Cloudflare Agents SDK with Pi: connect Sume's MCP tools
Cloudflare's Agents SDK now supports the Pi harness. Point the agent at https://mcp.sume.com/mcp and send an idempotency_key on every paid tool call.

To use Sume from a Cloudflare agent, give the agent the hosted MCP endpoint https://mcp.sume.com/mcp and authenticate with either an OAuth token or a Sume API key. Every paid or write tool then needs an idempotency_key.
What Cloudflare announced
The Cloudflare changelog entry dated October 2, 2026 says the Agents SDK now provides first-class support for building agents using the Pi harness, with the agent's work durably persisted even if interrupted mid-turn. Persistence matters for media work, because a generation job outlives a single model turn.
Connect to Sume
Sume's hosted MCP server lives at one URL. The client either follows MCP OAuth discovery or sends Authorization: Bearer <SUME_API_KEY> (or x-api-key).
| Mode | How it connects | What the agent sees |
|---|---|---|
| OAuth | Client follows MCP discovery and consent | mcp:read is read-only; mcp:write adds mutating and paid tools |
| API key | Bearer or x-api-key header | Full hosted tool set |
Gates the agent must respect
Paid and write tools are hidden until the session has mcp:write or an API key. There is no mcp:paid scope; spend is governed by the wallet and admission checks.
idempotency_keyis required on every write and paid tool. Store it with the agent's persisted state so a resumed turn reuses the same key.dry_run=truepreviews admission and cost without submitting.max_spend_usdis enforced only when you pass it.- Call
tools_listandtools_schemato read the live contract instead of assuming HTTP parity.
A sensible first run
Have the agent call tools_list, then tools_schema for generate_video, then a dry_run before any real submit. Follow a submit with jobs_wait and jobs_result. Because the Pi harness persists agent state, record the job id and the idempotency key together; on resume, poll the job rather than submitting again.
Sources
Related posts
More in Integrations
- Cloudflare Web Search API beta and Sume crawl tools for research
Cloudflare's Web Search API beta targets agents. Sume's hosted MCP has its own read-only crawl tools. How to research references first, then generate.
- Cloudflare Workers OAuth Provider 1.0: do you need it for Sume MCP?
Cloudflare shipped Workers OAuth Provider 1.0. You do not need it to use Sume's hosted MCP, which runs its own OAuth. When you would, and what Sume handles.
- Cursor Auto-review mode and paid Sume tool calls: keep dry_run on
Cursor's Auto-review classifier can allow a call you would block. For paid Sume tools, rely on server-side dry_run, max_spend_usd and OAuth scope.
- Cursor Run Everything mode: a read-only Sume token is the guardrail
In Run Everything, Cursor runs every tool call without review. Connect Sume with mcp:read so paid and write tools are not even visible.
Written by Sume