Gemini CLI includeTools for Sume MCP: expose reads, keep trust false
Gemini CLI can allowlist MCP tools with includeTools, and trust defaults to false. Use both to give an agent Sume reads without paid generation.

Set includeTools to a short list of Sume read tools and leave trust at its default of false. Gemini CLI then offers only those tools and still asks before each call. excludeTools is the opposite filter and wins if a name appears in both lists.
| Key | Type | Behavior |
|---|---|---|
includeTools | string array | Allowlist; only these are available |
excludeTools | string array | Blocklist; takes precedence |
trust | boolean, default false | True skips confirmations for the server |
Entry
This keeps an agent on discovery and job reads. The names match what tools_list returns.
{
"mcpServers": {
"sume": {
"httpUrl": "https://mcp.sume.com/mcp",
"includeTools": [
"mcp_health", "tools_list", "tools_schema",
"jobs_list", "jobs_status", "jobs_wait", "jobs_result"
],
"trust": false
}
}
}Two layers of filtering
The client filter and the server scope stack. With OAuth mcp:read, Sume itself hides write and paid tools, and a call to one returns insufficient_scope. With an API key, the server shows everything, so the client list becomes the only filter.
| Layer | Control | Effect |
|---|---|---|
| Gemini CLI | includeTools / excludeTools | Hides names from the model |
| Gemini CLI | trust: false | Confirmation per call |
| Sume OAuth | No mcp:write grant | Write and paid tools hidden |
| Sume API key | None by scope | Full tool set visible |
Do not set trust to true here
With trust: true, every call from the server runs without approval. Combined with an API key that can create paid jobs, that removes the last human step. Keep it false for Sume unless the allowlist holds only reads.
A starting allowlist
For a reporting agent, the seven names in the example are enough: health, discovery, and the four job reads. For a creative agent, add generation_admission_preview and the create tools you need, and leave jobs_cancel out until someone asks for it. Review the list when Sume adds tools, because an allowlist hides new tools by default, which is the safe direction.
Using excludeTools
Use excludeTools when you want almost everything but a few dangerous names, for example jobs_cancel and assets_create. Since exclusion wins, a name in both lists stays hidden. An allowlist is easier to reason about than a blocklist, so prefer includeTools for any agent that runs without supervision.
It helps to test the allowlist from the model's point of view. Start a session and ask the agent which Sume tools it can see. If a name is missing, check for a typo, since underscore ids are the live names and dotted aliases are only accepted by the server. Then try one call on a tool outside the list; the client should refuse it before any request is sent. Doing this once saves a surprise later, when an agent tries to create something you never meant to allow.
Keep in mind that Sume's hosted endpoint is the same for every client in this series: https://mcp.sume.com/mcp, with OAuth consent on the MCP host or an API key in a header. What differs is each client's config keys, its timeout defaults and its approval prompts. When a connection misbehaves, first separate those two layers: test the endpoint with curl and your credential, and only then look at the client's settings.
Sources
Related posts
More in Integrations
- Gemini CLI MCP timeout is 600000 ms; Sume jobs_wait caps at 55 s
Gemini CLI waits up to 10 minutes per MCP request, but Sume cuts jobs_wait at 55 seconds. Set the client timeout low and loop on wait_slice_expired.
- Can GLM-5.3 call Sume's hosted MCP? Function calling, not MCP
Z.ai's GLM-5.3 page lists function calling and does not mention MCP. How a GLM agent reaches Sume through an MCP client or through plain HTTP.
- Kling lists MCP and CLI tools for batch video; Sume's hosted MCP
Kling's home page mentions MCP and CLI tools for batch generation. Sume's hosted MCP at mcp.sume.com has generate_video; its Kling row is kling-3 only.
- LinkedIn wants a text-only SRT; Sume burns captions, so build one
LinkedIn video ad captions must be a text-only SRT. Sume burns captions into pixels and has no SRT export. Build the file from video-inspect segments.
Written by Sume