Genkit createMcpHost: connect the hosted Sume MCP server
Genkit's createMcpHost takes a url and requestInit headers for remote servers. Wire https://mcp.sume.com/mcp into ai.generate and close the host after.

Short answer
In @genkit-ai/mcp, declare the server under mcpServers with a url and a requestInit.headers object, pass await mcpHost.getActiveTools(ai) to ai.generate, and call await mcpHost.close() at the end. The Genkit MCP docs show url and requestInit for remote servers and name authProvider for OAuth flows.
Sume's endpoint is https://mcp.sume.com/mcp. The OAuth and API keys page says it accepts either OAuth or an API key sent as Authorization: Bearer or x-api-key. The sample below uses the key header so it needs no browser consent step.
What the Genkit docs document
The install is npm i genkit @genkit-ai/mcp; the sample below also uses the Google plugin, @genkit-ai/google-genai. The same page's complete example uses stdio servers and a Gemini model; the remote form swaps the command and args for a url.
| Option | Purpose |
|---|---|
| url | endpoint of a remote HTTP MCP server |
| requestInit | customize the HTTP requests, such as headers |
| authProvider | OAuth-based authentication flows |
| getActiveTools(ai) / close() | pass tools to ai.generate; disconnect when done |
The script
Save as sume.mjs, set SUME_API_KEY and the model credentials Genkit's Google plugin expects, and run it with Node. The prompt asks only for read tools, but the key itself can reach paid tools, so keep the instructions narrow.
import { googleAI } from '@genkit-ai/google-genai';
import { createMcpHost } from '@genkit-ai/mcp';
import { genkit } from 'genkit';
const mcpHost = createMcpHost({
name: 'sumeMcp',
mcpServers: {
sume: {
url: 'https://mcp.sume.com/mcp',
requestInit: {
headers: { Authorization: `Bearer ${process.env.SUME_API_KEY}` },
},
},
},
});
const ai = genkit({ plugins: [googleAI()] });
const { text } = await ai.generate({
model: googleAI.model('gemini-flash-latest'),
prompt: 'Call mcp_health, then tools_list, and summarize what this session can do.',
tools: await mcpHost.getActiveTools(ai),
});
console.log(text);
await mcpHost.close();Closing the host is not cancelling a job
Calling close() disconnects the MCP session. A Sume job that a tool call already started keeps running and billing; closing the client does not cancel it. Keep the job id from the tool result and resume with jobs_status or jobs_wait, or cancel with jobs_cancel, which is a write tool.
Each jobs_wait call holds at most 55 seconds, so a long render needs the call repeated with the same ids.
What Sume does and does not do
Sume gates by credential: an OAuth session reads by default, an API-key session sees everything and must send an idempotency_key on writes and paid calls. It publishes mcp_health, tools_list and tools_schema as the first calls to verify a session.
Sume does not run Genkit's model for you; the orchestrating LLM and its bill belong to the Genkit side.
Sources
Related posts
More in Developers
- Get one Sume video model by id: GET /v1/video-router/models/{id}
Look up a single Sume video model's limits and price with GET /v1/video-router/models/{id}. Response fields, the 404 for unknown ids, and a short script.
- GitHub App ghs_ tokens are now ~520 characters: check Sume calls
GitHub's new installation tokens are about 520 characters, not 40. What breaks in a workflow that also calls Sume, and why Sume takes one credential header.
- Go 1.27 drains response bodies: a Sume job poll loop
Go 1.27 drains unread HTTP/1 body bytes on Close. A stdlib loop that polls GET /v1/jobs/:id/status and honors next_poll_after_seconds.
- Go webhook handler: verify the Sume sume-v1 signature
A stdlib Go verifier for x-sume-webhook-signature: HMAC-SHA256 over timestamp.raw_body, five-minute window, constant-time compare, empty secret refused.
Written by Sume