Kilo Code MCP server: add Sume in kilo.jsonc

Add Sume's hosted MCP server to Kilo Code under the mcp key in kilo.jsonc: type remote, the Sume URL, and an API key header or an OAuth sign-in.

5 min readSume
All posts

To add an MCP server to Kilo Code, put it under the top-level mcp key of a Kilo config file, such as kilo.jsonc in your project or ~/.config/kilo/kilo.jsonc for every project; the extension's MCP settings write to the same file. For Sume's hosted MCP server, the entry is "type": "remote" with "url": "https://mcp.sume.com/mcp", plus an Authorization: Bearer header carrying a Sume API key, or no header and an OAuth sign-in, which Kilo starts automatically for servers that support it.

Kilo's side comes from its Using MCP in Kilo Code page, whose VS Code and CLI tabs sometimes differ; Sume's side comes from MCP OAuth and API keys, MCP tools and gates, and Jobs and results, all read on 2026-09-28. Sume has no official Kilo Code connector: Kilo connects to Sume's remote MCP server like any other, and Sume's basics page says hosted MCP still works but is not part of the primary path today. The sibling extensions have their own posts: Roo Code and Cline.

Where does Kilo Code's MCP config go?

In the VS Code extension, MCP servers live in the main Kilo config file at two levels, and the project level takes precedence over the global one. In the extension you can also open Settings → MCP, click Add Server, choose Remote (HTTP), and enter the URL and optional headers.

  • Global: ~/.config/kilo/kilo.jsonc, for all projects.
  • Project: kilo.jsonc in the project root, or .kilo/kilo.jsonc.
  • The CLI recommends kilo.json at the same places and also reads kilo.jsonc.
  • {env:SUME_API_KEY} reads an environment variable, so the key stays out of a file you might commit.
{
  "mcp": {
    "sume": {
      "type": "remote",
      "url": "https://mcp.sume.com/mcp",
      "headers": {
        "Authorization": "Bearer {env:SUME_API_KEY}"
      },
      "enabled": true,
      "timeout": 60000
    }
  }
}

Should I use an API key or OAuth with Kilo?

Sume's hosted MCP accepts both, and they behave differently:

  • API key: Sume accepts Authorization: Bearer or x-api-key. A key session sees Sume's full hosted tool set, paid tools included, and spend resolves to the key's workspace.
  • OAuth: leave out headers. In the extension, a needs_auth status shows a notification that starts the sign-in; the CLI has kilo mcp auth. "oauth": false turns OAuth off.
  • Sume's consent page keeps Write off by default, and without Write, paid tools such as generate_image return insufficient_scope. In current code, Sume's tokens last one hour and it issues no refresh token, so expect to sign in again.

How do I stop Kilo from running paid Sume tools unasked?

Kilo runs MCP tool calls through its permission system. Each tool's permission key is {server}_{tool}, so Sume's generate_video on a server named sume is sume_generate_video. When a tool is called, the Permission Dock asks for approval; Approve Always saves an allow rule, and the permission key in the config file takes tool names or wildcard patterns. Sume's authentication docs ask for explicit confirmation before write or paid generation, so allow only read tools:

  • Don't allow sume_*: the wildcard would auto-approve paid tools too.
  • Paid tools need an idempotency_key; dry_run=true previews cost without submitting; max_spend_usd caps a call only when it is sent.
{
  "permission": {
    "sume_mcp_health": "allow",
    "sume_tools_list": "allow",
    "sume_tools_schema": "allow",
    "sume_jobs_wait": "allow",
    "sume_jobs_result": "allow"
  }
}

What does each field in the remote entry do?

Fields from Kilo's Using MCP in Kilo Code (VS Code and CLI tabs); Sume values from MCP OAuth and API keys, read 2026-09-28.
FieldWhat Kilo's docs sayFor Sume
typeMust be "remote" for a remote serverremote
urlURL of the remote MCP serverhttps://mcp.sume.com/mcp
headersHTTP headers to send with requestsAuthorization, or none for OAuth
enabledEnable or disable the server on startuptrue
timeoutMilliseconds; default 15 seconds for remote servers (VS Code tab), 30000 (CLI tab)60000
oauthfalse disables OAuthUnset for OAuth

Why set timeout, and what else should I know?

  • One Sume jobs_wait call holds for up to 55 seconds, or 50 when timeout_seconds is omitted. Kilo's CLI tab calls timeout the timeout for fetching tools, and its page doesn't say whether it also bounds a tool call, so the example sets a value above one full Sume wait.
  • On wait_slice_expired, the agent should call jobs_wait again with the same ids and never resubmit the paid create. MCP tool call timeouts on long-running video jobs covers the pattern.
  • enabled: false turns Sume's server off without removing its entry.
  • Hosted MCP can't read files from your laptop.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume