OpenAI Agents API remote MCP server: what to give it for Sume

OpenAI's Agents API takes MCP servers at session setup. Give it Sume's mcp.sume.com/mcp URL and an API key, and gate paid calls with idempotency_key.

4 min readSume
All posts

Any remote MCP client needs three things from Sume: the endpoint https://mcp.sume.com/mcp, a credential, and a plan for paid calls. OpenAI's Agents API guide says tools or MCP servers are configured at session setup, so those three values are what you bring to that step. The guide's exact field names are on OpenAI's page, so this post does not repeat them.

What does the Agents API say about MCP servers?

OpenAI's overview says the API manages sessions, orchestration, context compaction, and recovery, while your application provides tools and chooses its execution environment. It says tools or MCP servers are configured at session setup, and that the API is in beta with US data residency only and no Zero Data Retention.

Those limits matter before you point it at a media account: check them against your own data rules on OpenAI's page.

What does Sume need at the other end?

The URL, a credential, and awareness of what the credential unlocks.

An API-key session sees the full hosted tool set, including write and paid tools, and the docs say execution still requires idempotency_key on mutating and paid calls.

What to supply for a remote MCP client, read 2026-09-29.
ItemValueWhere it is documented
Endpointhttps://mcp.sume.com/mcpSume MCP quickstart
API-key credentialAuthorization: Bearer <SUME_API_KEY> or x-api-keySume MCP OAuth page
Paid createidempotency_key requiredSume MCP tools and gates
Session setupTools or MCP servers configuredOpenAI Agents API overview

Which credential should a managed agent use?

A managed agent runs without a person watching, which is the case Sume's docs give for API-key remote MCP: automation that does not speak OAuth. Whether the Agents API can send a custom authorization header is a question for OpenAI's guide, and the snapshot this post used does not say. If it cannot, Sume's OAuth flow is the other route, and it grants read-only access unless Write is switched on at consent.

Never paste the key into a prompt. Sume's docs say to rotate a key that appears in logs or chat history.

How do I keep a paid tool from running away?

Ask the agent to call tools_schema and dry_run=true before any paid create, and pass max_spend_usd when you want a cap. Sume's docs say the cap is enforced only when provided, and that idempotency_key is for transport and dedup, not human approval. The playbook is in MCP tools and gates.

What should the first session do?

Keep it read-only. Ask it to call mcp_health and tools_list, then summarize the tools, exactly as Sume's quickstart suggests for a first check. Only after that let it near generate_image or another paid tool.

Sume's docs say hosted MCP cannot read files from your laptop: upload is create an upload URL, have the client PUT the bytes, then assets_complete. A managed session with its own execution environment needs a plan for that step, so decide where the bytes come from before you rely on it.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume