Codex default_tools_approval_mode = writes for Sume MCP

Codex sets approval per MCP server and per tool. Which of auto, prompt, writes and approve suits Sume's read and paid tools, and what output_token_limit does.

4 min readSume
All posts

For Sume's hosted MCP in Codex, set default_tools_approval_mode = "writes" for the server, so Codex prompts for tools that are not marked read-only, and override a paid tool by name with tools.<tool>.approval_mode if you want it to prompt every time. Use approve or auto only for a server that has nothing paid on it.

The Codex MCP page (read 2026-10-10, reached through a redirect from developers.openai.com/codex/mcp) lists four values: auto, prompt, writes and approve. It describes writes as prompting for tools that aren't marked read-only. It describes prompt as asking for confirmation before running tools, and auto as running tools without prompting.

What the four modes mean for Sume

Sume marks its tools with safety metadata, and tools_list returns it. MCP tools and gates says the list shows all tools the session can see and their safety metadata. That is the signal a writes mode can use, and it also means you should confirm, with one tools_list call, that the paid tools are not flagged read-only before you rely on the mode.

Codex approval modes (read 2026-10-10) applied to Sume's hosted MCP
ModeCodex behavior per its docsFit for Sume
autoRuns tools without promptingOnly with an OAuth Read-only grant
promptAsks before running toolsSafe for everything, noisy for reads
writesPrompts for tools not marked read-onlyBest default for an API-key or Write session
approveTools are automatically approvedAvoid for paid tools

Config you can paste

The page names the keys: url, bearer_token_env_var, http_headers, env_http_headers, http_headers_helper, enabled_tools, disabled_tools, default_tools_approval_mode, tools.<tool>.approval_mode, tools.<tool>.output_token_limit, startup_timeout_sec, tool_timeout_sec, enabled and required. Sume's key goes in an environment variable named by bearer_token_env_var, so the file holds no secret.

[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
bearer_token_env_var = "SUME_API_KEY"
default_tools_approval_mode = "writes"
tool_timeout_sec = 120

[mcp_servers.sume.tools.generate_video]
approval_mode = "prompt"

Output limits and long waits

output_token_limit is a positive token budget for one tool's output, applied before a standard 20% serialization allowance, and it supersedes the model's usual truncation for that tool. Use it on a tool that returns a large result. For a batch read such as jobs_result with job_ids, a limit stops a wave of results from filling the context.

Timeouts need care, too. Sume's jobs_wait holds at most 55 seconds per call on remote MCP, with a default of 50. A tool_timeout_sec below that makes Codex give up before the server answers, while the job continues and bills. Set it above 55, and when wait_slice_expired comes back, call jobs_wait again with the same ids. Never submit the paid create again.

  • Use enabled_tools for a read-only allowlist when exploring.
  • Use disabled_tools to remove paid tools for a shared setup.
  • Set required = true only when a task cannot proceed without Sume.
  • Keep idempotency_key stable across retries.

A review checklist before you trust the setting

Run the check in three steps. First, connect with OAuth Read only and call tools_list; with Write off, Sume hides the tools that change data and the paid tools, so the list shows only read-only tools. Second, add the Write grant or a key, and call tools_list again; the paid tools appear now. Third, ask Codex to run one dry_run=true call for generate_image and watch whether it prompts.

If it does not prompt under writes, the tool is being treated as read-only by Codex, and you should add a per-tool approval_mode = "prompt" override. That is the reason the override exists. A dry run submits nothing, so the test costs nothing, which Sume's docs describe as an admission and cost preview only.

Also decide who owns the approval. On a shared machine, the person at the keyboard answers the prompt, and Sume's wallet is charged whatever the editor setting says. The wallet and admission checks are the spend gate on the Sume side, so pair the approval mode with max_spend_usd on the calls you make, since Sume enforces that cap only when you provide it.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume