, including generate_image, generate_video and tts_create, each needing an idempotency_key. A project entry without a key and no way to complete OAuth gives you a server that needs authentication. Sume's max_spend_usd caps a call only when the model sends it, so it is not a policy.
How do I keep paid Sume tools out of a CI run?
Pick the narrowest control that fits. For a pipeline that must never generate, add the server to disabledMcpjsonServers. For a pipeline that should use only servers you name, use --strict-mcp-config with an explicit --mcp-config. The page says skipping the approval prompt for project servers a strict session is not loading needs Claude Code v2.1.246 or later.
Keep the key out of the committed file by referencing an environment variable in headers, and set that variable only in jobs that should have Sume. Claude Code --bare and MCP shows a related setup.
claude -p "summarize last week's jobs" \
--strict-mcp-config \
--mcp-config ./sume-readonly.jsonWhat should I check before merging the entry?
Confirm the behavior in a clean checkout rather than assuming it.
- Run
claude mcp get sume; aPending approvalstatus means the interactive prompt applies, andclaude -pwill not wait for it. - Confirm what the credential can do with
mcp_healthandtools_listin a throwaway session. - Add a permission ask rule for paid tool names if people run interactive sessions in the repo.
Sources
Related posts
More in Integrations
- Claude connector sign-in now, when needed or none: pick for Sume
For Sume's hosted MCP, pick Sign in now with OAuth, or add one auth header for an API key. No sign in fails, because the server needs a credential.
- Claude Desktop: add Sume's hosted MCP as a custom connector
Claude Desktop adds a remote MCP server through Customize > Connectors, not claude_desktop_config.json. Paste Sume's URL, sign in, and call tools_list.
- Claude Team or Enterprise: owner adds the Sume connector first
On Claude Team and Enterprise an owner adds the custom connector in Organization settings first, then members connect. Free plans get one custom connector.
- Cloudflare Cron Triggers: 5 free, 250 paid, one Sume bulk run
Free Workers accounts get 5 Cron Triggers, Paid get 250. Use one trigger to fan out many Sume Format runs through a bulk queue instead of one cron each.
Written by Sume