Claude managedMcpServers policy-only: set Sume tool permissions

Claude's transport policy-only sets tool permissions without declaring how to launch the server. How it applies to Sume's underscore tool names.

5 min readSume
All posts

With managedMcpServers, an admin can set transport to policy-only to attach tool permissions to an MCP server without saying how Claude launches it. For Sume that means you can pre-approve read tools and require approval for paid ones even when users add the connector themselves.

The Claude Desktop changelog says managedMcpServers and orgPluginSettings apply to MCP servers from any installed plugin, and that permission rules work on tool names that contain dots or spaces.

Why policy-only fits a hosted server

A hosted server has no launch command to manage, only a URL and a sign-in. Policy-only separates the two concerns: the user connects, the admin governs which tools run without asking.

At a glance

Policy-only fields used for Sume, read 2026-10-03.
ItemValueSource
Transportpolicy-onlyClaude Desktop changelog
Applies toMCP servers from any installed pluginClaude Desktop changelog
Sume discovery toolstools_list, tools_schema, mcp_health, catalog_listSume MCP docs
Sume paid-call guardidempotency_key required; max_spend_usd optionalSume MCP docs

Sume's tool names

Sume tool ids use underscores, such as tools_list, jobs_wait and script_run, and dotted aliases are canonicalized on the server. The dots-and-spaces fix in the changelog matters for other servers, but Sume's canonical ids are plain.

Sume read tools carry readOnlyHint true; write tools do not. Write and paid tools also require an idempotency_key argument, and OAuth sessions without mcp:write do not see them at all.

  • Allow tools_list, tools_schema, mcp_health and catalog_list without prompts.
  • Keep prompts on any tool that creates or spends.
  • Pair the policy with a per-run max_spend_usd when agents call paid tools.

Limits and what is not verified

I did not verify the full JSON shape of a managedMcpServers entry; take it from Anthropic's admin docs. The changelog does not state how a permission rule is matched when a server is both policy-only and user-added.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume