MCP sub-agent with narrower authority: a read-only Sume token
Give a sub-agent a Sume token granted only mcp:read and it sees read-only tools, so it can inspect jobs and assets but never submit a paid generation.

Connect the sub-agent with an OAuth token that has only mcp:read. Sume's hosted MCP shows such a session read-only tools, so the sub-agent can inspect jobs and assets but cannot see or call a tool that submits work.
The roadmap framing is from the MCP roadmap (last updated 2026-08-22), read 2026-10-01. The scope facts are from MCP OAuth and API keys and MCP tools and gates.
What problem does the roadmap describe?
It describes agents spawning sub-agents that should get narrower authority than their parent, and says servers lean on pasted API keys. A full standard for that is still being worked on. What you can do today is choose the narrowest credential Sume offers.
What does each Sume credential let a sub-agent do?
| Credential | Sees | Mutating call |
|---|---|---|
OAuth mcp:read | Read-only tools | insufficient_scope |
OAuth mcp:read + mcp:write | Mutating and paid tools | Needs idempotency_key |
| API key | Full hosted tool set | Needs idempotency_key |
How do I get a read-only token?
On the consent page, Read is locked on and the Write toggle defaults to off. Leave it off. Supported scopes are mcp:read (required) and mcp:write (opt-in), and granting write always includes read. There is no mcp:paid scope; spend is governed by wallet and admission.
What can a read-only sub-agent still do?
Read tools include jobs_status, jobs_result, jobs_wait, assets_list and generation_admission_preview, so it can check on work the parent started or preview a cost. jobs_cancel is a write tool and is out of reach. If a sub-agent really needs to submit, see the subagent setup and grant write deliberately. One caveat: the token is a bearer token, so keep it out of prompts.
Sources
Related posts
More in Developers
- MCP workload identity federation: Sume takes code grant only
MCP's roadmap names Workload Identity Federation. Sume's hosted MCP advertises only the authorization_code grant, so headless workloads use an API key.
- Modal 150-second web timeout and 303 redirect: Sume polling
Modal web endpoints return a 303 redirect after 150 seconds. Sume returns 202 with status_url and result_url, so a client polls and follows no redirects.
- Nano Banana batch API: Gemini's 24 h batch vs Sume async jobs
Gemini's Batch API trades up to 24 hours of turnaround for higher rate limits. Sume has no batch tier for images: send async or webhook jobs per request.
- OpenAI Agents API durable sessions and Sume job ids
A durable OpenAI Agents API session continues across turns; a Sume render is a separate job. Keep the job id in the session and re-read it, never re-create.
Written by Sume