Docker Agent YAML: add Sume as a remote MCP toolset

Docker Agent takes a remote MCP URL, headers and a tools allowlist. Here is the Sume entry with a Bearer key from the environment and a read-only tool list.

4 min readSume
All posts

To use Sume from a Docker Agent, add a type: mcp toolset with a remote block that points at https://mcp.sume.com/mcp, send your key in remote.headers, and list the tools you want in tools. Docker's Tool Configuration page (read 2026-10-10) documents exactly those keys, and Sume's hosted endpoint accepts the key as a Bearer header.

The part worth getting right is not the URL. It is the combination of an API key, which exposes the full hosted tool set, and the tools allowlist, which is the only thing that stops a first draft of an agent from seeing paid tools.

The toolset entry

Docker's page shows the remote shape as toolsets with type: mcp, then remote carrying url, transport_type (streamable or sse) and headers, and an optional tools list that it describes as exposing only the named tools. Header values support ${env.VAR} expansion, so the key never has to sit in the YAML file. Sume's hosted MCP is a streamable HTTP endpoint, so streamable is the transport to pick.

Sume documents two header spellings for API-key sessions: Authorization: Bearer <SUME_API_KEY> or x-api-key. The Bearer form fits the Docker headers map directly.

toolsets:
  - type: mcp
    remote:
      url: "https://mcp.sume.com/mcp"
      transport_type: "streamable"
      headers:
        Authorization: "Bearer ${env.SUME_API_KEY}"
    tools:
      - mcp_health
      - tools_list
      - tools_schema
      - catalog_list
      - account_me
      - balance_get
      - usage_get
      - jobs_status

Why the allowlist matters with an API key

Sume's OAuth and API keys page is explicit: an API-key session sees the full hosted tool set, including write and paid tools. Under OAuth, a session without mcp:write only sees read-only tools, but a Docker Agent YAML with a static header is an API-key setup, so the OAuth read-only default does not protect you.

That makes the tools list your guardrail for the first runs. The eight names above are read tools documented on Sume's MCP tools and gates page: health, discovery, catalog, account, balance, usage and a single job status read. An agent limited to them can explain what Sume offers and what a job is doing, and it cannot spend.

  • Start with the list above and confirm the session works with mcp_health, then tools_list.
  • Add generate_image or generate_video only when you want paid calls from that agent.
  • Keep jobs_wait out until you add a create tool; there is nothing to wait for before then.

What changes when you add paid tools

Write and paid tools require an idempotency_key on every call. dry_run previews cost without submitting, and max_spend_usd is enforced only when you pass it, so your agent instructions should say to pass both. Sume's docs state that the legacy allow_write and allow_paid flags are accepted but not required, and that they cannot bypass a missing scope.

Docker's tools filter is a client-side allowlist and Sume's gates are server-side. They do different jobs, so keep both.

Who enforces what for a Docker Agent calling Sume (Docker page read 2026-10-10; Sume docs MCP pages)
ControlWhere it livesWhat it stops
tools allowlistDocker Agent YAMLTools the model is never shown
Bearer API keyremote.headers via env varAnonymous calls to the endpoint
idempotency_keySume, required on write and paid toolsA retry creating a second job
dry_runSume, optional per callSurprise cost before a submit
max_spend_usdSume, enforced only if passedA single call above your ceiling

Checks before you trust it

Run the agent once with only mcp_health and tools_list and read what comes back: the tool names should match your allowlist and the auth source should be the API key. Sume's docs say tool ids use underscores, and the server folds a dot to an underscore, so write them with underscores in the YAML.

I read Docker's tool configuration page for the remote keys above. I did not run a Docker Agent against Sume for this post, so treat the YAML as the documented shape on both sides and confirm it with the mcp_health call before adding paid tools.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume