Cursor Run Everything mode: a read-only Sume token is the guardrail
In Run Everything, Cursor runs every tool call without review. Connect Sume with mcp:read so paid and write tools are not even visible.

If you run Cursor in Run Everything mode, connect Sume with OAuth read-only and keep Write off. Cursor's docs say that in this mode every tool call runs automatically, with no classifier review or sandbox protections (Cursor run modes, read 2026-10-04). A read-only Sume token means the paid and write tools are hidden from the session, so there is nothing expensive for an unreviewed call to reach.
What Run Everything removes
Cursor describes three modes. Auto-review sends non-sandboxed calls to a classifier. Allowlist mode runs only actions in your allowlist without approval. Run Everything skips both the classifier and the sandbox. Team administrators can override which modes are available to users, so the right default may not be yours to choose.
That makes the credential, not the mode, the real control for a remote server. Whatever the token can do is what an unreviewed run can do.
What a read-only Sume session can and cannot do
On the hosted endpoint https://mcp.sume.com/mcp, OAuth consent shows Permissions with Read locked on and the Write toggle off by default. A session with mcp:read sees read-only tools, and a mutating call returns insufficient_scope. Granting write always includes read (MCP OAuth and API keys).
An API key is the opposite: it gets the full hosted tool set. Do not put an API key behind a client that runs every call unreviewed unless you are happy with every tool being reachable.
| Credential | Tools the session sees | A paid call |
|---|---|---|
| OAuth mcp:read | Read-only tools | Not visible; a mutating call returns insufficient_scope |
| OAuth mcp:read and mcp:write | Read, write and paid tools | Needs idempotency_key; dry_run and max_spend_usd optional |
| API key | Full hosted tool set | Same gates; spend is wallet and admission |
Prove the session is read-only
After connecting, ask the agent to call mcp_health and check that the auth source is mcp_oauth, then call tools_list and confirm that only read tools appear. If a write tool is listed, the session was granted more than you intended, and you should reconnect with Write off.
- Useful read tools:
catalog_list,balance_get,jobs_list,jobs_status,assets_list. - Generation tools such as
generate_imageandgenerate_videoneedmcp:writeor an API key. - Switch to a write session only for the task that needs it, then disconnect.
When you do need to generate
Move to a separate connection with Write on, and pair it with a more careful run mode for that session. Preview with dry_run=true, send max_spend_usd, and use a stable idempotency_key so a retry cannot double-submit.
Sources
Related posts
More in Integrations
- Cline Connectors tab tool count: Sume read-only vs write session
Cline's desktop Connectors tab shows how many tools a connector adds to new sessions. Sume's count depends on the scope you grant or an API key.
- Discord multiline slash options: send a script to Sume Avatar
Discord string options now accept multiline input. Use one for an avatar script and post it to Sume's talking-video endpoint with an interaction-keyed id.
- Evaluating a video MCP server: five checks, with Runway as context
Runway shipped MCP and plugin channels on Sep 17, 22, 23 and Oct 1. Before you connect any video MCP server, check scopes, idempotency, spend caps and waits.
- fal lists Seedream 5.0 and Krea 2: find what Sume's image catalog has
fal.ai/models names GPT Image 2.5, Flux 2, Nano Banana 2, Ideogram 4, Krea 2 and Seedream 5.0. A Python check of which names appear in Sume's /v1/images/models.
Written by Sume