mcp:read hides Sume's write tools from tools/list: insufficient_scope
Under OAuth mcp:read, Sume's tools/list hides write and paid tools and a direct call returns insufficient_scope. How to tell a hidden tool from a broken one.

If generate_image is missing from your Sume tool list, your session probably has only mcp:read. Sume's hosted MCP hides the tools that change data and the paid tools until the session also has mcp:write, or uses an API key, per its docs read on 2026-10-04. A call to such a tool by name returns insufficient_scope. There is no mcp:paid scope.
How do the credentials compare?
| Session | Tools listed | Write or paid call |
|---|---|---|
OAuth mcp:read only | read-only tools | insufficient_scope |
OAuth mcp:read + mcp:write | full hosted set | needs idempotency_key and wallet admission |
| API key | full hosted set | same idempotency_key and admission rules |
How do I fix a hidden tool?
Grant write at consent. The consent page shows Read locked on and the Write toggle off by default, and a write grant always includes read. Reconnect the client and call tools_list again; the hidden tools should appear. The MCP OAuth and API keys page documents the toggle.
Passing allow_write or allow_paid does not help. Sume accepts both for back-compatibility, they are optional, and they cannot bypass a missing mcp:write scope.
Is the scope a spending limit?
No. Write access lets the model start paid work, and spend is decided by wallet and admission, not by a scope. Three optional arguments constrain a call: idempotency_key is required and de-duplicates, dry_run=true previews admission and cost without submitting, and max_spend_usd caps a call only when you send it. The model writes those arguments, so enforce limits on the client where you can. The MCP tools and gates page lists them.
What about script_run?
A script runs under the same credential. Calls inside it have the same gates, redaction and errors as a direct call, so a read-only session cannot create anything through a script either. Paid creates inside a script still need their own idempotency_key, and the run returns calls[] so you can see which inner call was refused.
When you debug, compare tools_list for the session to the tool you expected, and call mcp_health for the auth source. If the credential is right and the tool is still absent, read the live contract with tools_schema before you file a bug.
What is the quick diagnosis?
Three checks, in order. Is the tool absent from tools_list? Then the session is read-only or the name is wrong. Does a direct call return insufficient_scope? Then the grant lacks mcp:write. Does the call fail on idempotency_key? Then you reached the tool and only the arguments are wrong. Each answer points at a different fix, and none of them is a retry.
Sources
Related posts
More in Developers
- MCP tasks/cancel vs Sume jobs_cancel: cancel works only before start
TypeScript SDK 2.3.0 adds tasks/get and tasks/cancel. Sume's jobs_cancel is narrower: it succeeds only before generation starts, then returns 409.
- MCP spec timeline: 2025-11-25, RC on May 29, stable on July 28, 2026
The MCP 2026-07-28 spec went stable on July 28, 2026, 60 days after its May 29 RC, replacing 2025-11-25. Dates, and how to check what you run.
- MCP tasks extension and Sume job statuses: mapping for render tools
In MCP 2026-07-28 tasks are an extension polled with tasks/get. Map task handles, polling, update and list onto Sume job ids, status reads and jobs_cancel.
- MCP tool ran twice: idempotency_key saves your Sume render
Claude Code fixed MCP tool calls that sometimes ran twice on large results. Sume's paid MCP tools require an idempotency_key so a repeat does not bill twice.
Written by Sume