Codex config.toml enabled_tools and required for Sume's read tools

Codex's MCP config can allowlist tools with enabled_tools and fail startup with required. Give a task only Sume's read and wait tools and a longer timeout.

5 min readSume
All posts

Codex's MCP settings go beyond a URL. The Codex MCP configuration page lists startup_timeout_sec (default 10), tool_timeout_sec (default 60), required, enabled_tools, disabled_tools, default_tools_approval_mode, bearer_token_env_var, http_headers, env_http_headers, http_headers_helper and auth, read 2026-10-03. Those are enough to give a Codex task a deliberately small slice of Sume's hosted MCP server.

Allowlist the read side

The Sume tools and gates page lists jobs_wait, jobs_result, assets_*, balance_get, usage_get, mcp_health and tools_list among its tools. A task that only monitors work needs the read ones. With enabled_tools, Codex exposes just those. The bearer_token_env_var key reads the credential from the environment, so the file holds no secret. The jobs_wait hold is 55 seconds at most, so the 60-second default tool_timeout_sec is thin; raise it.

Using enabled_tools is a Codex-side filter. Sume still enforces idempotency_key on paid and write tools, and under OAuth a write tool with only mcp:read returns insufficient_scope.

[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
bearer_token_env_var = "SUME_API_KEY"
startup_timeout_sec = 20
tool_timeout_sec = 90
required = true
enabled_tools = ["jobs_wait", "jobs_result", "balance_get", "tools_list"]

What required does

The page lists required as a key but this post does not describe its exact failure behaviour beyond the name; test it before relying on it in automation.

Codex MCP settings used above, read 2026-10-03.
KeyDefaultWhy for Sume
startup_timeout_sec10A remote server can need longer on first connect
tool_timeout_sec60Above the 55-second jobs_wait cap
requiredNot setFail startup instead of running without Sume
enabled_toolsAllExpose only read and wait tools
bearer_token_env_varNoneKeep the key out of the file

OAuth and recent releases

The Codex changelog shows releases 0.158.0 to 0.160.0 between 2026-09-28 and 2026-10-01. Release 0.158.0 added codex mcp add --oauth-client-secret. The configuration page documents codex mcp login <server> with --oauth-client-registration cimd|dcr, plus mcp_oauth_callback_port and mcp_oauth_callback_url. Sume's docs do not say which client registration modes the server supports, so use an API key unless you have confirmed OAuth for your setup.

  • Allowlist read tools for monitoring tasks.
  • Raise tool_timeout_sec above 55.
  • Never resubmit a paid create after a timeout.
  • Keep the key in an environment variable.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume