Hermes Agent MCP server: add Sume in config.yaml
Add Sume's hosted MCP server to Hermes Agent under mcp_servers in config.yaml, with an API-key header or OAuth, and paid tools behind approval.

To add an MCP server to Hermes Agent, put an entry under mcp_servers in ~/.hermes/config.yaml: command and args for a local server, or url and headers for a remote one. For Sume's hosted MCP server that is url: "https://mcp.sume.com/mcp" with your Sume API key in an Authorization header, or auth: oauth to sign in through the browser instead. Hermes discovers servers at startup, and /reload-mcp picks up a change mid-session.
Hermes' side comes from its MCP guide and MCP Config Reference; Sume's side comes from MCP OAuth and API keys, MCP tools and gates, and Jobs and results, all read on 2026-09-28. Sume has no official Hermes Agent integration: Hermes connects to Sume's remote MCP server like any other, and Sume's basics page says hosted MCP still works but is not part of the primary path today. Hermes can also serve MCP itself with hermes mcp serve, a stdio-only server today; this post covers the client side.
How do I add Sume to config.yaml?
String values anywhere in a server entry, headers included, can reference an environment variable as ${VAR}. They resolve from the active profile's secret scope, falling back to the process environment, so put SUME_API_KEY in ~/.hermes/.env and keep the key out of the YAML. An unset variable keeps its literal placeholder.
After you save the entry below, run /reload-mcp, then hermes mcp test sume, which reports what the server actually answered; a 401 or 403 means the token or OAuth grant is wrong. Then ask Hermes to call mcp_health and tools_list, Sume's read-only discovery tools. The entry also limits the tools and makes paid calls ask first, as the next sections explain:
mcp_servers:
sume:
url: "https://mcp.sume.com/mcp"
headers:
Authorization: "Bearer ${SUME_API_KEY}"
trust: untrusted
tools:
include: [mcp_health, tools_list, tools_schema, generate_image, jobs_wait, jobs_result]Should I use an API key or OAuth?
Either works with Hermes' documented options. Replace headers with auth: oauth and Hermes runs the MCP SDK's OAuth 2.1 PKCE flow: metadata discovery, client identification, token exchange, and refresh. It identifies itself with a Client ID Metadata Document only when a server advertises client_id_metadata_document_supported: true. Sume's current metadata doesn't, and it does advertise a registration endpoint, so Hermes registers through dynamic client registration. Run the first sign-in with hermes mcp login sume from a fresh terminal: an edit made inside a running session reloads with a 30-second timeout, too short for an interactive flow, while hermes mcp login waits the full 5 minutes. On Sume's consent screen Read is locked on and Write is off by default; turn Write on if Hermes should generate.
OAuth has a catch on Sume today. In current code a Sume token lasts one hour and Sume issues no refresh token, so Hermes' automatic refresh has nothing to work with: expect to sign in again about hourly with hermes mcp login sume. The gateway and /reload-mcp never open a browser. For a gateway nobody watches, the API-key header is the practical choice; it sees Sume's full hosted tool set, which is why the entry above narrows it.
Will Hermes ask before a paid Sume tool runs?
Yes, when you mark the server untrusted. trust defaults to full. With trust: untrusted, every write-capable tool call, meaning any tool without a readOnlyHint: true annotation, needs your approval through Hermes' approval surface before it runs. Sume's current server marks its read tools readOnlyHint: true and its write and paid tools false, so jobs_wait and jobs_result run without asking and every generate_image call waits for you. MCP tool annotations explains the hint.
tools.includeregisters only the listed Sume tools, as exact names or globs; ifincludeandexcludeare both set,includewins. Write the original MCP tool names.- Sume's paid tools need an
idempotency_keyon every call.dry_run=truepreviews admission and cost without submitting, andmax_spend_usdcaps a call only when it is sent.
Does a long Sume job fit Hermes' timeouts?
Yes, with the defaults. timeout is the tool call timeout in seconds and defaults to 300, and Sume's jobs_wait holds one call for at most 55 seconds. For a longer render the agent should call jobs_wait again with the same ids and never resubmit the paid create. Hermes registers resource and prompt helpers only when a session supports them; Sume's current server declares only tools, so none appear.
| Key | What Hermes' reference says | For Sume |
|---|---|---|
url | Remote MCP endpoint | https://mcp.sume.com/mcp |
headers | Headers for remote server requests | Authorization with Bearer and your key, or x-api-key |
auth | oauth enables OAuth 2.1 with PKCE | Instead of headers, for a browser sign-in |
timeout | Tool call timeout in seconds; default 300 | The default covers the 55-second jobs_wait hold |
connect_timeout | Initial connection timeout in seconds; default 60 | The default |
trust | full (default) or untrusted | untrusted, so paid tools ask first |
transport | sse switches to the SSE transport | Leave it unset; Sume serves Streamable HTTP |
Sources
Related posts
More in Integrations
- HeyGen MCP server: URL, setup for Claude, and credits
HeyGen MCP runs at mcp.heygen.com/mcp/v1/. Add it to Claude Code or Claude, sign in with OAuth, and videos use your HeyGen plan's credits.
- Higgsfield MCP: server URL, setup, and what it costs
Higgsfield MCP runs at mcp.higgsfield.ai/mcp. Sign in with a Higgsfield account, no API key; each generation spends your plan's credits.
- Hono webhook: verify the signature on the raw body
Read the raw body with c.req.text(), verify the HMAC signature, then JSON.parse that string and answer 204. Works on Workers, Bun, Deno and Node.
- IntelliJ GitHub Copilot MCP: add Sume in mcp.json
Add an MCP server to GitHub Copilot in IntelliJ IDEA: Agent mode, Add MCP Tools, and a servers entry for Sume's hosted MCP with an API-key header.
Written by Sume