AgentCore SynchronizeGatewayTargets 202: refresh Sume's tool list

AgentCore Gateway caches an MCP target's tools in DEFAULT mode and refreshes on SynchronizeGatewayTargets. Why Sume's listChanged false means you must sync.

4 min readSume
All posts

If you add Sume's hosted MCP server as an Amazon Bedrock AgentCore Gateway target, the gateway keeps its own copy of the tool list, and nothing pushes changes to it. AWS's documentation, read on 2026-10-04, says the DEFAULT listing mode synchronizes through SynchronizeGatewayTargets, which returns 202 and can take minutes. Sume's server declares listChanged as false, so it never announces a change either. Refreshing is your job.

What does AWS say about the two listing modes?

The AgentCore Gateway MCP targets page describes DEFAULT, where the gateway caches tools and refreshes through synchronization, and DYNAMIC. The page says DYNAMIC is not interoperable with semantic search or with outbound three-legged OAuth.

Which mode fits Sume?

Mode facts from the AgentCore Gateway MCP targets page; Sume values from the OAuth docs and server code, read 2026-10-04.
Your setupModeReason
Sume with OAuth authorization codeDEFAULTDYNAMIC does not work with outbound 3LO
Sume with an API key, no semantic searcheitherno documented conflict
Gateway semantic search over Sume toolsDEFAULTDYNAMIC is not interoperable with it

When should I synchronize?

Sume's server has no change notification, so sync after anything that changes what your credential can see. Three cases matter. You changed the OAuth grant, for example adding mcp:write to a read-only grant, which un-hides write and paid tools. You swapped an OAuth credential for an API key, which exposes the full set. Or Sume shipped a tool, which you find by calling tools_list from a session. The MCP tools and gates page says to use tools_list and tools_schema for the live contract.

Because the call returns 202 and can take minutes, do not call a new tool the moment you sync. Check that the gateway lists it first.

What does a stale list look like?

A model asks for a tool the gateway no longer offers, or never sees one that exists. With a read-only OAuth grant, the list is shorter by design: write and paid tools are hidden, and a call to one that you somehow reach returns insufficient_scope. That is not staleness, so compare against tools_list from the same credential before you blame the cache.

Keep the gateway credential minimal. Register only the tools an agent needs, and remember that every paid create needs an idempotency_key. The MCP overview lists the groups.

What is a good routine?

Put synchronization in your deploy script, not in a runbook. After any change to the Sume credential or to the tool filter, trigger a sync, poll until the target is ready, then run a smoke test that calls tools_list through the gateway and compares it with a direct call from the same credential. If the two lists match, release; if not, wait and compare again rather than assuming a Sume change, because the gateway's copy can lag by minutes.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume