Claude Agent SDK allowedTools mcp__sume__* also allows paid Sume tools

A wildcard in allowedTools approves every tool the Sume server exposes. With an API key that includes paid ones. Name the read tools instead.

5 min readSume
All posts

Yes, mcp__sume__* would approve every tool on that server, paid ones included, when the session carries a Sume API key. The Claude Agent SDK docs say wildcards in allowedTools let you allow all tools from a server without listing each one (read 2026-10-05). Sume's docs say an API key sees the full hosted tool set. Put the two together and the model can call generate_video without a permission prompt.

How the naming works

The SDK names MCP tools mcp__<server-name>__<tool-name>, so a server you register as sume exposes mcp__sume__tools_list, mcp__sume__balance_get and so on (read 2026-10-05). allowedTools auto-approves what you list. MCP tools that you do not list need permission before Claude can use them.

The same page says to prefer allowedTools over permission modes for MCP access, because bypassPermissions approves MCP tools but also disables most other safety prompts.

allowedTools patterns for the Sume server, read 2026-10-05
PatternEffectFit for Sume
mcp__sume__*All tools of the serverOnly with an OAuth mcp:read session
mcp__sume__balance_getOne named toolGood: spends nothing
mcp__sume__jobs_statusOne named toolGood: read
mcp__sume__generate_videoOne named paid toolOnly with a human or a cap in the loop

Name the read tools

The Python options below approve three read tools and leave paid tools to the permission flow. It needs the claude-agent-sdk package and an API key in the environment.

import asyncio, os
from claude_agent_sdk import query, ClaudeAgentOptions, ResultMessage

async def main() -> None:
    options = ClaudeAgentOptions(
        mcp_servers={"sume": {
            "type": "http",
            "url": "https://mcp.sume.com/mcp",
            "headers": {"Authorization":
                        "Bearer " + os.environ["SUME_API_KEY"]},
        }},
        allowed_tools=["mcp__sume__tools_list",
                       "mcp__sume__balance_get",
                       "mcp__sume__jobs_status"],
    )
    async for msg in query(prompt="Show my Sume balance.",
                           options=options):
        if isinstance(msg, ResultMessage) and msg.subtype == "success":
            print(msg.result)

asyncio.run(main())

When a wildcard is fine

If the session uses OAuth with only mcp:read, Sume hides paid and write tools, and a call to one returns insufficient_scope. In that case the wildcard grants read tools only. The risk comes from combining a wildcard with an API key or an OAuth session that was given mcp:write.

The safest pattern pairs both layers: a named allow list in the SDK, and the least scope on the Sume side.

Tool search and large tool sets

Sume's hosted server exposes dozens of tools across generation, avatars, crawl and timeline. The SDK page covers tool search for large tool sets, which defers loading until Claude needs a tool (read 2026-10-05). Deferral does not change permission: a tool Claude finds through search still needs to be approved by allowedTools or by a prompt.

So a short named list helps twice. It keeps the permission surface small, and it keeps the model's choices focused on the tools your task needs.

Review list

Before you deploy a Claude Agent SDK worker that talks to Sume, check these.

  • No wildcard on a server that carries a key with paid tools.
  • Paid tools are approved only in a flow that sets max_spend_usd or a human step.
  • Server name in code matches the prefix in allowedTools.
  • The key is read from the environment, never from the prompt.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume