Gemini CLI settings.json httpUrl, timeout and includeTools for Sume

Gemini CLI's MCP entry takes httpUrl, headers, a 600000 ms timeout and includeTools. Set up Sume's hosted server with a read-only tool list and one credential.

5 min readSume
All posts

Gemini CLI configures MCP servers in its settings file, and the Gemini CLI MCP page lists httpUrl for Streamable HTTP servers, headers, a timeout that defaults to 600000 ms, and includeTools and excludeTools filters, read 2026-10-03. Sume's hosted MCP server is Streamable HTTP at https://mcp.sume.com/mcp, per the Sume MCP overview, so httpUrl is the matching field.

{
  "mcpServers": {
    "sume": {
      "httpUrl": "https://mcp.sume.com/mcp",
      "headers": { "Authorization": "Bearer YOUR_SUME_API_KEY" },
      "timeout": 90000,
      "includeTools": ["jobs_wait", "jobs_result", "balance_get"]
    }
  }
}

The timeout is generous already

The default of 600000 ms is ten minutes, far above Sume's jobs_wait cap of 55 seconds, per the tools and gates page. You do not need to raise it for waits. A shorter value, such as the 90 seconds above, is a deliberate choice: it stops a hung call sooner, but it must stay above 55 seconds or default waits will fail on the client side.

Gemini CLI settings for Sume, read 2026-10-03.
KeyDefaultChoice
httpUrlNonehttps://mcp.sume.com/mcp
timeout600000 msKeep above 55 seconds
includeToolsAll toolsRead and wait tools only
excludeToolsNoneAlternative: exclude create tools
headersNoneOne credential header

Allowlist beats blocklist

includeTools names exactly what the model may see, so a new Sume tool added later does not appear by surprise. excludeTools hides named tools but exposes everything else. For an agent that should only monitor jobs, use the allowlist. Sume still guards the server side: idempotency_key is required on paid and write tools, and a write tool under an mcp:read OAuth credential returns insufficient_scope.

Keep the key out of the file

The example shows a placeholder. The Gemini CLI page excerpt this post relies on does not describe environment-variable expansion in headers, so check the current docs before putting a variable reference there, and never commit a literal key. Send one credential: the Sume REST API rejects Authorization and x-api-key together with a 401.

  • Use httpUrl for Sume's Streamable HTTP endpoint.
  • Allowlist with includeTools.
  • Keep timeout above 55 seconds.
  • A client timeout does not cancel a Sume job; resume with jobs_wait and the same ids, never a new create.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume