Claude MCP connector allowlist: enable only Sume's read-only tools

Set the Claude MCP connector's default_config to disabled and enable named Sume tools. A read-only assistant list, plus the OAuth scope that backs it up.

4 min readSume
All posts

To give Claude only a few Sume tools through the MCP connector, add an mcp_toolset entry to tools, set default_config to enabled: false, then list each tool you want under configs with enabled: true. That is the allowlist pattern in Anthropic's MCP connector documentation, read on 2026-10-04. The same page recommends denylisting write tools for read-only assistants, which is the other pattern.

What does the connector need from the server?

The page requires a public HTTPS server speaking Streamable HTTP or SSE, a beta header of mcp-client-2025-11-20, and an mcp_servers entry with type set to url, plus url, name and an optional authorization_token. The API consumer handles OAuth and refreshes the token. Sume's hosted endpoint is https://mcp.sume.com/mcp, so the URL is a match.

Which Sume tools make a read-only list?

Sume's MCP tools and gates page lists the discovery and health tools as tools_list, tools_schema and mcp_health, and the account and catalog group includes account_me, balance_get, usage_get and catalog_list. Job reads such as jobs_status and jobs_result are covered on the Jobs and results page. Confirm the final names with tools_list on your own session.

{
  "type": "mcp_toolset",
  "mcp_server_name": "sume",
  "default_config": { "enabled": false },
  "configs": {
    "tools_list": { "enabled": true },
    "usage_get": { "enabled": true },
    "jobs_status": { "enabled": true },
    "jobs_result": { "enabled": true }
  }
}

Is the allowlist enough?

It limits what the model is offered, but it is a client-side setting. The stronger guard is the credential. Under OAuth with only mcp:read, Sume hides write and paid tools and returns insufficient_scope if one is called, per the MCP OAuth and API keys page. An API key, by contrast, gives the full tool set.

So the safe pair for a read-only assistant is an OAuth token granted only mcp:read plus the allowlist above. The scope covers a mistake in the list, and the list covers a model that asks for tools you did not intend.

Which gates still apply to writes?

If you do enable a paid tool, every write and paid call needs an idempotency_key. A dry_run=true previews admission and cost, and max_spend_usd caps a call only when it is sent. There is no mcp:paid scope; spend is decided by wallet and admission. The legacy allow_paid and allow_write arguments are accepted but optional, and they cannot bypass a missing mcp:write scope.

How do I verify the list?

After you set the toolset, ask Claude to call tools_list through the connector and compare the tools it can see with your allowlist. The two should agree; any extra name means the allowlist did not apply, and a missing one means the credential hides it. Repeat the check whenever you change the grant. A read-only OAuth session lists fewer tools than an API key, so test with the exact credential you will ship rather than your own admin key.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume