Microsoft Agent Framework hosted MCP tool for Sume (Python)
Attach https://mcp.sume.com/mcp to an Agent Framework agent with get_mcp_tool, allowed_tools and approval_mode. Foundry runs the calls, so mind the key.

Short answer
Create the tool with client.get_mcp_tool(name=..., url="https://mcp.sume.com/mcp", headers=..., approval_mode=..., allowed_tools=[...]) and pass it in tools=[...] to Agent. The Microsoft Learn page, last updated 2026-09-23, documents that call shape for Python, including headers, approval_mode values never_require and always_require, and allowed_tools.
The detail that matters for Sume: a hosted MCP tool is executed by the backing service, not by your process. The page says the MCP server is hosted and managed by Foundry for the Foundry client, and for the OpenAI client says the tool is executed remotely by OpenAI. So the Sume API key you put in headers travels to that service.
What the Microsoft page documents
Approval and filtering are the controls you have. Both are worth setting deliberately when the server behind the tool can spend money.
| Option | What the page says |
|---|---|
| get_mcp_tool(name, url) | creates a hosted MCP tool from a chat client |
| headers | sent to the MCP server, for example an Authorization bearer value |
| approval_mode | never_require or always_require |
| allowed_tools | omit or None sends no filter; [] sends an empty allowlist; names allow only those tools |
The agent
This is the page's own pattern with Sume substituted for the example server. It allows only discovery and job-reading tools, so a first run cannot start paid generation; because the allowlist is read-only, the sample sets never_require so the run completes without an approval loop. Set FOUNDRY_PROJECT_ENDPOINT and FOUNDRY_MODEL as the page describes, sign in with the Azure CLI, and export SUME_API_KEY.
import asyncio, os
from agent_framework import Agent
from agent_framework.foundry import FoundryChatClient
from azure.identity.aio import AzureCliCredential
async def main():
async with AzureCliCredential() as credential:
client = FoundryChatClient(credential=credential)
sume = client.get_mcp_tool(
name="Sume",
url="https://mcp.sume.com/mcp",
headers={"Authorization": "Bearer " + os.environ["SUME_API_KEY"]},
approval_mode="never_require",
allowed_tools=["mcp_health", "tools_list", "jobs_status", "jobs_wait"],
)
async with Agent(
client=client,
name="SumeAgent",
instructions="Use the Sume tools to report endpoint health and job status.",
tools=[sume],
) as agent:
result = await agent.run("Call mcp_health, then tools_list, and summarize.")
print(result.text)
asyncio.run(main())Opening the allowlist later
To let the agent submit work, add the generate tool you intend to use to allowed_tools, switch approval_mode to always_require (and handle the approval requests your host surfaces), and remember that Sume's hosted MCP requires an idempotency_key on every mutating or paid call. Ask for dry_run=true first, and pass max_spend_usd so a looping agent has a ceiling.
For a render that outlasts one wait, jobs_wait holds at most 55 seconds per call and answers wait_slice_expired when the slice ends; the agent should call it again with the same ids instead of resubmitting.
What Sume does and does not do
Sume's hosted MCP serves read tools to an OAuth session by default and the full tool set to an API-key session. It does not accept an OAuth token as an API key, and it has no paid OAuth scope.
Sume cannot see or limit what the agent host does with the key beyond the tool gates: use a key created for this integration so it can be rotated alone.
Sources
Related posts
More in Developers
- Migrate Video 1.0 to sume/auto on POST /v1/videos, field by field
Video 1.0 is retiring soon. Which fields move, which are ignored or rejected, and the request to send on POST /v1/videos with sume/auto.
- Migrate POST /v1/video-router/generate to /v1/videos: a field map
Same model ids, same jobs, different wire. How image_url and reference_image_urls become frame_images and input_references, and what stays on Video Router.
- MiniMax H3 Max in TypeScript: submit, poll and download with fetch
A TypeScript script under 30 lines: submit a minimax-h3-max job on Sume, poll until completed, save the MP4. Status values and the 409 on failed jobs.
- Mistral Vibe tool globs: keep Sume to read-only tools
Vibe prefixes MCP tools with the server name and lets you allow or deny them by glob. A read-only Sume allowlist for a key that otherwise sees paid tools.
Written by Sume