Claude Research with a Sume connector: turn off write tools first
Anthropic advises disabling write-action tools when a custom connector is used with Research. For Sume that means read-only OAuth, no paid tools.

If you use Claude's Research feature with a Sume connector, connect Sume with read-only OAuth and leave the generation tools off. Anthropic's help article on custom connectors recommends disabling write-action tools when using Research, because a connector can create, modify or delete data; on Sume's side, that advice is already the default, since an OAuth session with only mcp:read cannot see the tools that spend money.
The Anthropic guidance comes from Get started with custom connectors using remote MCP, read on 2026-10-11. The article does not describe how Research chooses tools, so I make no claim about that; the useful point is what Sume exposes at each scope. Sume's facts are from its OAuth and API keys, quickstart and tools and gates pages.
What does Anthropic actually say?
The article says custom connectors can create, modify or delete data, and recommends disabling write-action tools when using Research features. It does not split tools into read-only and write modes in the text I read, so there is no switch in the article that does this for you. The practical lever is the server's own permission model.
The article also lists the authentication choices: OAuth (Claude's identity, automatic registration or a custom OAuth client), fixed credentials through request headers, or no sign-in. Choosing the header route for Sume would mean a Sume API key, which sees the full tool set, so it is the wrong choice for a Research session.
What can Research reach at each Sume scope?
Sume's docs describe an API key as the full hosted tool set, and read-only as an OAuth grant, so the sign-in route you pick decides the exposure.
| Sign-in route | Tools visible | Paid or write call result |
|---|---|---|
| OAuth, Write off (default) | Read-only tools, such as jobs_list, assets_get, catalog_list and crawl_scrape | insufficient_scope |
| OAuth, Write on | Full hosted set | Needs idempotency_key; wallet and admission gate spend |
| API key in a header | Full hosted set | Needs idempotency_key; wallet and admission gate spend |
What is Research useful for with a read-only Sume?
Quite a lot. Sume's read tools include the web and social family: crawl_scrape, crawl_map, crawl_search, crawl_profile, crawl_feed, crawl_media and crawl_find. The quickstart names crawl_scrape among the read tools that work under mcp:read. A Research run can gather pages and public profile data, and read your jobs and assets with jobs_list, jobs_result and assets_get, without any path to spend.
One exception to check: crawl_site is listed as a write tool, unbilled, that needs an idempotency_key, so it will not appear in a read-only session. That is correct behavior, not a fault. Use crawl_scrape and crawl_map for single pages and site structure instead.
How do I confirm the session is really read-only?
Ask Claude to call mcp_health and report the auth source, then call tools_list. Sume's playbook says to expect mcp_oauth as the auth source, and that with Write off only the read-only tools are listed. If generate_image appears, the session has write access, and you should reconnect before running Research.
Treat links in results with care. Tool output can include signed URLs, and Sume's tool descriptions tell agents not to paste signed upload or download URLs into reports. A Research summary that quotes the public media.sume.com URL of a finished clip is fine; one that quotes a short-lived download link is not.
Sources
Related posts
More in Integrations
- Connect Sume to Zapier MCP Client: Run Tool vs Read-Only Tool
Add https://mcp.sume.com/mcp as a Zapier MCP Client connection: pick Streamable HTTP, bearer key or OAuth, and use the read-only search for job status.
- Continue: add Sume hosted MCP, agent mode only, timeout above 55 s
Continue runs MCP tools in agent mode only. Add Sume's hosted MCP as a streamable-http YAML file, send a key header, and raise requestOptions timeout past 55 s.
- Copilot CLI with a local Ollama model: do Sume MCP tools still work?
Copilot CLI can now discover Ollama models, but a local model is not offline mode. What that means for Sume's remote MCP tools, spend gates and tool calling.
- gemini mcp add for Sume: transport, header, timeout, include-tools
One gemini mcp add command registers Sume's hosted MCP over HTTP with a key header, a timeout above 55 seconds, and an include-tools list for read-only use.
Written by Sume