Claude MCP connector: allowlist read-only Sume tools by toolset

With the Messages API MCP connector an API-key Sume session exposes paid tools. Use an mcp_toolset with default_config enabled false and enable only job reads.

6 min readSume
All posts

When you reach Sume through Claude's Messages API MCP connector with an API key, the session sees the full tool set, paid tools included. Put an mcp_toolset in tools with default_config: {"enabled": false} and enable only the read tools you want, such as jobs_status, jobs_result and jobs_wait. Then a prompt mistake cannot reach generate_video, because Claude was never given it.

How the connector is shaped

Per Anthropic's connector page, you list servers in mcp_servers (type url, an https URL, a unique name, and an optional authorization_token) and configure them in a separate mcp_toolset entry in tools. Each server must be referenced by exactly one toolset, and a toolset must name a server that exists. The page marks the feature beta, with beta header mcp-client-2025-11-20, and lists zero data retention as not eligible. The same page describes a newer mcp-client-2026-09-15 header that pins a server's tool list and includes everything the older header does; send one header or the other, whichever your SDK uses.

Why Sume needs the allowlist

Per OAuth and API keys, an API-key session sees write and paid tools, while an OAuth session with only mcp:read sees read-only tools. The connector's authorization_token field is documented as an OAuth token. Sume accepts a bearer API key, but that makes your allowlist the only barrier between the model and paid tools, so put it in the request, not in the prompt.

Session type and what the model could call (read 2026-10-04)
CredentialSume tools visibleYour guard
OAuth mcp:read onlyRead-only toolsScope, enforced by Sume
OAuth mcp:read + mcp:writeFull hosted setToolset allowlist, dry_run
API keyFull hosted setToolset allowlist, dry_run

The toolset

Read-only means a short list. Names come from MCP tools and gates; confirm yours with tools_list.

{
  "type": "mcp_toolset",
  "mcp_server_name": "sume",
  "default_config": {"enabled": false},
  "configs": {
    "jobs_status": {"enabled": true},
    "jobs_result": {"enabled": true},
    "jobs_wait": {"enabled": true},
    "balance_get": {"enabled": true}
  }
}

Details that bite

  • Anthropic says an unknown tool name in configs only logs a backend warning, so a typo silently leaves that tool disabled. Check the response's tool list.
  • Sonnet 5.5 pricing is $2 input and $10 output per million tokens, with cache reads at $0.20, per the Sonnet 5.5 announcement. A long tool list costs input tokens every turn, which is another reason to enable few tools.
  • jobs_wait holds up to 55 seconds per call, so one connector turn can run close to a minute. Poll in slices rather than expecting a render to finish in one call; see Jobs and results.
  • The allowlist guards reads; to submit work, add the paid tool in a separate, deliberate request with an idempotency_key.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume