Claude MCP connector allowlist: enable only Sume's read-only tools
Set the Claude MCP connector's default_config to disabled and enable named Sume tools. A read-only assistant list, plus the OAuth scope that backs it up.

To give Claude only a few Sume tools through the MCP connector, add an mcp_toolset entry to tools, set default_config to enabled: false, then list each tool you want under configs with enabled: true. That is the allowlist pattern in Anthropic's MCP connector documentation, read on 2026-10-04. The same page recommends denylisting write tools for read-only assistants, which is the other pattern.
What does the connector need from the server?
The page requires a public HTTPS server speaking Streamable HTTP or SSE, a beta header of mcp-client-2025-11-20, and an mcp_servers entry with type set to url, plus url, name and an optional authorization_token. The API consumer handles OAuth and refreshes the token. Sume's hosted endpoint is https://mcp.sume.com/mcp, so the URL is a match.
Which Sume tools make a read-only list?
Sume's MCP tools and gates page lists the discovery and health tools as tools_list, tools_schema and mcp_health, and the account and catalog group includes account_me, balance_get, usage_get and catalog_list. Job reads such as jobs_status and jobs_result are covered on the Jobs and results page. Confirm the final names with tools_list on your own session.
{
"type": "mcp_toolset",
"mcp_server_name": "sume",
"default_config": { "enabled": false },
"configs": {
"tools_list": { "enabled": true },
"usage_get": { "enabled": true },
"jobs_status": { "enabled": true },
"jobs_result": { "enabled": true }
}
}Is the allowlist enough?
It limits what the model is offered, but it is a client-side setting. The stronger guard is the credential. Under OAuth with only mcp:read, Sume hides write and paid tools and returns insufficient_scope if one is called, per the MCP OAuth and API keys page. An API key, by contrast, gives the full tool set.
So the safe pair for a read-only assistant is an OAuth token granted only mcp:read plus the allowlist above. The scope covers a mistake in the list, and the list covers a model that asks for tools you did not intend.
Which gates still apply to writes?
If you do enable a paid tool, every write and paid call needs an idempotency_key. A dry_run=true previews admission and cost, and max_spend_usd caps a call only when it is sent. There is no mcp:paid scope; spend is decided by wallet and admission. The legacy allow_paid and allow_write arguments are accepted but optional, and they cannot bypass a missing mcp:write scope.
How do I verify the list?
After you set the toolset, ask Claude to call tools_list through the connector and compare the tools it can see with your allowlist. The two should agree; any extra name means the allowlist did not apply, and a missing one means the credential hides it. Repeat the check whenever you change the grant. A read-only OAuth session lists fewer tools than an API key, so test with the exact credential you will ship rather than your own admin key.
Sources
Related posts
More in Integrations
- Claude MCP connector: allowlist read-only Sume tools by toolset
With the Messages API MCP connector an API-key Sume session exposes paid tools. Use an mcp_toolset with default_config enabled false and enable only job reads.
- Opus 5.5 computer toolset rejects strict: Sume tools do not need it
Anthropic's computer and browser toolsets reject strict mode. Sume media work runs through MCP tools and API calls, so a Claude agent needs neither toolset.
- Cloudflare Agents SDK with Pi: connect Sume's MCP tools
Cloudflare's Agents SDK now supports the Pi harness. Point the agent at https://mcp.sume.com/mcp and send an idempotency_key on every paid tool call.
- Cloudflare Web Search API beta and Sume crawl tools for research
Cloudflare's Web Search API beta targets agents. Sume's hosted MCP has its own read-only crawl tools. How to research references first, then generate.
Written by Sume