mcp_health on Sume: which credential and scopes is this session using?

Sume's mcp_health tool reports the auth source and the credential behind a session: an OAuth token with client and scopes, or an API key prefix. How to read it.

5 min readSume
All posts

When a Sume MCP client shows fewer tools than you expected, call mcp_health first. It is read-only and tells you how the session authenticated: authenticated.auth_source is mcp_oauth for an OAuth session, and the credential block names either an OAuth access token with its client id and scopes, or an API key with its prefix and scopes. That one response usually explains whether a paid tool is hidden because Write was never granted.

The field names below come from the tool implementation in the Sume MCP server, and the behavior around scopes from MCP OAuth and API keys and MCP tools and gates, all read on 2026-10-03.

What the response carries

Besides status ok and the transport (streamable HTTP), the response includes the canonical MCP endpoint, a safety block, and the list of tool names visible to this session. The authenticated object is the part that matters for debugging: the auth source, the workspace id, and a credential descriptor.

For an OAuth session the descriptor has type oauth_access_token, the client id that was granted the token, and its scopes. For an API-key session it has type api_key, the key prefix, and the key's scopes. Only the key prefix is shown, never the key itself. The response also carries your workspace id, so check it before you paste it into a ticket, and do not paste anything else from the session next to it.

Reading the credential block (read 2026-10-03)
You seeIt meansTool surface
auth_source mcp_oauth, scopes mcp:readOAuth session, Write not grantedRead-only tools only
auth_source mcp_oauth, scopes mcp:read and mcp:writeOAuth session with Write onFull hosted tool set
credential type api_keyAPI-key sessionFull hosted tool set

Common diagnoses

If you expected to submit a video and generate_video is missing from the tool list, check the scopes in the credential block. A session with only mcp:read hides mutating and paid tools, and calling one returns insufficient_scope. The fix is to re-run the client's OAuth login and turn Write on at consent, or to use an API-key session.

If the auth source is not what you configured, the client may be using a different entry than you think. Compare the key prefix to the key you meant to use, and check which config file the client actually loaded.

What it does not tell you

mcp_health does not report balance, workspace plan or concurrency. Use account_me and balance_get for those. It also does not expose a token deadline, so treat an authorization failure mid-session as a cue to sign in again.

A good habit for CI or agent start-up is to call mcp_health once, assert that the auth source and scopes match the job's intent, and abort otherwise. A read-only reporting job that finds mcp:write in its scopes has been given more authority than it needs, and that is worth failing on.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume