Sume MCP consent: granting write always includes read
Sume's MCP consent offers mcp:read (required) and mcp:write (opt-in). A write grant always includes read, and there is no paid scope.

On Sume's MCP consent screen, mcp:read is required and mcp:write is opt-in. A write grant always includes read, so there is no way to hold write without read. There is no mcp:paid scope either.
This follows Sume's OAuth and API keys and MCP tools and gates, read 2026-10-06.
What does each grant allow?
The table below lists each item as documented.
| Grant | Includes | Use for |
|---|---|---|
mcp:read | Read tools | Discovery, status, results |
mcp:write | Read plus write tools | Changes that need approval |
| API key | Full tool set | Headless automation |
Is a paid call blocked without a paid scope?
Do not assume so. Because no paid scope exists, spend is controlled by the call arguments instead: paid and write calls need idempotency_key, and dry_run and max_spend_usd are optional gates you send per call. Read the rule on the tools-and-gates page, and tell agents to send them.
Sources
Related posts
More in Developers
- Haystack MCPTool 30-second timeout vs Sume jobs_wait holds
Haystack's MCPTool times out tool calls at 30 seconds; Sume's jobs_wait holds 50 to 55. Raise invocation_timeout or wait in shorter slices.
- Heroku H12 at 30 seconds: call Sume async, not sync
Heroku's router ends a request at 30 s (H12). Sume sync mode waits up to 30 s too. Submit async, return 202 to the browser, then poll or take a webhook.
- Does Sume hosted MCP match the HTTP API? Where parity stops
Not fully. Hosted MCP covers most generation families, but Image 1.0 and Video 1.0 are REST-only, and schedules have no MCP tool. Use the HTTP API for those.
- How long can an AI video Format run take? 90-minute limit
A Sume Format run expires 90 minutes after creation, sooner if silent. How to poll with backoff, when to use a webhook, and what expired means.
Written by Sume