mcp:read hides Sume's write tools from tools/list: insufficient_scope

Under OAuth mcp:read, Sume's tools/list hides write and paid tools and a direct call returns insufficient_scope. How to tell a hidden tool from a broken one.

4 min readSume
All posts

If generate_image is missing from your Sume tool list, your session probably has only mcp:read. Sume's hosted MCP hides the tools that change data and the paid tools until the session also has mcp:write, or uses an API key, per its docs read on 2026-10-04. A call to such a tool by name returns insufficient_scope. There is no mcp:paid scope.

How do the credentials compare?

Auth matrix from Sume's MCP tools and gates and MCP OAuth pages, read 2026-10-04.
SessionTools listedWrite or paid call
OAuth mcp:read onlyread-only toolsinsufficient_scope
OAuth mcp:read + mcp:writefull hosted setneeds idempotency_key and wallet admission
API keyfull hosted setsame idempotency_key and admission rules

How do I fix a hidden tool?

Grant write at consent. The consent page shows Read locked on and the Write toggle off by default, and a write grant always includes read. Reconnect the client and call tools_list again; the hidden tools should appear. The MCP OAuth and API keys page documents the toggle.

Passing allow_write or allow_paid does not help. Sume accepts both for back-compatibility, they are optional, and they cannot bypass a missing mcp:write scope.

Is the scope a spending limit?

No. Write access lets the model start paid work, and spend is decided by wallet and admission, not by a scope. Three optional arguments constrain a call: idempotency_key is required and de-duplicates, dry_run=true previews admission and cost without submitting, and max_spend_usd caps a call only when you send it. The model writes those arguments, so enforce limits on the client where you can. The MCP tools and gates page lists them.

What about script_run?

A script runs under the same credential. Calls inside it have the same gates, redaction and errors as a direct call, so a read-only session cannot create anything through a script either. Paid creates inside a script still need their own idempotency_key, and the run returns calls[] so you can see which inner call was refused.

When you debug, compare tools_list for the session to the tool you expected, and call mcp_health for the auth source. If the credential is right and the tool is still absent, read the live contract with tools_schema before you file a bug.

What is the quick diagnosis?

Three checks, in order. Is the tool absent from tools_list? Then the session is read-only or the name is wrong. Does a direct call return insufficient_scope? Then the grant lacks mcp:write. Does the call fail on idempotency_key? Then you reached the tool and only the arguments are wrong. Each answer points at a different fix, and none of them is a retry.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume