MCP sub-agent with narrower authority: a read-only Sume token

Give a sub-agent a Sume token granted only mcp:read and it sees read-only tools, so it can inspect jobs and assets but never submit a paid generation.

4 min readSume
All posts

Connect the sub-agent with an OAuth token that has only mcp:read. Sume's hosted MCP shows such a session read-only tools, so the sub-agent can inspect jobs and assets but cannot see or call a tool that submits work.

The roadmap framing is from the MCP roadmap (last updated 2026-08-22), read 2026-10-01. The scope facts are from MCP OAuth and API keys and MCP tools and gates.

What problem does the roadmap describe?

It describes agents spawning sub-agents that should get narrower authority than their parent, and says servers lean on pasted API keys. A full standard for that is still being worked on. What you can do today is choose the narrowest credential Sume offers.

What does each Sume credential let a sub-agent do?

Hosted MCP scopes from the Sume docs, read 2026-10-01.
CredentialSeesMutating call
OAuth mcp:readRead-only toolsinsufficient_scope
OAuth mcp:read + mcp:writeMutating and paid toolsNeeds idempotency_key
API keyFull hosted tool setNeeds idempotency_key

How do I get a read-only token?

On the consent page, Read is locked on and the Write toggle defaults to off. Leave it off. Supported scopes are mcp:read (required) and mcp:write (opt-in), and granting write always includes read. There is no mcp:paid scope; spend is governed by wallet and admission.

What can a read-only sub-agent still do?

Read tools include jobs_status, jobs_result, jobs_wait, assets_list and generation_admission_preview, so it can check on work the parent started or preview a cost. jobs_cancel is a write tool and is out of reach. If a sub-agent really needs to submit, see the subagent setup and grant write deliberately. One caveat: the token is a bearer token, so keep it out of prompts.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume