ant apply agent file: declare the Sume server, keep the key out
In an ant apply agent file, declare the Sume server by name and URL, https://mcp.sume.com/mcp. The API key belongs in a vault, never in the committed file.

Put only the server name and URL, https://mcp.sume.com/mcp, in the agent file you commit, and supply the Sume API key through a vault credential. The file is reviewed and locked in your repository, so a key inside it would be committed with it.
Vendor facts are from the ant apply page (CLI 1.30.0 or later); Sume facts from the MCP overview and OAuth and API keys, read 2026-10-01.
What does ant apply do?
It creates and updates Claude API resources from files: agents, environments, skills, memory stores, deployments and vaults. You run it, approve the plan it prints, then commit the claude-lock.json it writes so the next run updates the same resources instead of creating new ones.
What goes in the file and what does not?
| Value | In the committed file? | Source |
|---|---|---|
MCP URL https://mcp.sume.com/mcp | Yes | MCP overview |
Header x-api-key: $SUME_API_KEY | No, produced by the vault credential | OAuth and API keys |
| Write access | Not a file setting: OAuth mcp:write or an API key | There is no mcp:paid scope |
idempotency_key | Not config: passed on every write or paid call | Required on write and paid tools |
Does reviewing the plan cover paid calls?
Not by itself. The plan approves resource changes, not each generation. Sume's gate is per call: idempotency_key is transport and dedup, not human approval. Spend is wallet and admission, so add dry_run guidance to the agent's system prompt.
What should I check after applying?
Start a session and have the agent call mcp_health, which reports endpoint, auth source and safety posture. If it reports a read-only session, the credential is the problem, not the agent file.
Sources
Related posts
More in Developers
- Argil audio upload 50 MB vs Sume Fabric's 10 MB audio URL
Argil takes mp3, wav and m4a uploads up to 50 MB. Sume's Fabric route takes a Sume-hosted audio URL up to 10 MB; H3 Max lip sync wants 5-14.8 seconds.
- AssemblyAI Sync API: one call, and Sume STT sync mode
AssemblyAI's Sync API returns a short-clip transcript in one POST. Sume STT mode sync waits up to 30 seconds, then returns the job id to poll if not done.
- AssemblyAI Sync API file limit vs Sume STT duration_seconds
AssemblyAI's launch post frames its Sync API for short clips. Sume STT 1.0 takes duration_seconds from 1 to 600 and reserves one minute if you omit it.
- Avatar video captions error over 60 seconds: split the script
Inline captions on an avatar video are rejected when the estimated duration is over 60 seconds, the same cap as the job. Split long scripts into jobs.
Written by Sume