Claude managedMcpServers policy-only: set Sume tool permissions
Claude's transport policy-only sets tool permissions without declaring how to launch the server. How it applies to Sume's underscore tool names.

With managedMcpServers, an admin can set transport to policy-only to attach tool permissions to an MCP server without saying how Claude launches it. For Sume that means you can pre-approve read tools and require approval for paid ones even when users add the connector themselves.
The Claude Desktop changelog says managedMcpServers and orgPluginSettings apply to MCP servers from any installed plugin, and that permission rules work on tool names that contain dots or spaces.
Why policy-only fits a hosted server
A hosted server has no launch command to manage, only a URL and a sign-in. Policy-only separates the two concerns: the user connects, the admin governs which tools run without asking.
At a glance
| Item | Value | Source |
|---|---|---|
| Transport | policy-only | Claude Desktop changelog |
| Applies to | MCP servers from any installed plugin | Claude Desktop changelog |
| Sume discovery tools | tools_list, tools_schema, mcp_health, catalog_list | Sume MCP docs |
| Sume paid-call guard | idempotency_key required; max_spend_usd optional | Sume MCP docs |
Sume's tool names
Sume tool ids use underscores, such as tools_list, jobs_wait and script_run, and dotted aliases are canonicalized on the server. The dots-and-spaces fix in the changelog matters for other servers, but Sume's canonical ids are plain.
Sume read tools carry readOnlyHint true; write tools do not. Write and paid tools also require an idempotency_key argument, and OAuth sessions without mcp:write do not see them at all.
- Allow tools_list, tools_schema, mcp_health and catalog_list without prompts.
- Keep prompts on any tool that creates or spends.
- Pair the policy with a per-run max_spend_usd when agents call paid tools.
Limits and what is not verified
I did not verify the full JSON shape of a managedMcpServers entry; take it from Anthropic's admin docs. The changelog does not state how a permission rule is matched when a server is both policy-only and user-added.
Sources
Related posts
More in Integrations
- Claude Always allow for read-only MCP tools: Sume's tools
Claude Desktop 2.110 offers Always allow on read-only managed MCP tools unless mcpPersistentAlwaysAllowEnabled is false. What Sume marks read-only.
- Cloudflare K2 as a buffer in front of Sume bulk runs
K2 streams hold your video requests until a consumer submits them to Sume bulk runs. How to ack, nack and park rows so a redelivered batch never runs twice.
- Cloudflare MCP portal service tokens skip per-user OAuth servers
A Cloudflare service-token session cannot finish a per-user OAuth grant, so an OAuth upstream like Sume is left out. What to use for unattended agents.
- Cloudflare MCP portals GA: where Sume hosted MCP fits
Cloudflare MCP server portals went GA on 2026-09-24. What a portal changes for a remote server like Sume, and the three checks to run first.
Written by Sume