Read-only MCP session lists avatars; create gives insufficient_scope

A hosted MCP connection with read scope can list and search avatars, but paid avatar and video tools return insufficient_scope until you grant write.

3 min readSume
All posts

What a read-only session can do

Sume's hosted MCP exposes avatar tools in two groups. Read tools: avatars_list, avatars_get, avatars_search, avatar-videos_list and avatar-videos_get. Paid tools: avatars_create, avatar-videos_create, avatar-image-to-video_create and the avatar-video-previews tools.

Scope against tools (hosted MCP docs)
GrantedRead toolsPaid tools
mcp:read onlyWorkinsufficient_scope
mcp:write grantedWorkWork, with optional dry_run and max_spend_usd

The practical flow

Connect with read scope first and let the assistant look at your avatars. When it needs to spend, add write. The docs say the legacy allow_write and allow_paid arguments are not required and cannot bypass a missing mcp:write scope.

Cap what a write session can spend

Paid tools accept dry_run to preview admission and cost without submitting. They also accept max_spend_usd, which Sume enforces only when you send it. For a 10 s plus clip, a cap of 3 dollars would let it through and a cap of 2 would not.

If you hit it

  • Re-authorize the connection with write scope, then retry the same call.
  • Reads such as avatars_list still work in the meantime.
  • Use an idempotency_key on every write so a retry does not double bill.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume