Codex default_tools_approval_mode writes with Sume tools
With default_tools_approval_mode = "writes", Codex prompts for tools not marked read-only. Sume marks reads readOnlyHint true and writes false.

Set default_tools_approval_mode = "writes" on the Sume server in Codex and read tools run without a prompt while write and paid tools stop for approval. That works because Sume's server annotates tools: reads carry readOnlyHint: true, writes carry readOnlyHint: false.
The Codex docs list four modes (auto, prompt, writes, approve) and say writes "prompts for tools that aren't marked read-only". The Sume annotations are from packages/mcp-server/src/mcp-tool-results.ts, and the gates from MCP tools and gates, checked 2026-10-01.
How does Sume annotate its tools?
Two helpers in the server code build the annotations for most tools, so they fall into one of two shapes.
| Annotation | Read tools | Write tools |
|---|---|---|
readOnlyHint | true | false |
idempotentHint | true | false |
openWorldHint | false | false |
destructiveHint | false | false unless the tool is marked destructive |
What does the config look like?
One line on the server entry. A per-tool override, tools.<tool>.approval_mode, exists in the Codex docs if you want a specific tool to behave differently.
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
default_tools_approval_mode = "writes"Is the approval prompt the same as idempotency_key?
No. The docs describe idempotency_key, required on write and paid tools, as a "stable key for transport/dedup, not human approval". Codex's prompt is the human step; the key keeps a retried submit from creating a second job. Both apply to a paid call under writes mode.
Which mode should I pick?
writes suits an interactive session where you want reads to flow and spending to pause. If you need to exclude specific paid tools entirely, pair it with a deny list; see disabled_tools for paid Sume tools. Sume also supports dry_run=true to preview admission and cost before a submit.
Sources
Related posts
More in Integrations
- Claude highlight edit from a long video: Resolve 21.1 vs Sume MCP
Resolve 21.1 lets Claude edit highlights inside Resolve. Sume's hosted MCP can do a cloud version: inspect, trim ranges, join with timeline_create.
- Devin Desktop MCP authorization opens the provider: Sume page
Devin Desktop 3.10.23 opens MCP authorization at the provider directly. For Sume that is mcp.sume.com/oauth/authorize, then a consent page on the MCP host.
- Devin MCP write scopes by default: Sume keeps write opt-in
Devin now requests read/write scopes by default for Microsoft 365 MCP. Sume's hosted MCP asks for read only unless the user turns Write on at consent.
- fal MCP "why did my request fail": the Sume job equivalent
fal's Platform MCP lets an assistant debug a failed request. For a failed Sume media job, read jobs_events and the error, then retry by the error rules.
Written by Sume