Codex config.toml enabled_tools and required for Sume's read tools
Codex's MCP config can allowlist tools with enabled_tools and fail startup with required. Give a task only Sume's read and wait tools and a longer timeout.

Codex's MCP settings go beyond a URL. The Codex MCP configuration page lists startup_timeout_sec (default 10), tool_timeout_sec (default 60), required, enabled_tools, disabled_tools, default_tools_approval_mode, bearer_token_env_var, http_headers, env_http_headers, http_headers_helper and auth, read 2026-10-03. Those are enough to give a Codex task a deliberately small slice of Sume's hosted MCP server.
Allowlist the read side
The Sume tools and gates page lists jobs_wait, jobs_result, assets_*, balance_get, usage_get, mcp_health and tools_list among its tools. A task that only monitors work needs the read ones. With enabled_tools, Codex exposes just those. The bearer_token_env_var key reads the credential from the environment, so the file holds no secret. The jobs_wait hold is 55 seconds at most, so the 60-second default tool_timeout_sec is thin; raise it.
Using enabled_tools is a Codex-side filter. Sume still enforces idempotency_key on paid and write tools, and under OAuth a write tool with only mcp:read returns insufficient_scope.
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
bearer_token_env_var = "SUME_API_KEY"
startup_timeout_sec = 20
tool_timeout_sec = 90
required = true
enabled_tools = ["jobs_wait", "jobs_result", "balance_get", "tools_list"]What required does
The page lists required as a key but this post does not describe its exact failure behaviour beyond the name; test it before relying on it in automation.
| Key | Default | Why for Sume |
|---|---|---|
startup_timeout_sec | 10 | A remote server can need longer on first connect |
tool_timeout_sec | 60 | Above the 55-second jobs_wait cap |
required | Not set | Fail startup instead of running without Sume |
enabled_tools | All | Expose only read and wait tools |
bearer_token_env_var | None | Keep the key out of the file |
OAuth and recent releases
The Codex changelog shows releases 0.158.0 to 0.160.0 between 2026-09-28 and 2026-10-01. Release 0.158.0 added codex mcp add --oauth-client-secret. The configuration page documents codex mcp login <server> with --oauth-client-registration cimd|dcr, plus mcp_oauth_callback_port and mcp_oauth_callback_url. Sume's docs do not say which client registration modes the server supports, so use an API key unless you have confirmed OAuth for your setup.
- Allowlist read tools for monitoring tasks.
- Raise
tool_timeout_secabove 55. - Never resubmit a paid create after a timeout.
- Keep the key in an environment variable.
Sources
Related posts
More in Agents
- Can I create a Sume scheduled agent by API? Read and run, not create
The Sume API can list, read, run and monitor scheduled agents, but not create, edit or delete them. Authoring is the dashboard or the Agent chat.
- Fire a cron schedule on demand: api_trigger_enabled, cron kept
A Sume cron schedule can also accept API runs. Turn on api_trigger_enabled and your service can start it now without touching the cadence.
- Hermes Agent cron job that starts a Sume Format run
A Hermes cron job begins with no memory of last week. Write the prompt, idempotency key, spend cap and SILENT or CRON_FAILURE reply so a Sume run starts once.
- Hermes cron no-agent script: poll a Sume bulk queue quietly
A Hermes cron script that prints nothing while a Sume bulk queue runs and one line when every item is terminal. Includes the Python, 404 and 429 cases.
Written by Sume