Codex MCP per-tool approval_mode: always prompt on Sume generate_video
In Codex config.toml, tools.<tool>.approval_mode overrides the server default, so generate_video can prompt while jobs_status runs without asking.

In Codex, add a tools.<tool>.approval_mode table under the Sume server and set it to prompt for each paid tool, such as generate_video, while leaving the server default for everything else. Codex's MCP reference lists default_tools_approval_mode with the values auto, prompt, writes and approve, and a per-tool override that takes precedence for that tool (read 2026-10-02).
What the reference lists
The Codex reference groups approval settings with the other per-server keys. Codex CLI 0.159.0 and 0.160.0, released on 2026-09-29 and 2026-10-01, are the current builds in the changelog, and the changelog lists configurable tool and MCP input schema budgets in 0.159.0 and an opt-in Guardian review in 0.160.0.
| Key | What the Codex docs say | For Sume |
|---|---|---|
default_tools_approval_mode | Default approval behavior: auto, prompt, writes, approve | writes, then check the semantics |
tools.<tool>.approval_mode | Per-tool approval override | prompt for paid tools |
enabled_tools / disabled_tools | Tool allow and deny lists | Alternative to prompting |
bearer_token_env_var | Environment variable for the bearer token | SUME_API_KEY |
tool_timeout_sec | Seconds for a tool to run; default 60 | 90, above Sume's 55 s hold |
[mcp_servers.sume]
url = "https://mcp.sume.com/mcp"
bearer_token_env_var = "SUME_API_KEY"
default_tools_approval_mode = "writes"
tool_timeout_sec = 90
[mcp_servers.sume.tools.generate_video]
approval_mode = "prompt"
[mcp_servers.sume.tools.avatar-video-previews_generate_video]
approval_mode = "prompt"Which Sume tools to pin to prompt
Sume's docs list the paid tools: generate_image, generate_video, music_create, tts_create, stt_create, image_upscale_create, rmbg_create, video_upscale_create and kling-motion-control_create, plus the avatar creates (MCP tools and gates). Each needs an idempotency_key, which Sume describes as transport and deduplication, not human approval. So Sume's own gate will not stop an agent from submitting; Codex's prompt mode is what puts a person in the loop.
Pin the expensive ones, usually video and avatar creates, to prompt, and leave cheap reads alone. A server-wide default of writes is a good base, but check in the Codex docs how that mode treats a tool that Sume marks as paid, because the docs I read do not spell out how Codex classifies it.
Pair it with Sume's own preview
Ask the agent to run the paid call with dry_run=true first, then approve the real call when the preview looks right. max_spend_usd adds a cap, and Sume enforces it only when it is provided. A prompt on the real call plus a dry_run before it gives you a cost preview and a human decision, which neither gives alone.
Keep the OAuth versus key difference in mind: with OAuth mcp:read only, paid tools are hidden and return insufficient_scope, so per-tool approval only matters for key sessions and for OAuth sessions where you turned Write on (MCP OAuth and API keys).
Caveats
Verify the first call with mcp_health (MCP quickstart).
- I have not tested which tool-name spelling Codex expects for hyphenated Sume names; confirm with
codex mcp listand a trial call. - Approval settings control prompts, not spend; the wallet is the spend gate.
- Guardian review in 0.160.0 is opt-in per the changelog, and I did not read its behavior beyond that line.
Sources
Related posts
More in Integrations
- Convex HTTP action as a Sume webhook receiver: raw body, no retry
A Convex httpAction reads the raw body with request.text() and is not retried by Convex, so Sume's 10 delivery attempts and a job_id dedupe do the work.
- Copilot CLI 1.0.92: MCP tools after OAuth re-auth, with Sume
Copilot CLI 1.0.92-0 keeps MCP tools working after OAuth re-auth when definitions are unchanged. Sume tokens last one hour with no refresh, so you will hit it.
- Copilot CLI --mcp-github-auth: what Sume's MCP server receives
Copilot CLI's --mcp-github-auth limits GitHub auth to approved MCP origins. Sume's hosted MCP uses its own OAuth or API key, never your GitHub token.
- Crush MCP server: add Sume in crush.json with type http
Add Sume's hosted MCP to Crush in crush.json with type http, a header read from an environment variable, disabled_tools for paid tools, and a long timeout.
Written by Sume