Google Cloud CLI remote MCP plus Sume MCP in one agent
Google's Cloud CLI remote MCP server is in preview. Two hosted MCP servers in one agent: what each does and how to keep their permissions apart.

You can connect Google's Cloud CLI remote MCP server and Sume's hosted server to the same agent; they are independent endpoints with separate sign-in. Google announced the Cloud CLI server in preview on 2026-09-30 at https://cloudcli.googleapis.com/mcp, and Sume's is https://mcp.sume.com/mcp.
The risk to manage is permission blur, since one agent now holds a cloud-operations tool and a spend-capable media tool.
What Google's server offers
Per the announcement it exposes run_gcloud_command and run_bq_command, authenticates with keyless Agent Identity or OAuth 2.0, needs the Cloud CLI Execution API enabled and the roles/mcp.toolUser role, and has no extra charge for the server itself.
At a glance
| Item | Google Cloud CLI | Sume |
|---|---|---|
| Endpoint | https://cloudcli.googleapis.com/mcp | https://mcp.sume.com/mcp |
| Status | Preview (2026-09-30) | Hosted MCP server |
| Auth | Agent Identity or OAuth 2.0 | OAuth or API key |
| Tools | run_gcloud_command, run_bq_command | See tools_list |
What Sume's server offers
Sume's is a tools-only server for generation, jobs and assets. OAuth gives mcp:read by default and mcp:write on opt-in; an API key is the alternative. Write and paid calls need an idempotency_key.
Keep the two apart: give each its own approval rules, and never let a prompt from a Sume result flow into a gcloud command without review.
- Separate scopes: mcp:read for Sume, least-privilege role for Google.
- Review any command text the model builds from tool output.
- Set max_spend_usd on Sume paid calls.
Limits and what is not verified
I did not connect both in one client for this post. The Google details come from the announcement, which is a preview and may change.
Sources
Related posts
More in Integrations
- Google lifestyle_image_link vs additional_image_link
Put the AI scene in lifestyle_image_link, angles in additional_image_link, and host stable URLs. Limits, a Sume request and a feed snippet.
- Goose 1.53 MCP redirect SSRF guard: Sume endpoint still works?
Goose 1.53.0 guards MCP streamable-HTTP client redirects against SSRF. Add Sume as a direct URL and keep the endpoint redirect-free.
- Home Assistant MCP integration vs Sume's POST-only MCP URL
Home Assistant's MCP integration asks for an SSE Server URL. Sume's hosted MCP endpoint is POST-only, so here is what lines up and what to use instead.
- Kiro CLI 2.26 asks more in untrusted workspaces: Sume dry_run first
Kiro CLI 2.26 tightens approval checks for MCP tools in untrusted workspaces. What that means for Sume paid tools and how to make each prompt informative.
Written by Sume