Which Sume hosted MCP tools are read-only? 24 the docs label Read
The tools-and-gates page labels 24 hosted MCP tools as Read across five groups, plus meta and account tools. List and verify with tools_list.

Short answer
Sume's tools-and-gates page explicitly labels 24 hosted MCP tools as Read: 6 job tools, 3 asset tools, 2 text-to-speech source tools, 5 avatar tools and 8 crawl tools. A session with only the OAuth scope mcp:read sees read-only tools, and a call to a tool that changes data returns insufficient_scope.
The live registry is the real answer for your session. Always call tools_list and tools_schema, because the docs warn against assuming parity with the HTTP API.
| Group | Read tools | Count |
|---|---|---|
| Jobs | jobs_list, jobs_get, jobs_status, jobs_result, jobs_events, jobs_wait | 6 |
| Assets | assets_list, assets_get, assets_download_url | 3 |
| Text to speech | tts_source_get, tts_source_verify_spine | 2 |
| Avatars | avatars_list, avatars_get, avatars_search, avatar-videos_list, avatar-videos_get | 5 |
| Crawl | crawl_scrape, crawl_map, crawl_search, crawl_get, crawl_profile, crawl_feed, crawl_media, crawl_find | 8 |
Discovery tools outside that count
A second set exists for orientation: mcp_health, tools_list and tools_schema, plus account and catalog reads. The page groups these under meta, health, account and catalog rather than labelling each Read, which is why they are not in the 24. Under an OAuth read-only grant the quickstart treats mcp_health, tools_list, tools_schema, account_me and catalog_list as the useful first calls.
What is not read-only
Write tools need idempotency_key and mcp:write (or an API key): jobs_cancel, assets_create, assets_upload_url, assets_complete, and crawl_site, which is unbilled but still a write. The paid tools, such as the avatar create tools, additionally spend wallet funds.
There is no mcp:paid OAuth scope. Spend is gated by the wallet and admission, and by idempotency_key, optional dry_run and optional max_spend_usd.
Check it in your own session
Connect with OAuth and leave the Write toggle off on the consent page. Call mcp_health and confirm authenticated.auth_source is mcp_oauth. Then call tools_list: with Write off, only the read_only tools are listed, and the paid and write tools are hidden, not merely refused.
If you want agents to explore without any chance of spend, that is the safest configuration the docs describe. Grant mcp:write only for the session that must create.
- Read tools work under
mcp:read, includingcrawl_scrapeandjobs_list. - Write and paid calls under
mcp:readreturninsufficient_scope. - A grant of write always includes read.
How to use the list
Treat the 24 as a floor for an exploration-only agent, and confirm it against tools_list on your own connection, since the registry can change between the docs and your session. A short allowlist in your agent harness that names only these tools adds a second guard on top of the OAuth scope.
If a task needs one write, such as cancelling a job, consider a separate session with mcp:write that exists only for that step.
Where the line blurs
Two cases surprise people. crawl_site sounds like the other crawl tools, but it is a write, so a read-only session will not list it. And jobs_cancel sits next to six read tools in the same jobs group yet changes state. Group names do not tell you the gate; the label on each tool does.
Avatar create tools are paid and are handled with admission checks. The CLI has its own matching gate, --confirm-paid, for the same avatar creates, so a script that works in one place does not silently spend in the other.
- Read the label, not the group.
- An API key gets the full tool set, so use a key only where you accept writes and spend.
- Use
generation_admission_previewbefore any paid call you are unsure about.
Sources
Related posts
More in Developers
- Can hosted MCP run a Sume Format? Call it over REST with an API key
The hosted MCP tools-and-gates inventory lists no Format-run tool. Run Formats with POST /v1/formats/{handle}/{slug}/runs and an API key that has formats:write.
- Hosted video instead of a GPU: a Python submit-poll-download script
Replace a local H3 or Wan pipeline with three HTTP calls. A Python script that submits a minimax-h3 job to Sume, polls it and saves the MP4, with job states.
- How many Sume jobs can one key poll at once? Reads per minute by plan
Polling every 2 seconds costs 30 reads per job per minute. Divide your plan's read budget by 30 to size the poller: 160 jobs on Free, 1600 on Scale.
- How many minutes of speech fit in one 20,000-character TTS request?
Sume TTS caps a request at 20,000 characters. At 800 to 1,200 characters per minute that is roughly 17 to 25 minutes of audio and costs 95 cents.
Written by Sume