claude --strict-mcp-config: run CI with only the Sume server

--strict-mcp-config makes Claude Code use only servers from --mcp-config. A CI recipe for loading just Sume's hosted MCP, with a key, a wait limit and a cap.

4 min readSume
All posts

--strict-mcp-config tells Claude Code to use only the MCP servers named in --mcp-config. For a CI job that renders with Sume, that means the run sees https://mcp.sume.com/mcp and nothing from a developer's user or project config, so the tool list and the bill are the same on every run.

What do the flags do?

From the CLI reference: --strict-mcp-config uses only MCP servers from --mcp-config, and with -p, --mcp-config waits for pending servers up to MCP_TIMEOUT, 30 seconds by default.

Claude Code CLI reference (read 2026-10-09)
FlagEffect
--mcp-configWith -p, waits for pending servers up to MCP_TIMEOUT (30 s default)
--strict-mcp-configOnly use MCP servers from --mcp-config

What goes in the config?

A remote server entry with the URL and a key header. Sume accepts the key as Authorization: Bearer or as x-api-key. Keep the key in a CI secret and write the file at job start so it never lands in the repository. The quickstart has the exact shape for each client: MCP quickstart.

Why strict mode helps a paid pipeline

Three reasons:

  • A stray server cannot add tools that spend money or shadow a Sume tool name.
  • A key means the full hosted tool set, so add max_spend_usd and idempotency_key to the prompt rules.
  • For a read-only report, use OAuth mcp:read instead; write and paid tools then return insufficient_scope.

What if the first turn lacks Sume tools?

Then the server was not ready inside the wait. Call mcp_health first in the prompt and fail the job when it errors, rather than letting the agent improvise without tools.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume