Gemini API managed agents now take remote MCP: what to give Sume

Google's managed agents in the Gemini API can connect to remote MCP servers. Here is the Sume URL, auth choice and first read-only calls to set up.

5 min readSume
All posts

Yes, a managed agent in the Gemini API can use a remote MCP server, and for Sume that server is Sume's hosted MCP server at https://mcp.sume.com/mcp. Google's post says developers can connect managed agents to remote MCP servers instead of writing custom proxy middleware, so they can mix remote tools with the built-in sandbox (read 2026-10-04). The post is dated July 7, 2026, and it does not describe how an agent authenticates to a server.

Because of that gap, this post covers only the Sume side: which credential to hand over, which tools to try first, and which gates stop a paid call from running by accident.

Which credential should a managed agent use?

Sume's hosted MCP server accepts two credentials. OAuth is the preferred path for interactive clients, and an API key is the path for automation that does not speak OAuth. A background managed agent has no person at a consent screen, so an API key sent as Authorization: Bearer or x-api-key is the fit if Google's runtime lets you attach a header.

Hosted MCP credentials from Sume's MCP OAuth and API keys docs, read 2026-10-04.
CredentialWhat the session can doSpend gate
OAuth, mcp:read onlyRead-only tools; mutating calls return insufficient_scopeNone needed; paid tools are hidden
OAuth, mcp:read and mcp:writeFull hosted tool setWallet and admission; idempotency_key required
API keyFull hosted tool setWallet and admission; idempotency_key required

What should the agent call first?

The MCP quickstart lists the read-only checks:

  • mcp_health confirms the endpoint, auth source and safety posture.
  • tools_list lists every tool the credential can see.
  • tools_schema returns one tool's contract by name.
  • account_me and balance_get confirm the workspace and its funds.

How do I stop a managed agent overspending?

Paid and write tools need an idempotency_key; an optional dry_run previews cost, and an optional max_spend_usd is enforced only when you pass it. Tell the agent in its instructions to call generation_admission_preview or use dry_run=true before any burst, and to pass max_spend_usd on every paid call. If you want a read-only agent, use an OAuth token without write: Sume's tools and gates page says paid tools are hidden from it.

What does Sume not do here?

Sume's docs do not describe a Google-specific integration, and they list Cursor, Claude Code and Codex by name as clients. A Gemini managed agent connects as any other remote client would, so verify with mcp_health before you trust it with a task.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume