Same Sume MCP URL, different tools: what your credential can see
Two clients on one Sume MCP URL can list different tools. Credential scope sets the surface, so compare mcp_health tools[] before blaming the client.

Two clients pointed at the same Sume MCP URL can show different tool lists, because the visible surface depends on the credential. An OAuth session with only mcp:read lists read tools; a session with mcp:write or an API key lists the paid and write tools as well. Before blaming a client, call mcp_health in each and compare the tools array and the credential scopes.
The mcp_health shape is from the Sume MCP server code, and the scope rules are from MCP OAuth and API keys, read on 2026-10-03.
What decides the surface
The tools field in the mcp_health response lists the names visible to this request. It is computed per request from the credential, not from the URL, so two sessions on one endpoint can legitimately differ. The response also shows whether the surface is progressive: when it is, a tool_surface block lists tool families and the number of catalog tools.
| Difference | Where it shows in mcp_health | Effect |
|---|---|---|
| OAuth with Write off | scopes list only mcp:read | Read tools only |
| OAuth with Write on | scopes include mcp:write | Write and paid tools visible |
| API key | credential type api_key, with prefix | Full hosted tool set |
| Progressive surface | tool_surface with families | Discover more via tools_list and tools_schema |
A comparison routine
Run mcp_health in the working client and the broken one. Compare three things: authenticated.auth_source, the scopes in the credential block, and the tools array. Differences in the first two explain differences in the third. If all three match but the client still hides a tool, the problem is in the client's own tool filtering or a stale tool cache, and reconnecting is the next step.
The build block in the same response carries a commit and branch for the server. Include it when you report a problem to Sume so the report names the exact deployment.
What to change
If a tool is hidden because Write was never granted, sign in again and turn Write on, or switch the session to an API key. A mutating call without the scope returns insufficient_scope rather than doing anything, so the failure is safe and informative.
Do not widen scope just to make a list longer. A reporting agent that only reads should stay on mcp:read; the missing paid tools there are the feature.
Put it in CI
If an automated job depends on certain tools, add a start-up check: call mcp_health, then assert that each required tool name appears in tools. Fail early with a message that names the missing tool and the scopes found. A job that discovers a missing tool halfway through a batch has already done part of its work.
Keep the check read-only. It needs only mcp:read, so it works on every credential the job might run under.
Sources
Related posts
More in Developers
- MCP Python SDK 2.3 max_sse_event_size vs Sume's 256 KiB result cap
MCP Python SDK 2.3.0 adds max_sse_event_size. Sume caps a tool result at 256 KiB, so a normal Sume result fits well under any sane SSE limit.
- MCP TypeScript SDK 2.3 maxToolInputElements: Sume tool arguments
MCP TypeScript SDK 2.3.0 adds maxToolInputElements on McpServer. A server-side cap on array size; here is how it relates to Sume's tool arguments.
- MAI-Transcribe-2-Streaming '2x faster': measure your caption delay
Microsoft says words appear 2x faster than its closest competitor. Measure your own delay from speech to caption with a p50 and p95 script before you switch.
- Microsoft Agent Framework hosted MCP tool for Sume (Python)
Attach https://mcp.sume.com/mcp to an Agent Framework agent with get_mcp_tool, allowed_tools and approval_mode. Foundry runs the calls, so mind the key.
Written by Sume