CLAUDE_CODE_DISABLE_WEB_FETCH: what Sume crawl tools do
CLAUDE_CODE_DISABLE_WEB_FETCH turns off Claude Code's WebFetch tool. Sume's crawl_* tools come from an MCP server, so they are a separate path.

CLAUDE_CODE_DISABLE_WEB_FETCH is an environment variable that turns off Claude Code's WebFetch tool. It was added in v2.1.285. It names one built-in tool, so Sume's crawl_scrape, crawl_map, crawl_search and crawl_get, which arrive through the hosted MCP server, are not part of it.
The release note is from the Claude Code releases page. The Sume claims are from MCP tools and gates, read 2026-09-30. The release note does not say how the variable interacts with MCP tools, so test that in your own setup.
Which Sume tools fetch web pages?
The docs group the crawl tools as read tools, plus one write tool.
| Kind | Tools |
|---|---|
| Read | crawl_scrape, crawl_map, crawl_search, crawl_get, crawl_profile, crawl_feed, crawl_media, crawl_find |
Write (needs idempotency_key, unbilled utility) | crawl_site, then jobs_wait and crawl_get on the same id |
Do they work with a read-only connection?
Yes for the read tools. Under the default OAuth scope mcp:read, the quickstart lists crawl_scrape among the tools that work, and the OAuth page says mcp:read sessions only see read-only tools. crawl_site is a write tool, so it needs mcp:write or an API key.
How do I add the server to Claude Code?
Run claude mcp add --transport http sume https://mcp.sume.com/mcp, then claude mcp login sume. Permission rules for the resulting tools are covered in allowing MCP tools.
Does disabling WebFetch make crawling stricter?
Not by itself. If your goal is a policy that no tool reaches the web, disabling WebFetch is one step, and you would also review every connected MCP server. Which tools your sessions can call is decided by the scopes and permission rules above.
Sources
Related posts
More in Developers
- Claude Code MCP connection timeout: startup wait vs a Sume call
Claude Code 2.1.284 waits up to 10 s for a connecting MCP server on resumed calls and 2 s on a non-interactive first turn. Sume tool calls hold at most 55 s.
- Claude Code MCP error showed a Bearer token: rotate the Sume key
If an MCP error or log exposed a Sume Bearer value, rotate the API key. An OAuth token is not an API key. Report issues with the request id, not the key.
- Claude Code list_changed and reconnect: refresh Sume tools
Claude Code refreshes an MCP server's tools on list_changed and lets you reconnect from /mcp. After changing Sume's Write consent, verify with tools_list.
- Claude Code reserved MCP server name: widgets, and Sume's name
Claude Code 2.1.285 reserves the MCP server name widgets in cloud sessions and on self-hosted runners. Sume's documented name is sume, so nothing to rename.
Written by Sume