Qwen Code MCP server: add Sume with qwen mcp add --transport http
Add Sume's hosted MCP to Qwen Code with qwen mcp add --transport http: an API-key header, a timeout above 55 s, and include-tools to keep paid tools out.

To add Sume to Qwen Code, run qwen mcp add --transport http sume https://mcp.sume.com/mcp with a --header carrying your Sume API key, a --timeout above 55000 ms, and, if you want a safe first session, an --include-tools list of read-only tools. Qwen Code stores the entry in settings.json under mcpServers, using the httpUrl key for HTTP servers (read 2026-10-02).
Qwen Code's MCP page documents a settings.json entry with httpUrl and headers, so the setup is a single command or a small JSON edit.
What the Qwen Code docs list
The Qwen Code MCP page documents the qwen mcp add flags below. The docs show OAuth flags that take explicit authorization and token URLs, and Sume's own docs describe OAuth through discovery metadata for Cursor, Claude Code and Codex, so this post uses the API-key path for Qwen Code.
| Flag or key | What the Qwen docs say | For Sume |
|---|---|---|
--transport http | Selects the HTTP transport | http |
--header | Adds a custom header such as an Authorization bearer token | x-api-key: <key> or Authorization: Bearer <key> |
--timeout | Timeout in milliseconds; the docs example uses 5000 | 60000, above the 55 s jobs_wait hold |
--trust | Skips confirmations in trusted workspaces | Leave off for a key that can spend |
--include-tools / --exclude-tools | Allowlist or blocklist tool names | Read-only list first |
--scope | user or project | user |
qwen mcp add --transport http --scope user \
--header "x-api-key: $SUME_API_KEY" \
--timeout 60000 \
--include-tools mcp_health,tools_list,tools_schema,balance_get,jobs_status,jobs_result \
sume https://mcp.sume.com/mcpWhy timeout and scope matter
Sume's jobs_wait tool holds a call for at most 55 seconds, 50 by default, and answers wait_slice_expired when the slice ends so the client retries with the same ids. A 5000 ms client timeout, like the one in the Qwen docs example, would cut that wait short, so set --timeout above 55000 (Jobs and results).
Use --scope user. The Qwen docs show headers stored as plain text in settings.json; the project scope writes .qwen/settings.json inside the repo, where a key could be committed by accident. The user scope writes ~/.qwen/settings.json, which stays on your machine.
Keep paid tools out of the first session
Sume documents that an API-key session sees the full hosted tool set, including paid generation tools. Paid and write calls need an idempotency_key, dry_run previews cost, and max_spend_usd is enforced only when you pass it (MCP tools and gates). Nothing in the Qwen flags changes that, so the --include-tools list above is your guard.
Start with the discovery tools mcp_health and tools_list, then ask the agent to call tools_schema for generate_image and explain dry_run. When you want to generate, widen the list or re-add the server with the paid tools you need.
What this post does not claim
Verify the connection by asking for mcp_health; it reports the endpoint and auth source (MCP quickstart).
- It does not claim Qwen Code can complete Sume OAuth. Sume's docs do not cover that client.
- It does not claim
includeToolstakes the same names Qwen shows for other servers; check withtools_listafter connecting. --trustis documented as skipping confirmations, so a trusted workspace can run a paid Sume tool without asking.
Sources
Related posts
More in Integrations
- Raycast MCP: add Sume's hosted server with Dynamic OAuth
Add Sume to Raycast as an HTTP MCP server: URL, Dynamic OAuth sign-in, read-only by default, and when to switch to an API-key header for paid tools.
- Replit Add MCP server: connect Sume with an X-API-Key header
Replit's Add MCP server flow takes an HTTPS endpoint, optional custom headers and Test and save. Connect Sume's hosted MCP and confirm the tools load.
- Slack Events API retries 3 times: keep one Sume run per event
Slack retries a missed Events API ack three times and can disable your subscriptions. Ack in 3 seconds and let an Idempotency-Key keep one Sume run per event.
- smolagents MCPClient: give a CodeAgent Sume's remote tools
Connect a smolagents CodeAgent to Sume's hosted MCP with MCPClient and the streamable-http transport, send an API key header, and wait on jobs correctly.
Written by Sume