Codex default_tools_approval_mode writes with Sume tools

With default_tools_approval_mode = "writes", Codex prompts for tools not marked read-only. Sume marks reads readOnlyHint true and writes false.

4 min readSume
All posts

Set default_tools_approval_mode = "writes" on the Sume server in Codex and read tools run without a prompt while write and paid tools stop for approval. That works because Sume's server annotates tools: reads carry readOnlyHint: true, writes carry readOnlyHint: false.

The Codex docs list four modes (auto, prompt, writes, approve) and say writes "prompts for tools that aren't marked read-only". The Sume annotations are from packages/mcp-server/src/mcp-tool-results.ts, and the gates from MCP tools and gates, checked 2026-10-01.

How does Sume annotate its tools?

Two helpers in the server code build the annotations for most tools, so they fall into one of two shapes.

MCP tool annotations in packages/mcp-server, read 2026-10-01
AnnotationRead toolsWrite tools
readOnlyHinttruefalse
idempotentHinttruefalse
openWorldHintfalsefalse
destructiveHintfalsefalse unless the tool is marked destructive

What does the config look like?

One line on the server entry. A per-tool override, tools.<tool>.approval_mode, exists in the Codex docs if you want a specific tool to behave differently.

[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
default_tools_approval_mode = "writes"

Is the approval prompt the same as idempotency_key?

No. The docs describe idempotency_key, required on write and paid tools, as a "stable key for transport/dedup, not human approval". Codex's prompt is the human step; the key keeps a retried submit from creating a second job. Both apply to a paid call under writes mode.

Which mode should I pick?

writes suits an interactive session where you want reads to flow and spending to pause. If you need to exclude specific paid tools entirely, pair it with a deny list; see disabled_tools for paid Sume tools. Sume also supports dry_run=true to preview admission and cost before a submit.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume