claude --strict-mcp-config: run CI with only the Sume server
--strict-mcp-config makes Claude Code use only servers from --mcp-config. A CI recipe for loading just Sume's hosted MCP, with a key, a wait limit and a cap.

--strict-mcp-config tells Claude Code to use only the MCP servers named in --mcp-config. For a CI job that renders with Sume, that means the run sees https://mcp.sume.com/mcp and nothing from a developer's user or project config, so the tool list and the bill are the same on every run.
What do the flags do?
From the CLI reference: --strict-mcp-config uses only MCP servers from --mcp-config, and with -p, --mcp-config waits for pending servers up to MCP_TIMEOUT, 30 seconds by default.
| Flag | Effect |
|---|---|
| --mcp-config | With -p, waits for pending servers up to MCP_TIMEOUT (30 s default) |
| --strict-mcp-config | Only use MCP servers from --mcp-config |
What goes in the config?
A remote server entry with the URL and a key header. Sume accepts the key as Authorization: Bearer or as x-api-key. Keep the key in a CI secret and write the file at job start so it never lands in the repository. The quickstart has the exact shape for each client: MCP quickstart.
Why strict mode helps a paid pipeline
Three reasons:
- A stray server cannot add tools that spend money or shadow a Sume tool name.
- A key means the full hosted tool set, so add
max_spend_usdandidempotency_keyto the prompt rules. - For a read-only report, use OAuth
mcp:readinstead; write and paid tools then returninsufficient_scope.
What if the first turn lacks Sume tools?
Then the server was not ready inside the wait. Call mcp_health first in the prompt and fail the job when it errors, rather than letting the agent improvise without tools.
Sources
Related posts
More in Integrations
- Cursor mcp.json for Sume: a URL and nothing else
The Cursor entry for hosted Sume MCP is one url field with no key in the file; OAuth sign-in happens in the client and the consent page lives on the MCP host.
- Devin Desktop ${file:} interpolation for the Sume API key
Devin Desktop expands ${file:/path} and ${env:NAME} in mcp_config.json. Put the Sume API key in a file outside the config; the 100-tool cap still applies.
- Gemini CLI authProviderType: connect Sume with dynamic_discovery
Gemini CLI defaults authProviderType to dynamic_discovery. For Sume that means OAuth discovery, not Google credentials. What each of the three values does.
- Does Copilot's MCP policy apply to Pro+ or Max? Sume hosted MCP
GitHub's MCP servers in Copilot policy covers Business and Enterprise, off by default. Free, Pro, Pro+ and Max users can add Sume's hosted MCP server directly.
Written by Sume