Let a video agent read before it spends: MCP OAuth read, then write
Hosted MCP OAuth gives mcp:read by default and mcp:write by a consent toggle. Let an agent plan with reads, then enable write for paid calls.

How do you stop an AI agent from spending money while it plans a video? Connect it to hosted MCP with OAuth and leave the Write toggle off: mcp:read is required and read-only. Turn on mcp:write on the consent page, or use an API key, only when you want it to run paid tools such as avatar creation.
Sume's docs treat reads and paid writes as two different permissions, so a planning agent can look without being able to spend.
The matrix
Hosted MCP lives at https://mcp.sume.com/mcp. It accepts OAuth access tokens or Sume API keys, and one credential cannot stand in for the other.
| Mode | Capability | Paid calls |
|---|---|---|
| OAuth, Write off | mcp:read, read-only | Not available |
| OAuth, Write on | mcp:read and mcp:write | Allowed, with idempotency_key |
| API key | Full hosted tool set; spend is wallet admission | Allowed, with idempotency_key |
What a planning pass reads
With mcp:read, a session sees only read-only tools; a call that changes data returns insufficient_scope. The paid hosted tools include generate_image, generate_video, music_create, tts_create, avatars_create and avatar-videos_create. Write and paid calls must send idempotency_key.
There is no mcp:paid scope; write is the gate. The workspace comes from the key or the session, so tools must never ask the user for a workspace id.
A safe default
Start every new agent integration with OAuth and Write off. Let it list catalog models, read job status and usage, and draft a plan with prices. Review the plan, then grant write for the session that executes it.
Log request ids, job ids and high-level status. Do not log API keys, signed URLs, raw private media URLs or large transcripts.
Where this fits
This split suits agents that plan a season of episodes. The planning pass uses read tools only. The execution pass needs write. Before the first paid submit, Sume recommends dry_run=true or generation_admission_preview, and max_spend_usd sets a maximum spend when you pass it. A person reads the plan, then enables write.
- Use OAuth for people-in-the-loop work.
- Use an API key for unattended jobs, with a tight cap.
- Send idempotency_key on every write and paid call.
Reviewing the plan
A useful plan lists each call the agent intends to make, the model or tool, and the expected cost. Ask the agent for that list in structured form, use dry_run to preflight cost, and only then switch on write. If the agent proposes something outside the list, deny the call.
Sources
Related posts
More in Agents
- MCP wants a human in the loop: Sume gates for unattended agents
MCP says a human SHOULD be able to deny tool calls. For unattended agents, Sume adds scopes, idempotency keys and a required Agent Completions cap.
- Auditing agent tool calls: MCP log advice, Sume script_run journal
The MCP spec tells clients to log tool usage for audit. For Sume's script_run, the response includes a calls[] journal and child jobs[] to use with jobs_wait.
- Mistral Large 4 preview: Sume's agent model field takes one value
Mistral Large 4 is reported in preview. Sume lists no Mistral Large id; Agent Completions accepts only sume-agent. What to send instead, and what it bills.
- One webhook handler for Sume agent, Format and schedule runs
A single receiver can handle all three Sume run types: verify the HMAC over timestamp.body, dedupe on request_id, and branch on outcome (ok, degraded, error).
Written by Sume