Kilo Code MCP server: add Sume in kilo.jsonc
Add Sume's hosted MCP server to Kilo Code under the mcp key in kilo.jsonc: type remote, the Sume URL, and an API key header or an OAuth sign-in.

To add an MCP server to Kilo Code, put it under the top-level mcp key of a Kilo config file, such as kilo.jsonc in your project or ~/.config/kilo/kilo.jsonc for every project; the extension's MCP settings write to the same file. For Sume's hosted MCP server, the entry is "type": "remote" with "url": "https://mcp.sume.com/mcp", plus an Authorization: Bearer header carrying a Sume API key, or no header and an OAuth sign-in, which Kilo starts automatically for servers that support it.
Kilo's side comes from its Using MCP in Kilo Code page, whose VS Code and CLI tabs sometimes differ; Sume's side comes from MCP OAuth and API keys, MCP tools and gates, and Jobs and results, all read on 2026-09-28. Sume has no official Kilo Code connector: Kilo connects to Sume's remote MCP server like any other, and Sume's basics page says hosted MCP still works but is not part of the primary path today. The sibling extensions have their own posts: Roo Code and Cline.
Where does Kilo Code's MCP config go?
In the VS Code extension, MCP servers live in the main Kilo config file at two levels, and the project level takes precedence over the global one. In the extension you can also open Settings → MCP, click Add Server, choose Remote (HTTP), and enter the URL and optional headers.
- Global:
~/.config/kilo/kilo.jsonc, for all projects. - Project:
kilo.jsoncin the project root, or.kilo/kilo.jsonc. - The CLI recommends
kilo.jsonat the same places and also readskilo.jsonc. {env:SUME_API_KEY}reads an environment variable, so the key stays out of a file you might commit.
{
"mcp": {
"sume": {
"type": "remote",
"url": "https://mcp.sume.com/mcp",
"headers": {
"Authorization": "Bearer {env:SUME_API_KEY}"
},
"enabled": true,
"timeout": 60000
}
}
}Should I use an API key or OAuth with Kilo?
Sume's hosted MCP accepts both, and they behave differently:
- API key: Sume accepts
Authorization: Bearerorx-api-key. A key session sees Sume's full hosted tool set, paid tools included, and spend resolves to the key's workspace. - OAuth: leave out
headers. In the extension, aneeds_authstatus shows a notification that starts the sign-in; the CLI haskilo mcp auth."oauth": falseturns OAuth off. - Sume's consent page keeps Write off by default, and without Write, paid tools such as
generate_imagereturninsufficient_scope. In current code, Sume's tokens last one hour and it issues no refresh token, so expect to sign in again.
How do I stop Kilo from running paid Sume tools unasked?
Kilo runs MCP tool calls through its permission system. Each tool's permission key is {server}_{tool}, so Sume's generate_video on a server named sume is sume_generate_video. When a tool is called, the Permission Dock asks for approval; Approve Always saves an allow rule, and the permission key in the config file takes tool names or wildcard patterns. Sume's authentication docs ask for explicit confirmation before write or paid generation, so allow only read tools:
- Don't allow
sume_*: the wildcard would auto-approve paid tools too. - Paid tools need an
idempotency_key;dry_run=truepreviews cost without submitting;max_spend_usdcaps a call only when it is sent.
{
"permission": {
"sume_mcp_health": "allow",
"sume_tools_list": "allow",
"sume_tools_schema": "allow",
"sume_jobs_wait": "allow",
"sume_jobs_result": "allow"
}
}What does each field in the remote entry do?
| Field | What Kilo's docs say | For Sume |
|---|---|---|
type | Must be "remote" for a remote server | remote |
url | URL of the remote MCP server | https://mcp.sume.com/mcp |
headers | HTTP headers to send with requests | Authorization, or none for OAuth |
enabled | Enable or disable the server on startup | true |
timeout | Milliseconds; default 15 seconds for remote servers (VS Code tab), 30000 (CLI tab) | 60000 |
oauth | false disables OAuth | Unset for OAuth |
Why set timeout, and what else should I know?
- One Sume
jobs_waitcall holds for up to 55 seconds, or 50 whentimeout_secondsis omitted. Kilo's CLI tab callstimeoutthe timeout for fetching tools, and its page doesn't say whether it also bounds a tool call, so the example sets a value above one full Sume wait. - On
wait_slice_expired, the agent should calljobs_waitagain with the same ids and never resubmit the paid create. MCP tool call timeouts on long-running video jobs covers the pattern. enabled: falseturns Sume's server off without removing its entry.- Hosted MCP can't read files from your laptop.
Sources
Related posts
More in Integrations
- Kling API in n8n: HTTP Request node, auth, and waiting
Call the Kling API from n8n with an HTTP Request node and a Bearer credential, then poll or resume a Wait node. Direct to Kling, or kling-3 through Sume.
- Langflow MCP client: add Sume's hosted MCP server
Use Langflow as an MCP client for Sume's hosted server: register it with a Bearer global variable, then wire MCP Tools into an Agent.
- LibreChat MCP server: add Sume in librechat.yaml
Add Sume's hosted MCP server to LibreChat under mcpServers in librechat.yaml: streamable-http, a Bearer key header, and requiresOAuth set to false.
- LlamaIndex MCP: load Sume's hosted tools into an agent
Load Sume's hosted MCP tools into a LlamaIndex agent with BasicMCPClient and aget_tools_from_mcp_url, a Bearer key header, and allowed_tools.
Written by Sume