Claude Code routine connectors: leave Sume's Write off first
A new Claude Code routine includes every connector and can call write tools without asking. Grant Sume read-only first, then widen it on purpose.

A new Claude Code routine includes all of your connected connectors by default, and Claude can use every tool from an included connector, writes included, without asking during a run. If Sume is one of your claude.ai connectors, that means a routine can reach Sume's paid tools unless the connector itself was granted read-only. Sume's consent screen starts that way: Read is locked on and the Write toggle is off by default, so leave it off until a routine really needs to generate media.
Both sides are described in Anthropic's routines documentation and Sume's MCP OAuth and API keys page, read on 2026-10-03.
What does a routine do with connectors by default?
The routines page says routines run as full cloud sessions with no permission-mode picker. Under Connectors, all connected MCP connectors are included, and the page tells you to remove any the routine does not need, because Claude can use every tool from an included connector, including writes, without asking permission during a run.
The same page says routines belong to your individual account and that actions through connectors use your linked accounts. It describes removing a connector from a routine. It does not describe narrowing a connector's scopes per routine, so treat the scope you granted at consent as the ceiling for every routine that includes it.
What does Sume expose to a read-only session?
Sume's hosted MCP has two OAuth scopes: mcp:read, which is required, and mcp:write, which is opt-in. There is no mcp:paid scope. An mcp:read session sees only read-only tools, and a mutating or paid call returns insufficient_scope. An mcp:write session or an API key sees the full hosted tool set, and paid tools such as generate_image and generate_video then need an idempotency_key.
So a read-only grant is a real wall for a routine: it can list jobs, read balance and inspect the catalog, but it cannot start a paid generation.
| Sume grant | Tools visible | Paid call from a routine |
|---|---|---|
OAuth mcp:read only | Read-only tools | Rejected with insufficient_scope |
OAuth mcp:read + mcp:write | Full hosted set | Allowed, needs idempotency_key, no approval prompt |
| API key | Full hosted set | Allowed, same rules |
What should I do before the first run?
- Connect Sume with Write off and run the routine once. Call
mcp_healthandtools_listin the prompt and have the routine report what it can see. - Remove every connector the routine does not need, Sume included, if the job is only code review or triage.
- If the routine must generate media, ask for
dry_run=truefirst in its prompt and passmax_spend_usdon every paid call. Both are optional arguments the model writes, so they are habits in the prompt, not limits Anthropic enforces. - For a hard per-run ceiling, start a Sume Format or Agent Completion from the routine with
generation_spend_cap_usdinstead of giving it a write-enabled connector.
Where does this stop being enough?
Read-only protects against spend, not against reading. A connector with Read can still return private data into the session, so keep Sume's read tools out of routines that also fetch untrusted text. Sume's Safe automation page asks for the same separation: keep read-only operations apart from credit-spending ones, and never log keys or signed URLs.
Sources
Related posts
More in Agents
- Claude Code routine run is green: did the Sume video get made?
A green routine status means the session exited cleanly, not that the task worked. Read Sume's run receipt: status, outcome, output_error and billed amount.
- Claude Sonnet 4.5 retires Nov 30: what to move to on Sume
Anthropic deprecated claude-sonnet-4-5-20250929 on Sep 30, retiring it Nov 30, 2026 in favor of Sonnet 5.5. Sume's catalog has no Sonnet 4.5 row.
- Claude thinking blocks are model-bound: one model per thread
Sonnet 5.5 and Fable 5.1 thinking blocks only work for the model (and account) that made them. Why an agent thread should keep one model, and how to log it.
- Codex 0.160 Guardian review reads prior instructions: Sume args
Codex CLI 0.160 adds opt-in Guardian review that can fetch earlier user instructions. Write Sume calls so a reviewer can approve them from the arguments alone.
Written by Sume