Cloudflare Web Search API beta and Sume crawl tools for research

Cloudflare's Web Search API beta targets agents. Sume's hosted MCP has its own read-only crawl tools. How to research references first, then generate.

4 min readSume
All posts

Use any search tool you like for the research step, and keep it separate from the generation step. The Cloudflare changelog lists a Web Search API beta for agents, and Sume's hosted MCP has its own read-only crawl tools, so an agent can gather references with one and spend credits with the other.

The split matters because research is cheap to repeat and generation is not. Sume's crawl read tools work under OAuth mcp:read; the paid generation tools do not.

What the changelog lists

Entries from the Oct 2 window.

Cloudflare changelog (read 2026-10-03)
ItemWhat the page says
Web Search APIBeta, for agents
Workers KV jurisdictionsGenerally available
Analytics30 days on every plan

Sume's crawl tools

The hosted inventory lists a crawl group for web and social research. Everything except site crawling is a read tool, which is visible to a read-only OAuth session; crawl_site is a write tool, unbilled, that you follow with jobs_wait and then crawl_get on the same id. The docs also name two skills for it: crawl-web for web research and crawl-social for social discovery.

Sume hosted crawl tools, from the tools and gates docs (read 2026-10-03)
ToolGateUse
crawl_scrapeReadFetch one page
crawl_mapReadList the pages of a site
crawl_searchReadSearch the web
crawl_profile, crawl_feed, crawl_media, crawl_findReadSocial discovery
crawl_siteWrite, idempotency_keyCrawl a site as a job; unbilled utility
crawl_getReadRead a crawl result

A research-then-generate loop

Keep the stages explicit so a failure in one does not repeat the other.

  • Research: collect a handful of reference pages or images with the search tool of your choice, or with crawl_search and crawl_scrape.
  • Brief: have the agent write a short brief that names the references it used. Store it.
  • Preview: call the generation tool with dry_run=true, or generation_admission_preview, and report the estimate.
  • Generate: after confirmation, call it with a fresh idempotency_key, then wait on the job ids.

Where references can come from

Hosted MCP cannot read files from your laptop. If a reference is a local file, the upload flow is to create an upload URL, have the client PUT the bytes, and then call assets_complete. For a social video link, the docs point to media-imports_create as the social URL mirror.

Whichever source you use, check you have the right to use the reference for the work you plan, and keep a note of where each one came from. The agent should cite its references in the brief, not paraphrase them from memory.

Do not mix the credentials

A web search API key is a different credential from a Sume key or OAuth token, and none of them belong in a prompt. An OAuth token is not a Sume API key; do not forward it to a third party, including a search provider.

If you run the loop unattended, use an API key held as a secret on the server, and keep max_spend_usd on every paid call so a bad brief cannot run up a bill.

What the beta status means

The changelog calls the search API a beta. Treat its interface as something that may change, wrap it behind one function in your agent, and keep the brief format independent of it. Then swapping the research tool, whether for a Sume crawl tool or another provider, does not change the generation step.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume