Codex enabled_tools: allowlist only read-only Sume MCP tools

Codex's enabled_tools setting limits which tools a Sume MCP server exposes. Here is an allowlist of Sume's read tools, and why it matters most for API keys.

4 min readSume
All posts

To let Codex use Sume without letting it start paid work, add enabled_tools to the Sume server table in config.toml and list only read tools such as mcp_health, tools_list, jobs_status, jobs_wait and jobs_result. Codex's page calls enabled_tools a tool allow list, so every Sume tool you leave out is outside it. The list matters most when you connect with an API key, because a key session sees Sume's full hosted tool set.

Codex facts come from Codex: Model Context Protocol; Sume facts from MCP tools and gates and MCP OAuth and API keys, both read 2026-10-02.

What does enabled_tools do in Codex?

Codex's MCP page lists enabled_tools as an optional tool allow list and disabled_tools as a deny list that is applied after enabled_tools. Both sit in the [mcp_servers.<name>] table next to url. The page also describes default_tools_approval_mode, with values auto, prompt, writes and approve, and a per-tool approval_mode override.

The allow list and the approval mode do different jobs. The allow list answers which tools the server may offer; the approval mode answers whether Codex asks before running one that is offered. For paid generation you usually want both.

Codex settings from its MCP page and Sume values from its MCP docs, read 2026-10-02.
SettingWhat the Codex page saysSume value
enabled_toolsTool allow list for the serverRead tools only, for example mcp_health, tools_list, tools_schema, balance_get, jobs_status, jobs_wait, jobs_result
disabled_toolsTool deny list, applied after enabled_toolsPaid names you never want, such as generate_video
default_tools_approval_modeauto, prompt, writes or approveprompt for anything that is not read-only
bearer_token_env_varEnvironment variable that holds the bearer tokenSUME_API_KEY, never the key itself

Which Sume tools are safe to put on the list?

Sume's docs group the hosted tools by kind. Meta and health tools (mcp_health, tools_list, tools_schema) are read-only. Account and catalog reads include account_me, balance_get, usage_get and catalog_list. The job reads are jobs_list, jobs_get, jobs_status, jobs_result, jobs_events and jobs_wait. Asset reads are assets_list, assets_get and assets_download_url.

Paid and write tools carry a required idempotency_key. generate_image, generate_video, music_create, tts_create and jobs_cancel are examples. Leave them off the allow list unless the task is to generate.

[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
bearer_token_env_var = "SUME_API_KEY"
enabled_tools = [
  "mcp_health", "tools_list", "tools_schema",
  "account_me", "balance_get", "catalog_list",
  "jobs_status", "jobs_wait", "jobs_result",
]

Does an allow list replace the OAuth read scope?

No, they stack. With OAuth, Sume's default consent grants mcp:read only, and mutating or paid tools are hidden until you turn Write on at consent. With an API key there is no such filter, so the allow list is the only thing between the model and a paid create on your Codex side.

Neither is a spend limit. Sume's docs say max_spend_usd is enforced only when the call provides it, and dry_run=true only previews cost. Both are arguments the model writes. A tool that is not on the list cannot be called, which is a stronger guarantee than either.

How do I check the list took effect?

Run codex mcp list, then open the /mcp view in the Codex TUI, which the page says shows your active MCP servers. Ask Codex to call tools_list. Sume's tools_list returns every tool the session can see on the Sume side, so it will still show the full set; the Codex allow list is what narrows the model's view. If a tool you need is missing, add its exact underscore name from tools_list and restart the session.

If you later need a generation run, either add the specific tool for that session or use a separate server entry with its own table name, so the read-only entry stays the default.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume