Gemini CLI includeTools for Sume MCP: expose reads, keep trust false

Gemini CLI can allowlist MCP tools with includeTools, and trust defaults to false. Use both to give an agent Sume reads without paid generation.

5 min readSume
All posts

Set includeTools to a short list of Sume read tools and leave trust at its default of false. Gemini CLI then offers only those tools and still asks before each call. excludeTools is the opposite filter and wins if a name appears in both lists.

Gemini CLI tool controls, read 2026-10-08
KeyTypeBehavior
includeToolsstring arrayAllowlist; only these are available
excludeToolsstring arrayBlocklist; takes precedence
trustboolean, default falseTrue skips confirmations for the server

Entry

This keeps an agent on discovery and job reads. The names match what tools_list returns.

{
  "mcpServers": {
    "sume": {
      "httpUrl": "https://mcp.sume.com/mcp",
      "includeTools": [
        "mcp_health", "tools_list", "tools_schema",
        "jobs_list", "jobs_status", "jobs_wait", "jobs_result"
      ],
      "trust": false
    }
  }
}

Two layers of filtering

The client filter and the server scope stack. With OAuth mcp:read, Sume itself hides write and paid tools, and a call to one returns insufficient_scope. With an API key, the server shows everything, so the client list becomes the only filter.

Where each limit is enforced, read 2026-10-08
LayerControlEffect
Gemini CLIincludeTools / excludeToolsHides names from the model
Gemini CLItrust: falseConfirmation per call
Sume OAuthNo mcp:write grantWrite and paid tools hidden
Sume API keyNone by scopeFull tool set visible

Do not set trust to true here

With trust: true, every call from the server runs without approval. Combined with an API key that can create paid jobs, that removes the last human step. Keep it false for Sume unless the allowlist holds only reads.

A starting allowlist

For a reporting agent, the seven names in the example are enough: health, discovery, and the four job reads. For a creative agent, add generation_admission_preview and the create tools you need, and leave jobs_cancel out until someone asks for it. Review the list when Sume adds tools, because an allowlist hides new tools by default, which is the safe direction.

Using excludeTools

Use excludeTools when you want almost everything but a few dangerous names, for example jobs_cancel and assets_create. Since exclusion wins, a name in both lists stays hidden. An allowlist is easier to reason about than a blocklist, so prefer includeTools for any agent that runs without supervision.

It helps to test the allowlist from the model's point of view. Start a session and ask the agent which Sume tools it can see. If a name is missing, check for a typo, since underscore ids are the live names and dotted aliases are only accepted by the server. Then try one call on a tool outside the list; the client should refuse it before any request is sent. Doing this once saves a surprise later, when an agent tries to create something you never meant to allow.

Keep in mind that Sume's hosted endpoint is the same for every client in this series: https://mcp.sume.com/mcp, with OAuth consent on the MCP host or an API key in a header. What differs is each client's config keys, its timeout defaults and its approval prompts. When a connection misbehaves, first separate those two layers: test the endpoint with curl and your credential, and only then look at the client's settings.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume