Claude Always allow for read-only MCP tools: Sume's tools
Claude Desktop 2.110 offers Always allow on read-only managed MCP tools unless mcpPersistentAlwaysAllowEnabled is false. What Sume marks read-only.

Claude Desktop v2.110.0 and v1.46388.0 now offer an Always allow choice for read-only tools from managed and built-in MCP servers, unless an admin sets mcpPersistentAlwaysAllowEnabled to false. On Sume, only tools marked read-only can ever reach that choice.
Sume's read tools set readOnlyHint true, idempotentHint true, destructiveHint false and openWorldHint false. Its write tools set readOnlyHint false, so they keep prompting.
What the setting changes
Before, a user might approve the same lookup repeatedly. Now the prompt can include a persistent allow for the read-only ones. An admin who does not want persistent decisions turns the flag off.
At a glance
| Tool type | readOnlyHint | Persistent allow offered |
|---|---|---|
| Read tools (for example tools_list) | true | Yes, if the setting is on |
| Write and paid tools | false | No, per the changelog's read-only condition |
| Admin flag mcpPersistentAlwaysAllowEnabled | n/a | False disables the option |
What counts as read-only on Sume
The classification comes from the tool annotations the server sends, not from the tool name. Sume's discovery and listing tools are read tools. Anything that mutates or spends is a write tool, needs the mcp:write scope, and requires an idempotency_key.
That makes Always allow low-risk for tools_list and similar calls, while a paid create still asks.
- Set mcpPersistentAlwaysAllowEnabled to false for strict review environments.
- Leave it on if you want fewer prompts for lookups.
- Never rely on Always allow for spend control; use max_spend_usd and spend caps.
Limits and what is not verified
The changelog does not say how Claude treats a tool with no annotations, and I did not test the prompt flow against Sume. The annotation values come from Sume's server source, and the offer rule comes from the changelog.
Sources
Related posts
More in Integrations
- Cloudflare K2 as a buffer in front of Sume bulk runs
K2 streams hold your video requests until a consumer submits them to Sume bulk runs. How to ack, nack and park rows so a redelivered batch never runs twice.
- Cloudflare MCP portal service tokens skip per-user OAuth servers
A Cloudflare service-token session cannot finish a per-user OAuth grant, so an OAuth upstream like Sume is left out. What to use for unattended agents.
- Cloudflare MCP portals GA: where Sume hosted MCP fits
Cloudflare MCP server portals went GA on 2026-09-24. What a portal changes for a remote server like Sume, and the three checks to run first.
- Cloudflare private MCP servers vs Sume public MCP endpoint
Cloudflare portals can now reach MCP servers on a private network. Sume's hosted MCP is a public HTTPS endpoint, so here is what changes and what does not.
Written by Sume