mcp_health on Sume: which credential and scopes is this session using?
Sume's mcp_health tool reports the auth source and the credential behind a session: an OAuth token with client and scopes, or an API key prefix. How to read it.

When a Sume MCP client shows fewer tools than you expected, call mcp_health first. It is read-only and tells you how the session authenticated: authenticated.auth_source is mcp_oauth for an OAuth session, and the credential block names either an OAuth access token with its client id and scopes, or an API key with its prefix and scopes. That one response usually explains whether a paid tool is hidden because Write was never granted.
The field names below come from the tool implementation in the Sume MCP server, and the behavior around scopes from MCP OAuth and API keys and MCP tools and gates, all read on 2026-10-03.
What the response carries
Besides status ok and the transport (streamable HTTP), the response includes the canonical MCP endpoint, a safety block, and the list of tool names visible to this session. The authenticated object is the part that matters for debugging: the auth source, the workspace id, and a credential descriptor.
For an OAuth session the descriptor has type oauth_access_token, the client id that was granted the token, and its scopes. For an API-key session it has type api_key, the key prefix, and the key's scopes. Only the key prefix is shown, never the key itself. The response also carries your workspace id, so check it before you paste it into a ticket, and do not paste anything else from the session next to it.
| You see | It means | Tool surface |
|---|---|---|
| auth_source mcp_oauth, scopes mcp:read | OAuth session, Write not granted | Read-only tools only |
| auth_source mcp_oauth, scopes mcp:read and mcp:write | OAuth session with Write on | Full hosted tool set |
| credential type api_key | API-key session | Full hosted tool set |
Common diagnoses
If you expected to submit a video and generate_video is missing from the tool list, check the scopes in the credential block. A session with only mcp:read hides mutating and paid tools, and calling one returns insufficient_scope. The fix is to re-run the client's OAuth login and turn Write on at consent, or to use an API-key session.
If the auth source is not what you configured, the client may be using a different entry than you think. Compare the key prefix to the key you meant to use, and check which config file the client actually loaded.
What it does not tell you
mcp_health does not report balance, workspace plan or concurrency. Use account_me and balance_get for those. It also does not expose a token deadline, so treat an authorization failure mid-session as a cue to sign in again.
A good habit for CI or agent start-up is to call mcp_health once, assert that the auth source and scopes match the job's intent, and abort otherwise. A read-only reporting job that finds mcp:write in its scopes has been given more authority than it needs, and that is worth failing on.
Sources
Related posts
More in Developers
- Same Sume MCP URL, different tools: what your credential can see
Two clients on one Sume MCP URL can list different tools. Credential scope sets the surface, so compare mcp_health tools[] before blaming the client.
- MCP Python SDK 2.3 max_sse_event_size vs Sume's 256 KiB result cap
MCP Python SDK 2.3.0 adds max_sse_event_size. Sume caps a tool result at 256 KiB, so a normal Sume result fits well under any sane SSE limit.
- MCP TypeScript SDK 2.3 maxToolInputElements: Sume tool arguments
MCP TypeScript SDK 2.3.0 adds maxToolInputElements on McpServer. A server-side cap on array size; here is how it relates to Sume's tool arguments.
- MAI-Transcribe-2-Streaming '2x faster': measure your caption delay
Microsoft says words appear 2x faster than its closest competitor. Measure your own delay from speech to caption with a p50 and p95 script before you switch.
Written by Sume