Hermes Agent MCP server: add Sume in config.yaml

Add Sume's hosted MCP server to Hermes Agent under mcp_servers in config.yaml, with an API-key header or OAuth, and paid tools behind approval.

5 min readSume
All posts

To add an MCP server to Hermes Agent, put an entry under mcp_servers in ~/.hermes/config.yaml: command and args for a local server, or url and headers for a remote one. For Sume's hosted MCP server that is url: "https://mcp.sume.com/mcp" with your Sume API key in an Authorization header, or auth: oauth to sign in through the browser instead. Hermes discovers servers at startup, and /reload-mcp picks up a change mid-session.

Hermes' side comes from its MCP guide and MCP Config Reference; Sume's side comes from MCP OAuth and API keys, MCP tools and gates, and Jobs and results, all read on 2026-09-28. Sume has no official Hermes Agent integration: Hermes connects to Sume's remote MCP server like any other, and Sume's basics page says hosted MCP still works but is not part of the primary path today. Hermes can also serve MCP itself with hermes mcp serve, a stdio-only server today; this post covers the client side.

How do I add Sume to config.yaml?

String values anywhere in a server entry, headers included, can reference an environment variable as ${VAR}. They resolve from the active profile's secret scope, falling back to the process environment, so put SUME_API_KEY in ~/.hermes/.env and keep the key out of the YAML. An unset variable keeps its literal placeholder.

After you save the entry below, run /reload-mcp, then hermes mcp test sume, which reports what the server actually answered; a 401 or 403 means the token or OAuth grant is wrong. Then ask Hermes to call mcp_health and tools_list, Sume's read-only discovery tools. The entry also limits the tools and makes paid calls ask first, as the next sections explain:

mcp_servers:
  sume:
    url: "https://mcp.sume.com/mcp"
    headers:
      Authorization: "Bearer ${SUME_API_KEY}"
    trust: untrusted
    tools:
      include: [mcp_health, tools_list, tools_schema, generate_image, jobs_wait, jobs_result]

Should I use an API key or OAuth?

Either works with Hermes' documented options. Replace headers with auth: oauth and Hermes runs the MCP SDK's OAuth 2.1 PKCE flow: metadata discovery, client identification, token exchange, and refresh. It identifies itself with a Client ID Metadata Document only when a server advertises client_id_metadata_document_supported: true. Sume's current metadata doesn't, and it does advertise a registration endpoint, so Hermes registers through dynamic client registration. Run the first sign-in with hermes mcp login sume from a fresh terminal: an edit made inside a running session reloads with a 30-second timeout, too short for an interactive flow, while hermes mcp login waits the full 5 minutes. On Sume's consent screen Read is locked on and Write is off by default; turn Write on if Hermes should generate.

OAuth has a catch on Sume today. In current code a Sume token lasts one hour and Sume issues no refresh token, so Hermes' automatic refresh has nothing to work with: expect to sign in again about hourly with hermes mcp login sume. The gateway and /reload-mcp never open a browser. For a gateway nobody watches, the API-key header is the practical choice; it sees Sume's full hosted tool set, which is why the entry above narrows it.

Will Hermes ask before a paid Sume tool runs?

Yes, when you mark the server untrusted. trust defaults to full. With trust: untrusted, every write-capable tool call, meaning any tool without a readOnlyHint: true annotation, needs your approval through Hermes' approval surface before it runs. Sume's current server marks its read tools readOnlyHint: true and its write and paid tools false, so jobs_wait and jobs_result run without asking and every generate_image call waits for you. MCP tool annotations explains the hint.

  • tools.include registers only the listed Sume tools, as exact names or globs; if include and exclude are both set, include wins. Write the original MCP tool names.
  • Sume's paid tools need an idempotency_key on every call. dry_run=true previews admission and cost without submitting, and max_spend_usd caps a call only when it is sent.

Does a long Sume job fit Hermes' timeouts?

Yes, with the defaults. timeout is the tool call timeout in seconds and defaults to 300, and Sume's jobs_wait holds one call for at most 55 seconds. For a longer render the agent should call jobs_wait again with the same ids and never resubmit the paid create. Hermes registers resource and prompt helpers only when a session supports them; Sume's current server declares only tools, so none appear.

Keys from Hermes Agent's MCP Config Reference; Sume values from MCP OAuth and API keys and Jobs and results, read 2026-09-28.
KeyWhat Hermes' reference saysFor Sume
urlRemote MCP endpointhttps://mcp.sume.com/mcp
headersHeaders for remote server requestsAuthorization with Bearer and your key, or x-api-key
authoauth enables OAuth 2.1 with PKCEInstead of headers, for a browser sign-in
timeoutTool call timeout in seconds; default 300The default covers the 55-second jobs_wait hold
connect_timeoutInitial connection timeout in seconds; default 60The default
trustfull (default) or untrusteduntrusted, so paid tools ask first
transportsse switches to the SSE transportLeave it unset; Sume serves Streamable HTTP

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume