Claude Agent SDK allowedTools mcp__sume__* also allows paid Sume tools
A wildcard in allowedTools approves every tool the Sume server exposes. With an API key that includes paid ones. Name the read tools instead.

Yes, mcp__sume__* would approve every tool on that server, paid ones included, when the session carries a Sume API key. The Claude Agent SDK docs say wildcards in allowedTools let you allow all tools from a server without listing each one (read 2026-10-05). Sume's docs say an API key sees the full hosted tool set. Put the two together and the model can call generate_video without a permission prompt.
How the naming works
The SDK names MCP tools mcp__<server-name>__<tool-name>, so a server you register as sume exposes mcp__sume__tools_list, mcp__sume__balance_get and so on (read 2026-10-05). allowedTools auto-approves what you list. MCP tools that you do not list need permission before Claude can use them.
The same page says to prefer allowedTools over permission modes for MCP access, because bypassPermissions approves MCP tools but also disables most other safety prompts.
| Pattern | Effect | Fit for Sume |
|---|---|---|
| mcp__sume__* | All tools of the server | Only with an OAuth mcp:read session |
| mcp__sume__balance_get | One named tool | Good: spends nothing |
| mcp__sume__jobs_status | One named tool | Good: read |
| mcp__sume__generate_video | One named paid tool | Only with a human or a cap in the loop |
Name the read tools
The Python options below approve three read tools and leave paid tools to the permission flow. It needs the claude-agent-sdk package and an API key in the environment.
import asyncio, os
from claude_agent_sdk import query, ClaudeAgentOptions, ResultMessage
async def main() -> None:
options = ClaudeAgentOptions(
mcp_servers={"sume": {
"type": "http",
"url": "https://mcp.sume.com/mcp",
"headers": {"Authorization":
"Bearer " + os.environ["SUME_API_KEY"]},
}},
allowed_tools=["mcp__sume__tools_list",
"mcp__sume__balance_get",
"mcp__sume__jobs_status"],
)
async for msg in query(prompt="Show my Sume balance.",
options=options):
if isinstance(msg, ResultMessage) and msg.subtype == "success":
print(msg.result)
asyncio.run(main())When a wildcard is fine
If the session uses OAuth with only mcp:read, Sume hides paid and write tools, and a call to one returns insufficient_scope. In that case the wildcard grants read tools only. The risk comes from combining a wildcard with an API key or an OAuth session that was given mcp:write.
The safest pattern pairs both layers: a named allow list in the SDK, and the least scope on the Sume side.
Tool search and large tool sets
Sume's hosted server exposes dozens of tools across generation, avatars, crawl and timeline. The SDK page covers tool search for large tool sets, which defers loading until Claude needs a tool (read 2026-10-05). Deferral does not change permission: a tool Claude finds through search still needs to be approved by allowedTools or by a prompt.
So a short named list helps twice. It keeps the permission surface small, and it keeps the model's choices focused on the tools your task needs.
Review list
Before you deploy a Claude Agent SDK worker that talks to Sume, check these.
- No wildcard on a server that carries a key with paid tools.
- Paid tools are approved only in a flow that sets
max_spend_usdor a human step. - Server name in code matches the prefix in
allowedTools. - The key is read from the environment, never from the prompt.
Sources
Related posts
More in Developers
- claude -p total_cost_usd vs your Sume bill: which number to trust
claude -p prints total_cost_usd for the Claude side of a run. Sume's generation spend is billed on Sume and read from GET /v1/usage. Here is how to log both.
- Sonnet 5.5 token bill vs Sume spend cap: two meters on one agent run
Sonnet 5.5 tokens bill at the model vendor. Sume generation bills in the Sume wallet. A worked example shows why one cap cannot cover both.
- Cloudflare Worker for a social video pipeline: SDK verifyWebhook
@sume-com/sdk 0.2.0 needs only fetch and WebCrypto, so verifyWebhook runs in a Cloudflare Worker. Verify the raw body, then answer 2xx before you post.
- Cloudflare Worker that verifies a Sume video webhook (verifyWebhook)
A 20-line Cloudflare Worker for Sume job webhooks: verifyWebhook from @sume-com/sdk on WebCrypto, empty-secret guard, 204 fast ack. Why the check is async.
Written by Sume