Strands Agents MCP: connect an agent to Sume's MCP server

Connect a Strands agent to a remote MCP server with MCPClient: Sume's hosted MCP URL, an API-key header, and tool_filters to keep paid tools out.

5 min readSume
All posts

Strands Agents connects to MCP servers through MCPClient: give it a remote server's url and headers, pass the client to Agent(tools=[...]), and Strands loads the server's tools and hands them to the agent like any other tool. For Sume's hosted MCP server, the URL is https://mcp.sume.com/mcp and the header is Authorization: Bearer with a Sume API key; tool_filters keeps paid tools out unless you want them.

Strands' side comes from Connect your agent to MCP tools, MCP transports, and the MCPClient API reference; Sume's side comes from MCP OAuth and API keys, MCP tools and gates, and Jobs and results, all read on 2026-09-28. Strands Agents is an open-source SDK for Python and TypeScript whose default model provider is Amazon Bedrock; this post uses Python. Sume has no official Strands integration: the agent connects to Sume's remote MCP server like any other, and Sume's basics page says hosted MCP still works but is not part of the primary path today.

How do I connect a Strands agent to Sume's MCP server?

Pass the client straight to the agent, the pattern Strands recommends, so the connection's lifecycle is managed for you. With url set, MCPClient builds the Streamable HTTP transport itself, and headers go out on every request. Read the key from the environment, never from the prompt:

import os
from strands import Agent
from strands.tools.mcp import MCPClient

sume = MCPClient(
    url="https://mcp.sume.com/mcp",
    headers={"Authorization": f"Bearer {os.environ['SUME_API_KEY']}"},
    # Read tools only; add "generate_image" behind an approval step.
    tool_filters={"allowed": ["mcp_health", "tools_list", "jobs_status",
                              "jobs_wait", "jobs_result"]},
)

agent = Agent(tools=[sume])
agent("Call mcp_health and summarize what it reports.")

Which MCPClient settings matter for Sume?

Strands' transports page also shows MCPClient(lambda: streamablehttp_client(url=..., headers=...)). The MCP Python SDK's v1.x source marks streamablehttp_client deprecated ("Use streamable_http_client instead"), so the url form above avoids that helper.

From Strands' MCPClient API reference and MCP transports; Sume values from MCP OAuth and API keys, read 2026-09-28.
ArgumentWhat Strands' docs sayFor Sume
urlA streamable HTTP transport is constructed automatically.https://mcp.sume.com/mcp
headersHTTP headers on every request; requires url.Authorization: Bearer <key> or x-api-key
tool_filtersallowed names or regex patterns; allowed applies first, then rejected.Only the tools the agent needs
authOAuth with the client_credentials grant, for machine-to-machine use.Won't work: Sume's current server accepts only authorization_code
auth_providerAny httpx.Auth, for flows such as the interactive authorization_code grant.Needs a person to sign in in a browser
startup_timeoutTimeout after which server initialization is cancelled; default 30.Default

Why use an API key instead of Strands' OAuth option?

Because the two OAuth paths don't fit an unattended agent. Strands' auth option authenticates with the OAuth client_credentials grant, and Sume's current server advertises only the authorization_code grant. auth_provider can run the interactive authorization_code flow, but someone has to sign in, consent starts with Write off, and in Sume's current code the access token lasts one hour with no refresh token.

A key session sees Sume's full hosted tool set, and spend resolves to the key's workspace. Keep the key on a trusted server or in a secret store, never in frontend code, and rotate it if it appears in logs or chat history.

How do I keep the agent from spending?

Load only what the task needs. Python's tool_filters loads only the tool names listed under allowed, and a rejected list removes tools after that. When the agent may spend, put a person in the loop: Strands' HumanInTheLoop intervention, passed to the agent's interventions, pauses before a tool call so someone can approve, edit, or reject it. Tools in the handler's own allowed_tools skip approval, so name only Sume's read tools there. Each paid Sume tool needs an idempotency_key; dry_run=true previews admission and cost without submitting the job, and max_spend_usd caps a call only when it is sent. The model writes those arguments, so your code doesn't enforce them. Sume MCP tools list groups the tools by read, write, and paid.

How long can a Sume tool call take?

A jobs_wait call holds for up to 55 seconds, or 50 when timeout_seconds is omitted. Strands advises setting timeouts for tool calls so long operations don't hang, so leave more than 55 seconds. A client-side timeout does not cancel the job, which keeps running and still bills, so on wait_slice_expired the agent should call jobs_wait again with the same ids and never resubmit the paid create.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume