Gemini API managed agents now take remote MCP: what to give Sume
Google's managed agents in the Gemini API can connect to remote MCP servers. Here is the Sume URL, auth choice and first read-only calls to set up.

Yes, a managed agent in the Gemini API can use a remote MCP server, and for Sume that server is Sume's hosted MCP server at https://mcp.sume.com/mcp. Google's post says developers can connect managed agents to remote MCP servers instead of writing custom proxy middleware, so they can mix remote tools with the built-in sandbox (read 2026-10-04). The post is dated July 7, 2026, and it does not describe how an agent authenticates to a server.
Because of that gap, this post covers only the Sume side: which credential to hand over, which tools to try first, and which gates stop a paid call from running by accident.
Which credential should a managed agent use?
Sume's hosted MCP server accepts two credentials. OAuth is the preferred path for interactive clients, and an API key is the path for automation that does not speak OAuth. A background managed agent has no person at a consent screen, so an API key sent as Authorization: Bearer or x-api-key is the fit if Google's runtime lets you attach a header.
| Credential | What the session can do | Spend gate |
|---|---|---|
OAuth, mcp:read only | Read-only tools; mutating calls return insufficient_scope | None needed; paid tools are hidden |
OAuth, mcp:read and mcp:write | Full hosted tool set | Wallet and admission; idempotency_key required |
| API key | Full hosted tool set | Wallet and admission; idempotency_key required |
What should the agent call first?
The MCP quickstart lists the read-only checks:
mcp_healthconfirms the endpoint, auth source and safety posture.tools_listlists every tool the credential can see.tools_schemareturns one tool's contract by name.account_meandbalance_getconfirm the workspace and its funds.
How do I stop a managed agent overspending?
Paid and write tools need an idempotency_key; an optional dry_run previews cost, and an optional max_spend_usd is enforced only when you pass it. Tell the agent in its instructions to call generation_admission_preview or use dry_run=true before any burst, and to pass max_spend_usd on every paid call. If you want a read-only agent, use an OAuth token without write: Sume's tools and gates page says paid tools are hidden from it.
What does Sume not do here?
Sume's docs do not describe a Google-specific integration, and they list Cursor, Claude Code and Codex by name as clients. A Gemini managed agent connects as any other remote client would, so verify with mcp_health before you trust it with a task.
Sources
Related posts
More in Integrations
- GitHub Actions: generate a release-note image with the Sume Images API
A workflow that fires when a release is published, calls Sume's image endpoint with curl and jq, downloads the result and uploads it as a build artifact.
- Sheets 20 million cells: how many Sume jobs can a ledger hold?
Google Sheets doubled its cell limit to 20 million. Work out how many Sume job rows fit by column count, and why GET /v1/jobs stays the system of record.
- Sheets manual calculation: keep paid Sume calls out of formulas
Google Sheets can now pause automatic recalculation. Keep Sume job submits in a menu-driven Apps Script, not formulas, so a recalc never buys a render.
- GPT-6.1 Sol is in ChatGPT Work and Codex, not chat: attach Sume's MCP
OpenAI put GPT-6.1 Sol in ChatGPT Work and Codex rather than regular chat. Which of those surfaces can take Sume's hosted MCP server.
Written by Sume