gemini mcp add for Sume: transport, header, timeout, include-tools

One gemini mcp add command registers Sume's hosted MCP over HTTP with a key header, a timeout above 55 seconds, and an include-tools list for read-only use.

5 min readSume
All posts

Register Sume in Gemini CLI with one command: gemini mcp add --transport http sume https://mcp.sume.com/mcp. The --transport flag takes stdio, sse or http, and http is the right value for Sume's streamable HTTP endpoint. Add --header for an API key, --timeout in milliseconds, and --include-tools to limit what the model can call.

Which flags does gemini mcp add accept?

The Gemini CLI docs give the form gemini mcp add [options] <name> <commandOrUrl> [args...] and list the options below.

gemini mcp add options relevant to a remote server (Gemini CLI docs read 2026-10-11)
FlagWhat it doesUse with Sume
-t, --transportstdio, sse or httphttp
-H, --headerAdds an HTTP headerAuthorization for an API key session
--timeoutMillisecondsAbove 55000, see below
--trustBypasses confirmationsLeave off for paid tools
--include-tools / --exclude-toolsComma-separated tool listsRead-only subset, or hide paid tools

How do you add the server?

For an interactive session, skip the header and let the client do OAuth discovery; the Gemini docs name dynamic_discovery as the default auth provider type. Sume returns an OAuth challenge and protected-resource metadata, then sends you to the consent page on the MCP host, where Write is off unless you turn it on.

For a script or CI run, use a key instead:

gemini mcp add --transport http \
  --header "Authorization: Bearer $SUME_API_KEY" \
  --timeout 65000 \
  sume https://mcp.sume.com/mcp

Why a timeout above 55 seconds?

Sume's jobs_wait holds up to 55 seconds per call on remote MCP, with a default of 50. A client timeout shorter than that cuts a healthy wait. The Gemini docs show 30000 as an example timeout value, so set your own explicitly. Your shell expands $SUME_API_KEY when you run the command, so the key lands in the settings file; keep that file out of version control.

How do you keep paid tools out of reach?

Gemini documents that exclusions take precedence over inclusions. Run tools_list once to read the live names, then pass them to --include-tools for a discovery-only setup. Sume's own gate is separate: write and paid tools need an idempotency_key, and an OAuth session without mcp:write cannot call them at all.

How do you check the result?

After adding the server, start Gemini CLI and ask it to call mcp_health. The response reports the endpoint, the auth source and the safety posture, so you can see whether the session came from OAuth or from your key. Then call tools_list: with a read-only OAuth grant you see only read tools, and with a key you see the full hosted set, including generate_image and generate_video.

If you restrict the list with --include-tools, remember the filter is applied on the Gemini side. It narrows what the model can see, but it does not change what your credential is allowed to do. For a hard boundary, pair it with an OAuth session that has Write off, and keep --trust off so confirmations stay in place for anything that spends credits.

Finally, run a single dry_run call to a paid tool such as generate_image. A dry run previews admission and cost without submitting, which proves the header, the timeout and the tool filter all work together before real spend.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume