Crush MCP server: add Sume in crush.json with type http
Add Sume's hosted MCP to Crush in crush.json with type http, a header read from an environment variable, disabled_tools for paid tools, and a long timeout.

To connect Crush to Sume, add an entry under the mcp key of crush.json with "type": "http", "url": "https://mcp.sume.com/mcp" and a headers object that carries your Sume API key from an environment variable. Crush's README says values such as $GH_PAT expand when the config loads (read 2026-10-02), so the key itself does not need to sit in the file.
The Crush fields that matter
The Crush README documents HTTP servers with type, url and headers, plus the options below. Sume's side is from its MCP docs.
| Crush option | What the README says | For Sume |
|---|---|---|
mcp key in crush.json | Where MCP servers are configured | One entry named sume |
type, url, headers | HTTP transport, endpoint, custom headers | http, the hosted URL, x-api-key |
$VAR expansion | Expands at config load | $SUME_API_KEY |
disabled_tools | Hides specific tools from the agent | Paid tool names |
timeout | Request timeout; the example uses 10 | Above Sume's 55 s jobs_wait hold; check the unit |
oauth | true for servers that support OAuth | Not covered by Sume's docs for Crush |
{
"$schema": "https://charm.land/crush.json",
"mcp": {
"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp",
"headers": { "x-api-key": "$SUME_API_KEY" },
"timeout": 90
}
}
}Check the timeout unit before trusting it
The README example uses --timeout 10, which reads like seconds, but the page I read does not state the unit. Sume's jobs_wait can hold a call for up to 55 seconds, and when the slice ends it answers wait_slice_expired so the client retries with the same ids (Jobs and results). Pick a value that is above 55 in the unit Crush uses, then ask for a jobs_wait on a queued job to confirm the call is not cut off.
Hide the paid tools you do not want yet
An API-key session sees the full hosted tool set, including paid generation tools, and paid calls still need an idempotency_key (MCP tools and gates). Crush's disabled_tools option hides tools from the agent entirely, so listing generate_image, generate_video, music_create and tts_create there leaves the agent with discovery, job reads and asset reads.
Remove names from the list when you are ready to spend, and have the agent call dry_run first. Add max_spend_usd to the call if you want a cap, since Sume enforces it only when provided.
Limits of this setup
Start the conversation with mcp_health and tools_list; both are read-only (MCP quickstart).
- The README says known sessionless servers are detected and others need
"sessionless": true. Sume's docs do not say how its endpoint should be classified, so if Crush reports session errors, test that flag and confirm withmcp_health. - Sume's OAuth docs cover Cursor, Claude Code and Codex. They do not cover Crush, so use the header route.
- Keep
crush.jsonfree of literal keys if it lives in a repo.
Sources
Related posts
More in Integrations
- Cursor CLI --approve-mcps: what it skips for paid Sume tools
Cursor CLI's --approve-mcps flag skips MCP approval prompts. How that affects paid Sume tools, plus agent mcp list-tools and login to check the connection.
- Cursor MCP allowlist: approve Sume's URL and its read tools
Cursor enterprise admins approve remote MCP servers by URL entry and list tools per server. How to allow Sume's mcp.sume.com/mcp and which tools to list.
- Cursor supports MCP roots and elicitation; Sume uses tools only
Cursor lists tools, prompts, resources, roots, elicitation and Apps as supported. Sume's hosted MCP answers only tools, so here is what you will see.
- Deno.serve webhook receiver for Sume with a KV dedupe check
A short Deno.serve receiver for Sume webhooks: verify sume-v1 over the raw body, dedupe on job_id with an atomic KV write, and acknowledge with 204.
Written by Sume