Evaluating a video MCP server: five checks, with Runway as context

Runway shipped MCP and plugin channels on Sep 17, 22, 23 and Oct 1. Before you connect any video MCP server, check scopes, idempotency, spend caps and waits.

4 min readSume
All posts

Before you connect a video MCP server to an agent, check five things: whether paid tools are separated from read tools, whether paid calls need an idempotency key, whether you can preview or cap spend, how long waits are bounded, and whether the agent can list tool schemas. Runway's changelog shows four new connection channels in two weeks, so these checks matter more each month.

Runway integration entries from its changelog (read 2026-10-03)
DateEntry
Sep 17, 2026Grok Bot plugin
Sep 22, 2026Read-only Brand Kits through MCP
Sep 23, 2026Cursor Marketplace and DaVinci Resolve plugin
Oct 1, 2026OpenAI Dots integration, available on all plans

1. Read and write are separate

A server that lets any connected agent spend money on first contact is a risk. Sume's hosted MCP defaults to read-only visibility under OAuth mcp:read; mutating and paid tools stay hidden until the session has mcp:write or uses an API key. Runway's Brand Kits entry is described as read-only, which is the same instinct applied to a single feature.

2. Paid calls carry an idempotency key

Agents retry. A paid tool without a dedup key turns a dropped connection into a second charge. On Sume, idempotency_key is required on every write and paid tool, so a retry can reuse the same key instead of paying twice.

3. Preview and cap the spend

Look for a dry run and a ceiling. Sume offers dry_run=true for an admission and cost preview without submitting, and max_spend_usd, which is enforced only when you provide it. The second point matters: a cap you never set protects nothing, so set it in the agent's instructions.

4. Waiting is bounded

A held HTTP request dies at the edge eventually. Sume's jobs_wait holds at most 55 seconds per call (50 by default), accepts 1 to 20 job ids, and returns wait_slice_expired when the slice ends so the agent repeats the wait instead of resubmitting the paid create. A server that promises a ten-minute wait in one call is promising something transport cannot deliver.

5. The agent can discover the contract

tools_list and tools_schema let an agent read the live contract before it acts, and the docs advise against assuming parity with the HTTP API. Run both against any candidate server and read the safety metadata for yourself. The full inventory is in MCP tools and gates.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume