n8n AI Agent: force tool call on first iteration with Sume

n8n 2.40 added Force Tool Call on First Iteration to AI Agent v3. If Sume MCP is the tool, the first call is real: what a session can reach and the gates.

4 min readSume
All posts

Turning on Force Tool Call on First Iteration means the n8n agent has to call a tool before it can answer, so if Sume's hosted MCP server is that tool, the first call can be a real one. What that call can do depends on the session: an OAuth read-only session only sees read-only Sume tools, while an API-key session sees the paid ones too.

The option's name comes from the n8n release notes, read 2026-09-29; those notes give the name and nothing about how n8n picks the tool, so check n8n's own node documentation for that. Everything about Sume below is from the MCP tools and gates docs.

What did n8n add?

The n8n 2.40 release (2026-09-15) lists an AI Agent node v3 option named "Force Tool Call on First Iteration". The same entry adds custom headers for MCP registry remotes that survive OAuth token refreshes. The notes do not describe which tool a forced call chooses, so this post does not either.

Which Sume tools can a forced first call reach?

It depends on how the MCP session authenticated, not on n8n. Hosted MCP defaults to read-only visibility, and mutating and paid tools stay hidden until the session has mcp:write or an API key.

Sume hosted MCP visibility by session auth, from the docs read 2026-09-29.
Session authWhat a tool call can reach
OAuth mcp:read onlyRead-only tools. Mutating or paid calls return insufficient_scope.
OAuth mcp:read + mcp:writeFull hosted tool set. Paid submits still need idempotency_key and wallet/admission.
API keyFull hosted tool set. Same idempotency_key and admission rules.

What protects a forced paid call?

Three gates sit on the tool call. idempotency_key is required on write and paid tools; the docs describe it as a key for transport and dedup, not human approval. dry_run=true is an optional admission and cost preview that does not submit the job. max_spend_usd is optional and enforced only when provided.

The docs also say ordinary single creates do not need admission theater, and prefer generation_admission_preview or dry_run before expensive bursts. So a forced first call with an API key can spend money unless your prompt or the tool arguments say otherwise.

How do I make the first call a harmless one?

Give the agent a read tool to reach for. tools_list lists every tool visible in the session, tools_schema fetches one tool contract by name, and mcp_health reports endpoint readiness and safety posture. In the system message, tell the agent to start with tools_list and only then choose.

Connect with OAuth and leave Write off while you test; the docs' read-only playbook does exactly that, then stops before any mutating tool. Turn Write on, or switch to an API key, only for the workflow that should generate media. Before that, have the agent call tools_schema with the tool name and explain idempotency_key and dry_run.

Call tools_schema with name "generate_image" and explain idempotency_key and
dry_run before submitting any paid generation.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume