LlamaIndex MCP: load Sume's hosted tools into an agent

Load Sume's hosted MCP tools into a LlamaIndex agent with BasicMCPClient and aget_tools_from_mcp_url, a Bearer key header, and allowed_tools.

5 min readSume
All posts

LlamaIndex uses MCP servers through the llama-index-tools-mcp package: BasicMCPClient connects to a server, and aget_tools_from_mcp_url or McpToolSpec turns the server's tools into FunctionTools you pass to any agent. For Sume's hosted MCP server, point the client at https://mcp.sume.com/mcp, send a Sume API key in headers, and name the tools the agent needs in allowed_tools.

LlamaIndex's side comes from its Using MCP Tools with LlamaIndex guide, MCP usage examples, and MCP API reference; Sume's side comes from MCP OAuth and API keys, MCP tools and gates, and Jobs and results, all read on 2026-09-28. Sume has no official LlamaIndex connector: this is LlamaIndex's own MCP client talking to Sume's remote server, and Sume's basics page says hosted MCP still works but is not part of the primary path today. LlamaIndex image generation tool wraps Sume's REST Image API in a FunctionTool instead.

How do I load Sume's MCP tools into a LlamaIndex agent?

Install llama-index-tools-mcp. BasicMCPClient treats an https URL such as Sume's as a Streamable HTTP endpoint. The example keeps four Sume tools and pins a spend cap on the paid one:

  • allowed_tools returns only the named tools. Leaving it out returns every tool, and an empty list returns none, with a warning.
  • partial_params_by_tool maps tool names to fixed arguments. In the reference's source listing, those fields are removed from the schema the model sees and passed to the tool as partial params, so the model isn't asked for the cap; Sume enforces max_spend_usd whenever it is sent.
  • The model still writes idempotency_key, which every paid Sume tool requires, and can preview cost with dry_run=true.
import asyncio
import os
from llama_index.core.agent.workflow import FunctionAgent
from llama_index.llms.openai import OpenAI
from llama_index.tools.mcp import BasicMCPClient, aget_tools_from_mcp_url

SUME_MCP = "https://mcp.sume.com/mcp"

async def main() -> None:
    client = BasicMCPClient(
        SUME_MCP,
        headers={"Authorization": f"Bearer {os.environ['SUME_API_KEY']}"},
        timeout=60,
    )
    tools = await aget_tools_from_mcp_url(
        SUME_MCP,
        client=client,
        allowed_tools=["tools_schema", "generate_image", "jobs_wait", "jobs_result"],
        partial_params_by_tool={"generate_image": {"max_spend_usd": 2}},
    )
    agent = FunctionAgent(
        tools=tools,
        llm=OpenAI(model="gpt-5-mini"),
        system_prompt="Preview paid calls with dry_run=true. Wait with jobs_wait; never resubmit.",
    )
    print(await agent.run("A product photo of a red mug on a white table."))

asyncio.run(main())

Which timeout should BasicMCPClient use?

BasicMCPClient documents timeout, the timeout for HTTP operations in seconds (default 30), and sse_read_timeout, the timeout for SSE reads (default 300). The reference's source listing also passes timeout to the MCP session as read_timeout_seconds. One Sume jobs_wait call can hold for up to 55 seconds, or 50 when timeout_seconds is omitted, and current code gives each MCP request a 60-second deadline, so timeout=60 is at least as long as any single Sume call.

From LlamaIndex's MCP API reference; Sume values from MCP OAuth and API keys and Jobs and results, read 2026-09-28.
`BasicMCPClient` parameterLlamaIndex defaultFor Sume
command_or_urlRequiredhttps://mcp.sume.com/mcp
headersNoneAuthorization: Bearer …
timeout30 seconds60
sse_read_timeout300 secondsDefault
authNone (an OAuth client provider)Unset with a key
http_clientNone; when set, timeout and headers are ignoredUnset

Can I use OAuth instead of an API key?

LlamaIndex has BasicMCPClient.with_oauth(...), which takes a client name, redirect URIs, and handlers for the redirect and the returned code. It keeps tokens in memory by default, so they are lost on restart, and its source registers for the authorization_code and refresh_token grants. Sume's OAuth behaves differently from a key; MCP server OAuth flow on Sume has the details.

  • Sessions are read-only until the user turns Write on at consent; without Write, paid tools such as generate_image return insufficient_scope.
  • In current code, access tokens last one hour and Sume issues no refresh token, so a long-running LlamaIndex service would need a new sign-in about every hour.
  • Sume keeps API-key remote MCP as the path for automation that doesn't speak OAuth, which fits a server-side agent.

What else should I know?

  • Leave include_resources at its default, False. In current code, Sume's server declares only the tools capability and answers other methods, such as resource listing, with a method-not-found error.
  • An API-key session sees Sume's full hosted tool set, paid tools included; allowed_tools is your narrowing.
  • On wait_slice_expired, the agent should call jobs_wait again with the same ids and never resubmit the paid create. MCP tool call timeouts on long-running video jobs covers the pattern.
  • Keep the key on a trusted server or in a secret store, never in frontend JavaScript. Hosted MCP can't read files from your laptop.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume