Codex default_tools_approval_mode = writes for Sume MCP
Codex sets approval per MCP server and per tool. Which of auto, prompt, writes and approve suits Sume's read and paid tools, and what output_token_limit does.

For Sume's hosted MCP in Codex, set default_tools_approval_mode = "writes" for the server, so Codex prompts for tools that are not marked read-only, and override a paid tool by name with tools.<tool>.approval_mode if you want it to prompt every time. Use approve or auto only for a server that has nothing paid on it.
The Codex MCP page (read 2026-10-10, reached through a redirect from developers.openai.com/codex/mcp) lists four values: auto, prompt, writes and approve. It describes writes as prompting for tools that aren't marked read-only. It describes prompt as asking for confirmation before running tools, and auto as running tools without prompting.
What the four modes mean for Sume
Sume marks its tools with safety metadata, and tools_list returns it. MCP tools and gates says the list shows all tools the session can see and their safety metadata. That is the signal a writes mode can use, and it also means you should confirm, with one tools_list call, that the paid tools are not flagged read-only before you rely on the mode.
| Mode | Codex behavior per its docs | Fit for Sume |
|---|---|---|
auto | Runs tools without prompting | Only with an OAuth Read-only grant |
prompt | Asks before running tools | Safe for everything, noisy for reads |
writes | Prompts for tools not marked read-only | Best default for an API-key or Write session |
approve | Tools are automatically approved | Avoid for paid tools |
Config you can paste
The page names the keys: url, bearer_token_env_var, http_headers, env_http_headers, http_headers_helper, enabled_tools, disabled_tools, default_tools_approval_mode, tools.<tool>.approval_mode, tools.<tool>.output_token_limit, startup_timeout_sec, tool_timeout_sec, enabled and required. Sume's key goes in an environment variable named by bearer_token_env_var, so the file holds no secret.
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
bearer_token_env_var = "SUME_API_KEY"
default_tools_approval_mode = "writes"
tool_timeout_sec = 120
[mcp_servers.sume.tools.generate_video]
approval_mode = "prompt"Output limits and long waits
output_token_limit is a positive token budget for one tool's output, applied before a standard 20% serialization allowance, and it supersedes the model's usual truncation for that tool. Use it on a tool that returns a large result. For a batch read such as jobs_result with job_ids, a limit stops a wave of results from filling the context.
Timeouts need care, too. Sume's jobs_wait holds at most 55 seconds per call on remote MCP, with a default of 50. A tool_timeout_sec below that makes Codex give up before the server answers, while the job continues and bills. Set it above 55, and when wait_slice_expired comes back, call jobs_wait again with the same ids. Never submit the paid create again.
- Use
enabled_toolsfor a read-only allowlist when exploring. - Use
disabled_toolsto remove paid tools for a shared setup. - Set
required = trueonly when a task cannot proceed without Sume. - Keep
idempotency_keystable across retries.
A review checklist before you trust the setting
Run the check in three steps. First, connect with OAuth Read only and call tools_list; with Write off, Sume hides the tools that change data and the paid tools, so the list shows only read-only tools. Second, add the Write grant or a key, and call tools_list again; the paid tools appear now. Third, ask Codex to run one dry_run=true call for generate_image and watch whether it prompts.
If it does not prompt under writes, the tool is being treated as read-only by Codex, and you should add a per-tool approval_mode = "prompt" override. That is the reason the override exists. A dry run submits nothing, so the test costs nothing, which Sume's docs describe as an admission and cost preview only.
Also decide who owns the approval. On a shared machine, the person at the keyboard answers the prompt, and Sume's wallet is charged whatever the editor setting says. The wallet and admission checks are the spend gate on the Sume side, so pair the approval mode with max_spend_usd on the calls you make, since Sume enforces that cap only when you provide it.
Sources
Related posts
More in Integrations
- Cursor remote MCP has no envFile: where the Sume key goes
Cursor's envFile works for stdio servers only. For Sume's remote MCP, read the key from your shell with a headers entry, or skip keys and use OAuth.
- Docker Agent YAML: add Sume as a remote MCP toolset
Docker Agent takes a remote MCP URL, headers and a tools allowlist. Here is the Sume entry with a Bearer key from the environment and a read-only tool list.
- Framer looping video: keep it under 5 MB, Framer won't compress
Framer says keep looping videos under 5 MB, uses H.264 MP4, and serves a 4K upload at full size. Render and trim a Sume clip small before you upload.
- Freshdesk Trigger Webhook: 1000 calls an hour and Sume bulk runs
Freshdesk automations cap webhook calls at 1000 an hour and retry failures every 30 minutes. Here is how a relay maps ticket bursts onto Sume bulk runs.
Written by Sume