Codex enabled_tools: allowlist only read-only Sume MCP tools
Codex's enabled_tools setting limits which tools a Sume MCP server exposes. Here is an allowlist of Sume's read tools, and why it matters most for API keys.

To let Codex use Sume without letting it start paid work, add enabled_tools to the Sume server table in config.toml and list only read tools such as mcp_health, tools_list, jobs_status, jobs_wait and jobs_result. Codex's page calls enabled_tools a tool allow list, so every Sume tool you leave out is outside it. The list matters most when you connect with an API key, because a key session sees Sume's full hosted tool set.
Codex facts come from Codex: Model Context Protocol; Sume facts from MCP tools and gates and MCP OAuth and API keys, both read 2026-10-02.
What does enabled_tools do in Codex?
Codex's MCP page lists enabled_tools as an optional tool allow list and disabled_tools as a deny list that is applied after enabled_tools. Both sit in the [mcp_servers.<name>] table next to url. The page also describes default_tools_approval_mode, with values auto, prompt, writes and approve, and a per-tool approval_mode override.
The allow list and the approval mode do different jobs. The allow list answers which tools the server may offer; the approval mode answers whether Codex asks before running one that is offered. For paid generation you usually want both.
| Setting | What the Codex page says | Sume value |
|---|---|---|
enabled_tools | Tool allow list for the server | Read tools only, for example mcp_health, tools_list, tools_schema, balance_get, jobs_status, jobs_wait, jobs_result |
disabled_tools | Tool deny list, applied after enabled_tools | Paid names you never want, such as generate_video |
default_tools_approval_mode | auto, prompt, writes or approve | prompt for anything that is not read-only |
bearer_token_env_var | Environment variable that holds the bearer token | SUME_API_KEY, never the key itself |
Which Sume tools are safe to put on the list?
Sume's docs group the hosted tools by kind. Meta and health tools (mcp_health, tools_list, tools_schema) are read-only. Account and catalog reads include account_me, balance_get, usage_get and catalog_list. The job reads are jobs_list, jobs_get, jobs_status, jobs_result, jobs_events and jobs_wait. Asset reads are assets_list, assets_get and assets_download_url.
Paid and write tools carry a required idempotency_key. generate_image, generate_video, music_create, tts_create and jobs_cancel are examples. Leave them off the allow list unless the task is to generate.
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
bearer_token_env_var = "SUME_API_KEY"
enabled_tools = [
"mcp_health", "tools_list", "tools_schema",
"account_me", "balance_get", "catalog_list",
"jobs_status", "jobs_wait", "jobs_result",
]Does an allow list replace the OAuth read scope?
No, they stack. With OAuth, Sume's default consent grants mcp:read only, and mutating or paid tools are hidden until you turn Write on at consent. With an API key there is no such filter, so the allow list is the only thing between the model and a paid create on your Codex side.
Neither is a spend limit. Sume's docs say max_spend_usd is enforced only when the call provides it, and dry_run=true only previews cost. Both are arguments the model writes. A tool that is not on the list cannot be called, which is a stronger guarantee than either.
How do I check the list took effect?
Run codex mcp list, then open the /mcp view in the Codex TUI, which the page says shows your active MCP servers. Ask Codex to call tools_list. Sume's tools_list returns every tool the session can see on the Sume side, so it will still show the full set; the Codex allow list is what narrows the model's view. If a tool you need is missing, add its exact underscore name from tools_list and restart the session.
If you later need a generation run, either add the specific tool for that session or use a separate server entry with its own table name, so the read-only entry stays the default.
Sources
Related posts
More in Integrations
- Codex MCP required = true: fail fast when the Sume server is down
Codex's required = true makes startup fail if an enabled MCP server cannot initialize. When to set it for Sume, and how the 1000 ms grace and 10 s timeout work.
- Convex HTTP action as a Sume webhook receiver: raw body, no retry
A Convex httpAction reads the raw body with request.text() and is not retried by Convex, so Sume's 10 delivery attempts and a job_id dedupe do the work.
- Copilot CLI 1.0.92: MCP tools after OAuth re-auth, with Sume
Copilot CLI 1.0.92-0 keeps MCP tools working after OAuth re-auth when definitions are unchanged. Sume tokens last one hour with no refresh, so you will hit it.
- Cursor MCP allowlist: approve Sume's URL and its read tools
Cursor enterprise admins approve remote MCP servers by URL entry and list tools per server. How to allow Sume's mcp.sume.com/mcp and which tools to list.
Written by Sume