Goose 1.53 MCP redirect SSRF guard: Sume endpoint still works?

Goose 1.53.0 guards MCP streamable-HTTP client redirects against SSRF. Add Sume as a direct URL and keep the endpoint redirect-free.

5 min readSume
All posts

Use the documented endpoint, https://mcp.sume.com/mcp, as the remote extension URL in Goose. Goose v1.53.0 (2026-10-02) added a guard on MCP streamable-HTTP client redirects against server-side request forgery, so any setup that relied on a redirect to reach the real server is the one to fix.

A direct URL gives the guard nothing to block.

What the release says

The v1.53.0 notes list Guard MCP streamable-HTTP client redirects against SSRF (PR #11501). They also remove MCP sampling code and add MCP Apps picture-in-picture.

At a glance

Goose 1.53 items relevant to Sume, read 2026-10-03.
ChangeEffect on a Sume connection
Redirect SSRF guardRedirecting URLs may be blocked; use the direct endpoint
MCP sampling code removedNone; Sume does not use sampling
MCP Apps picture-in-pictureNone; Sume ships tools only

Setting up Sume in Goose

Add a streamable HTTP extension pointing at the endpoint above and authenticate with an API key or OAuth. Sume's server is tools-only; sampling is unsupported on Sume's side, so the sampling removal changes nothing for this connection.

Keep the idempotency_key habit from earlier Goose retry changes: any paid create call needs one, and a retry with the same key is safe.

  • Use the direct URL, not a forwarder.
  • Check the extension loads with mcp_health.
  • Use dry_run or max_spend_usd on paid calls.

Limits and what is not verified

The release note does not define which redirects the guard allows, and I did not run Goose against a redirecting URL. The Sume claims come from Sume's docs, not from a Goose test.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume