Gemini CLI excludeTools: hide paid Sume tools from the agent
Use includeTools and excludeTools in Gemini CLI settings.json to give an API-key Sume session only read tools, since excludeTools wins over includeTools.

In Gemini CLI, set includeTools on the Sume entry to a short list of read tools, such as mcp_health, tools_list, jobs_status and jobs_result, or set excludeTools to the paid names. Gemini's MCP docs say excludeTools takes precedence, so a name in both lists is blocked (read 2026-10-02). This matters most for an API-key session, which sees every Sume tool.
What Gemini CLI documents
Gemini CLI's settings reference lists the per-server keys below. The filtering keys take tool names as the server reports them.
| Key | What the Gemini docs say | For Sume |
|---|---|---|
httpUrl | HTTP streaming endpoint URL | https://mcp.sume.com/mcp |
headers | Custom HTTP headers | x-api-key for a key session |
includeTools | List of tool names to include | Read-only names |
excludeTools | List of names to exclude; takes precedence | Paid names |
trust | When true, bypasses all tool-call confirmations | Leave off |
timeout | Request timeout in milliseconds; default 600000 | Fine above 55 s |
{
"mcpServers": {
"sume": {
"httpUrl": "https://mcp.sume.com/mcp",
"headers": { "x-api-key": "<your key>" },
"includeTools": [
"mcp_health", "tools_list", "tools_schema",
"balance_get", "jobs_list", "jobs_status",
"jobs_result", "assets_list", "assets_get"
]
}
}
}When you need it, and when you do not
Sume's OAuth path already narrows the surface. A session with mcp:read only sees read-only tools, and a mutating or paid call returns insufficient_scope. An API-key session sees the full tool set (MCP OAuth and API keys). So a tool filter is the way to get read-only behavior when you connect with a key.
Do not mix the two ideas up. A filter hides tools from Gemini; it does not change what the credential can do, and the same key used from another client still sees every tool.
Keeping the list correct
The names above come from Sume's hosted tool list: discovery tools mcp_health, tools_list and tools_schema, account reads balance_get and usage_get, job reads jobs_list, jobs_get, jobs_status, jobs_result, jobs_events and jobs_wait, and asset reads assets_list, assets_get and assets_download_url (MCP tools and gates).
Sume says to call tools_list for the session-visible subset rather than assume a fixed set, and an allowlist will not pick up new tools by itself. Prefer includeTools for read-only use, since a new paid tool stays hidden until you add it, whereas an excludeTools list would let a new paid tool through.
Checking the result
After editing settings, restart Gemini CLI, run /mcp to see the server's discovered tools, and ask it to call tools_list. Sume's list will show more tools than Gemini does, which is the expected difference. If a paid tool such as generate_image still shows in /mcp, look for a second entry for the same server in another settings scope. Gemini's docs name trust as the key that skips confirmations, so confirm it is not set to true on that entry.
Sources
Related posts
More in Integrations
- Gemini CLI headless: ask_user acts as deny, so paid Sume calls skip
In Gemini CLI non-interactive mode a policy of ask_user is treated as deny. A paid Sume call then never runs, so allow it narrowly or use an API-key script.
- Gemini CLI 63-character MCP tool names: do Sume tool names fit?
Gemini CLI builds names as mcp_server_tool and truncates past 63 characters. Sume's longest documented tool names fit if the server name stays short.
- Gumloop custom MCP server: use a bearer token for Sume
Gumloop's Anthropic models do not forward custom headers, so connect Sume's hosted MCP with a bearer token. Or pick another model for x-api-key.
- Hookdeck Delivery Groups: per-tenant rates for Sume webhooks
Hookdeck Delivery Groups limit delivery rate per tenant. Use them to stop one account's burst of Sume completions starving others on a shared relay.
Written by Sume