Grok 4.7 remote MCP tool: connect Sume to the xAI Responses API

xAI's remote MCP tool works with grok-4.7 on the Responses API. Point server_url at Sume's hosted MCP, restrict allowed_tools, and cap spend on the Sume side.

5 min readSume
All posts

To give Grok 4.7 video generation, send a request to xAI's Responses endpoint with a remote MCP tool whose server_url is https://mcp.sume.com/mcp, a Sume API key in headers, and an allowed_tools list that names only the Sume tools you want. xAI's docs say the remote MCP tool works with grok-4.7.

xAI released Grok 4.7 on Sep 21, 2026, according to its announcement. The model page lists model id grok-4.7, a 500k context, $2 input and $6 output per million tokens, and the endpoint https://api.x.ai/v1/responses. All xAI facts here were read 2026-09-29.

What does xAI's remote MCP tool accept?

The tool object takes the fields below. xAI's page says only streamable HTTP and SSE transports are supported, and that require_approval and connector_id are not supported.

From xAI's remote MCP tools page, read 2026-09-29.
FieldPurpose
type"mcp"
server_urlThe remote MCP endpoint
server_labelA name for the server
allowed_toolsRestrict which tools the model may call
authorizationAuthorization value for the server
headersExtra request headers

What is the request?

This uses jq to put the Sume key into the tool's headers, and XAI_API_KEY for xAI. Sume accepts a key as x-api-key or a Bearer token.

curl https://api.x.ai/v1/responses \
  -H "Authorization: Bearer $XAI_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$(jq -n --arg key "$SUME_API_KEY" '{
    model: "grok-4.7",
    input: "Check Sume MCP health, then list the video tools.",
    tools: [{
      type: "mcp",
      server_url: "https://mcp.sume.com/mcp",
      server_label: "sume",
      allowed_tools: ["mcp_health", "tools_list"],
      headers: { "x-api-key": $key }
    }]
  }')"

Is it safe to hand a key to another vendor?

The key travels to xAI in the request, so treat it as shared with them. Use a key made for this purpose, keep allowed_tools short, and rotate it if it appears in a log. Read-only tools cannot spend; start there, as in the example.

To let the model start a paid clip, add generate_video, jobs_wait and jobs_result. Because xAI does not support require_approval, the approval step has to live on Sume's side.

What replaces the missing approval prompt?

Sume's own arguments. Paid calls need an idempotency_key, dry_run=true previews cost without submitting, and max_spend_usd caps the call when provided. Tell the model in the prompt to preview first and to reuse the same idempotency key on a retry.

Then wait with jobs_wait on the returned job ids. On wait_slice_expired, wait again on the same ids; do not resubmit the create call.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume