Claude Code routine connectors: leave Sume's Write off first

A new Claude Code routine includes every connector and can call write tools without asking. Grant Sume read-only first, then widen it on purpose.

5 min readSume
All posts

A new Claude Code routine includes all of your connected connectors by default, and Claude can use every tool from an included connector, writes included, without asking during a run. If Sume is one of your claude.ai connectors, that means a routine can reach Sume's paid tools unless the connector itself was granted read-only. Sume's consent screen starts that way: Read is locked on and the Write toggle is off by default, so leave it off until a routine really needs to generate media.

Both sides are described in Anthropic's routines documentation and Sume's MCP OAuth and API keys page, read on 2026-10-03.

What does a routine do with connectors by default?

The routines page says routines run as full cloud sessions with no permission-mode picker. Under Connectors, all connected MCP connectors are included, and the page tells you to remove any the routine does not need, because Claude can use every tool from an included connector, including writes, without asking permission during a run.

The same page says routines belong to your individual account and that actions through connectors use your linked accounts. It describes removing a connector from a routine. It does not describe narrowing a connector's scopes per routine, so treat the scope you granted at consent as the ceiling for every routine that includes it.

What does Sume expose to a read-only session?

Sume's hosted MCP has two OAuth scopes: mcp:read, which is required, and mcp:write, which is opt-in. There is no mcp:paid scope. An mcp:read session sees only read-only tools, and a mutating or paid call returns insufficient_scope. An mcp:write session or an API key sees the full hosted tool set, and paid tools such as generate_image and generate_video then need an idempotency_key.

So a read-only grant is a real wall for a routine: it can list jobs, read balance and inspect the catalog, but it cannot start a paid generation.

What a routine can do with Sume, by grant (read 2026-10-03)
Sume grantTools visiblePaid call from a routine
OAuth mcp:read onlyRead-only toolsRejected with insufficient_scope
OAuth mcp:read + mcp:writeFull hosted setAllowed, needs idempotency_key, no approval prompt
API keyFull hosted setAllowed, same rules

What should I do before the first run?

  • Connect Sume with Write off and run the routine once. Call mcp_health and tools_list in the prompt and have the routine report what it can see.
  • Remove every connector the routine does not need, Sume included, if the job is only code review or triage.
  • If the routine must generate media, ask for dry_run=true first in its prompt and pass max_spend_usd on every paid call. Both are optional arguments the model writes, so they are habits in the prompt, not limits Anthropic enforces.
  • For a hard per-run ceiling, start a Sume Format or Agent Completion from the routine with generation_spend_cap_usd instead of giving it a write-enabled connector.

Where does this stop being enough?

Read-only protects against spend, not against reading. A connector with Read can still return private data into the session, so keep Sume's read tools out of routines that also fetch untrusted text. Sume's Safe automation page asks for the same separation: keep read-only operations apart from credit-spending ones, and never log keys or signed URLs.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume