MCP spec: tool annotations are untrusted. What that means for Sume
The MCP spec says clients must treat tool annotations as untrusted unless they come from a trusted server. Treat Sume as trusted only for your own workspace.

The 2025-11-25 MCP specification says clients must consider tool annotations untrusted unless they come from a trusted server. In practice that means a client may show readOnlyHint to a person, but it should not let that hint alone skip an approval for a tool that spends money. For Sume, the safer reading is that the annotation is a convenience and the credential is the real gate.
Where the real gate sits
The enforcement lives on the Sume side. Under an OAuth session that has only mcp:read, write tools are not in the list, and calling one by name returns insufficient_scope. A model cannot talk its way past that, and a wrong annotation cannot widen it.
| Concern | Spec says | Sume does |
|---|---|---|
| Annotations | Untrusted unless from a trusted server | Tools carry read-only hints, but scope does not depend on them |
| Confirmation | Clients SHOULD prompt for confirmation on sensitive operations | Write calls hidden under mcp:read; need mcp:write or an API key |
| Logging | Clients SHOULD log tool usage | Write and paid calls need an idempotency_key you can log |
| Errors | Tool errors use isError true | Scope failures return insufficient_scope with required_scope mcp:write |
Settings that follow from this
Sume's max_spend_usd and dry_run are optional and apply only when sent, so they are a habit to teach the agent, not a guarantee. A client approval prompt on paid tools is the control that does not depend on the model.
- Auto-approve only tools you have checked in the Sume tool list, not everything with a read-only hint.
- Prefer OAuth with Write off for sessions that only browse models, jobs and balances.
- Keep paid tools on manual approval, and send max_spend_usd so a call has a ceiling.
- Log the idempotency_key and job id for every write call so a retry can be told apart from a new spend.
When trust is reasonable
You connect to https://mcp.sume.com/mcp with your own credential, so the server is yours to trust at the scope you granted. That is different from a third-party server you found in a directory, where a hint could be wrong or hostile. Even for Sume, trust follows the credential: an API key means the full surface, and an OAuth session means the scopes you ticked.
A short test for your client
Connect with an OAuth session that has Write off, then ask the model to submit a paid job. You should see no write tool in the list, and a direct call by name should fail with insufficient_scope. Repeat with an API key and a paid tool and confirm that your client still asks you before it runs. If it does not ask, the client is trusting an annotation or an auto-approve rule, and that is the setting to change.
Sources
Related posts
More in Integrations
- MCP tool error or JSON-RPC error: where Sume's failures land
Sume returns tool failures as results with isError true and keeps JSON-RPC errors for protocol faults, per the 2025-11-25 MCP spec. Here is the split.
- Perplexity Agent API MCP tool: server_label rules for Sume
Perplexity MCP tool: server_label must match ^[a-zA-Z0-9_-]{1,64}$. A Sume entry that passes, with authorization, headers and allowed_tools.
- Perplexity MCP authorization field with Sume: one-hour token
Perplexity passes the authorization value to the MCP server as an access token. A Sume OAuth token lasts one hour with no refresh, so use an API key unattended.
- Sume MCP read_busy 503: four concurrent reads per owner
read_busy is a retryable 503 from Sume's MCP host. Reads inside tools, including jobs_wait polls, are capped at 4 at once per owner, 512 across the host.
Written by Sume