Crush MCP server: add Sume in crush.json with type http

Add Sume's hosted MCP to Crush in crush.json with type http, a header read from an environment variable, disabled_tools for paid tools, and a long timeout.

5 min readSume
All posts

To connect Crush to Sume, add an entry under the mcp key of crush.json with "type": "http", "url": "https://mcp.sume.com/mcp" and a headers object that carries your Sume API key from an environment variable. Crush's README says values such as $GH_PAT expand when the config loads (read 2026-10-02), so the key itself does not need to sit in the file.

The Crush fields that matter

The Crush README documents HTTP servers with type, url and headers, plus the options below. Sume's side is from its MCP docs.

Crush MCP options, read 2026-10-02 from the Crush README; Sume values from the Sume MCP docs.
Crush optionWhat the README saysFor Sume
mcp key in crush.jsonWhere MCP servers are configuredOne entry named sume
type, url, headersHTTP transport, endpoint, custom headershttp, the hosted URL, x-api-key
$VAR expansionExpands at config load$SUME_API_KEY
disabled_toolsHides specific tools from the agentPaid tool names
timeoutRequest timeout; the example uses 10Above Sume's 55 s jobs_wait hold; check the unit
oauthtrue for servers that support OAuthNot covered by Sume's docs for Crush
{
  "$schema": "https://charm.land/crush.json",
  "mcp": {
    "sume": {
      "type": "http",
      "url": "https://mcp.sume.com/mcp",
      "headers": { "x-api-key": "$SUME_API_KEY" },
      "timeout": 90
    }
  }
}

Check the timeout unit before trusting it

The README example uses --timeout 10, which reads like seconds, but the page I read does not state the unit. Sume's jobs_wait can hold a call for up to 55 seconds, and when the slice ends it answers wait_slice_expired so the client retries with the same ids (Jobs and results). Pick a value that is above 55 in the unit Crush uses, then ask for a jobs_wait on a queued job to confirm the call is not cut off.

Hide the paid tools you do not want yet

An API-key session sees the full hosted tool set, including paid generation tools, and paid calls still need an idempotency_key (MCP tools and gates). Crush's disabled_tools option hides tools from the agent entirely, so listing generate_image, generate_video, music_create and tts_create there leaves the agent with discovery, job reads and asset reads.

Remove names from the list when you are ready to spend, and have the agent call dry_run first. Add max_spend_usd to the call if you want a cap, since Sume enforces it only when provided.

Limits of this setup

Start the conversation with mcp_health and tools_list; both are read-only (MCP quickstart).

  • The README says known sessionless servers are detected and others need "sessionless": true. Sume's docs do not say how its endpoint should be classified, so if Crush reports session errors, test that flag and confirm with mcp_health.
  • Sume's OAuth docs cover Cursor, Claude Code and Codex. They do not cover Crush, so use the header route.
  • Keep crush.json free of literal keys if it lives in a repo.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume