Docker Agent YAML: add Sume as a remote MCP toolset
Docker Agent takes a remote MCP URL, headers and a tools allowlist. Here is the Sume entry with a Bearer key from the environment and a read-only tool list.

To use Sume from a Docker Agent, add a type: mcp toolset with a remote block that points at https://mcp.sume.com/mcp, send your key in remote.headers, and list the tools you want in tools. Docker's Tool Configuration page (read 2026-10-10) documents exactly those keys, and Sume's hosted endpoint accepts the key as a Bearer header.
The part worth getting right is not the URL. It is the combination of an API key, which exposes the full hosted tool set, and the tools allowlist, which is the only thing that stops a first draft of an agent from seeing paid tools.
The toolset entry
Docker's page shows the remote shape as toolsets with type: mcp, then remote carrying url, transport_type (streamable or sse) and headers, and an optional tools list that it describes as exposing only the named tools. Header values support ${env.VAR} expansion, so the key never has to sit in the YAML file. Sume's hosted MCP is a streamable HTTP endpoint, so streamable is the transport to pick.
Sume documents two header spellings for API-key sessions: Authorization: Bearer <SUME_API_KEY> or x-api-key. The Bearer form fits the Docker headers map directly.
toolsets:
- type: mcp
remote:
url: "https://mcp.sume.com/mcp"
transport_type: "streamable"
headers:
Authorization: "Bearer ${env.SUME_API_KEY}"
tools:
- mcp_health
- tools_list
- tools_schema
- catalog_list
- account_me
- balance_get
- usage_get
- jobs_statusWhy the allowlist matters with an API key
Sume's OAuth and API keys page is explicit: an API-key session sees the full hosted tool set, including write and paid tools. Under OAuth, a session without mcp:write only sees read-only tools, but a Docker Agent YAML with a static header is an API-key setup, so the OAuth read-only default does not protect you.
That makes the tools list your guardrail for the first runs. The eight names above are read tools documented on Sume's MCP tools and gates page: health, discovery, catalog, account, balance, usage and a single job status read. An agent limited to them can explain what Sume offers and what a job is doing, and it cannot spend.
- Start with the list above and confirm the session works with
mcp_health, thentools_list. - Add
generate_imageorgenerate_videoonly when you want paid calls from that agent. - Keep
jobs_waitout until you add a create tool; there is nothing to wait for before then.
What changes when you add paid tools
Write and paid tools require an idempotency_key on every call. dry_run previews cost without submitting, and max_spend_usd is enforced only when you pass it, so your agent instructions should say to pass both. Sume's docs state that the legacy allow_write and allow_paid flags are accepted but not required, and that they cannot bypass a missing scope.
Docker's tools filter is a client-side allowlist and Sume's gates are server-side. They do different jobs, so keep both.
| Control | Where it lives | What it stops |
|---|---|---|
| tools allowlist | Docker Agent YAML | Tools the model is never shown |
| Bearer API key | remote.headers via env var | Anonymous calls to the endpoint |
| idempotency_key | Sume, required on write and paid tools | A retry creating a second job |
| dry_run | Sume, optional per call | Surprise cost before a submit |
| max_spend_usd | Sume, enforced only if passed | A single call above your ceiling |
Checks before you trust it
Run the agent once with only mcp_health and tools_list and read what comes back: the tool names should match your allowlist and the auth source should be the API key. Sume's docs say tool ids use underscores, and the server folds a dot to an underscore, so write them with underscores in the YAML.
I read Docker's tool configuration page for the remote keys above. I did not run a Docker Agent against Sume for this post, so treat the YAML as the documented shape on both sides and confirm it with the mcp_health call before adding paid tools.
Sources
Related posts
More in Integrations
- Freshdesk Trigger Webhook: 1000 calls an hour and Sume bulk runs
Freshdesk automations cap webhook calls at 1000 an hour and retry failures every 30 minutes. Here is how a relay maps ticket bursts onto Sume bulk runs.
- Grafana alert webhook with HMAC to a Sume run: incident explainer
Grafana's webhook contact point can sign alerts with HMAC over timestamp:body. Verify it, then start a Sume Format run per firing alert with a stable key.
- Jotform webhook rawRequest and a 30 s timeout: start a Sume run
Jotform posts submissions as form data with a rawRequest field and a 30 s timeout. Answer fast, start a Sume Format run, and let a webhook return the result.
- Render deploy hook returns 202: start a Sume run after a deploy
Render deploy hooks return 200 when a deploy starts and 202 when queued. Call one, then start a Sume Format run for the release only once it ships.
Written by Sume